New User Cyber Safety Pack
A simple cyber security induction for new starters and employees, covering phishing, social engineering, passwords, MFA, device security and incident reporting, with free NCSC training and a downloadable quick-reference guide.
What's inside
- The five essential cyber safety rules for new starters
- STOP, CHECK, VERIFY, REPORT: a simple habit for spotting scams
- How modern phishing and social engineering actually work in 2026
- Protecting passwords, MFA and your devices
- What to do if something goes wrong, with no blame
- A direct link to the free official NCSC staff training
Starting a new job means new systems, new passwords, new people and lots of unfamiliar emails. That also makes the first few weeks an ideal opportunity for cyber criminals.
This free cyber safety pack gives employees the practical basics they need to work safely online, recognise phishing and social engineering, protect their accounts and know what to do when something does not look right. No technical knowledge is required.
NEW USER CYBER SAFETY PACK
Phishing. Passwords. MFA. Devices. Social engineering. Reporting.
Free official NCSC training. No account required. Takes less than 30 minutes. Includes a short quiz. The NCSC training opens on the National Cyber Security Centre website in a new tab.
Under 30 minutes
Complete the NCSC core training in one short session.
No technical knowledge needed
Written for ordinary employees, not IT specialists.
Practical advice
Learn what to do when an email, call, login or request does not feel right.
Free to use
No registration and no email address required.
Five things every new starter should know
01 Stop before you click
Unexpected does not automatically mean malicious, but unexpected messages deserve a second look. Be cautious when an email, Teams message, text or other communication:
- asks you to sign in
- asks for a password or MFA code
- contains an unexpected attachment
- asks you to change bank details
- asks you to make an urgent payment
- claims your account will be disabled
- pressures you to act immediately
- asks you to bypass a normal procedure
Do not rely on bad spelling as a warning sign. Modern phishing messages can be perfectly written. Learn how phishing has changed.
02 Verify unusual requests another way
If someone asks you to do something unusual, sensitive or financially important, verify it using a contact method you already trust. Do not simply reply to the message that caused the concern. For example, call the person on their normal known number, speak to them in person, use an existing company directory, ask your manager or IT team, or follow your organisation’s payment or identity verification procedure.
A familiar name, email address, phone number or even a voice is no longer enough on its own. Urgency is not a reason to skip security procedures. See how social engineering attacks work in the real world.
03 Protect your accounts
Your work account is part of your organisation’s security perimeter. Employees should:
- use a strong, unique work password or passphrase
- never reuse a work password on personal websites
- use the approved company password manager where provided
- use multi-factor authentication (MFA)
- never approve an MFA request they did not initiate
- never tell anyone an MFA code
- never share passwords with colleagues
- contact IT about unexpected authentication prompts
A genuine IT team should not need to know your password to help you.
04 Keep devices safe
A secure account is only part of the picture. The device you use matters too. Employees should lock their screen whenever they leave a device, only install approved software, avoid unknown USB devices, take care with screens in public, keep laptops, phones and tablets physically secure, and immediately report a lost or stolen work device.
If your organisation manages updates centrally, allow the update or restart when your IT team asks you to.
05 Report it quickly
Cyber incidents become harder to deal with when nobody knows they have happened. If you clicked a suspicious link, opened an unexpected attachment, entered your password into a page you now distrust, approved an unexpected MFA request, sent information to the wrong person, responded to a suspected scam, lost a work device, or noticed anything else unusual, report it immediately.
Clicked something? Tell someone.
Reporting a mistake quickly gives your IT team the best chance of protecting you and the organisation. Do not wait to see what happens, and do not try to hide it.
Remember four words
Complete the official NCSC staff training
The UK’s National Cyber Security Centre provides a free cyber security awareness course designed for non-technical staff. It covers four core areas:
- strong passwords
- securing devices
- defending against phishing
- reporting incidents
It takes less than 30 minutes and includes a short quiz.
Start NCSC Top Tips for Staff ↗
The NCSC training opens on the National Cyber Security Centre website. System Force IT does not operate or control the NCSC training platform.
Download the NCSC staff security infographic ↗
External resource from the National Cyber Security Centre.
More free System Force resources
Safer Internet for Business
An eight-page guide to phishing, social engineering, MFA, password hygiene and reducing human error.
AI Scams: Deepfakes, Voice Clones and Smarter Phishing
Why modern scams are harder to recognise and why good spelling is no longer proof that a message is genuine.
The M&S Cyber Attack Started With a Phone Call
A real-world example of social engineering and why identity verification procedures matter.
Phishing Defence Playbook for UK SMEs
A deeper guide for business owners and IT teams covering phishing controls, awareness and incident response.
Using this pack for employee onboarding
You can use this page as part of your new-starter induction process. A simple approach is:
- Ask the employee to read the New User Cyber Safety Pack.
- Ask them to complete the NCSC Top Tips for Staff training.
- Make sure they know your organisation’s own incident reporting procedure.
- Explain who they should contact if they make a mistake or see something suspicious.
- Repeat security awareness periodically rather than treating it as a once-only exercise.
Every organisation should add its own reporting process, acceptable-use policies and role-specific requirements. This public guide does not replace an employer’s policies.
There is also a simple printable onboarding record (PDF) that managers and HR can use to note completion. It is a record, not a certificate.
If your organisation is supported by System Force IT, use your normal System Force support route. Otherwise, follow your organisation’s own incident reporting process.
Frequently Asked Questions
Yes. The System Force New User Cyber Safety Pack is free to download and the NCSC Top Tips for Staff training is also provided free of charge by the National Cyber Security Centre.
The NCSC states that its Top Tips for Staff training takes less than 30 minutes. The System Force Cyber Safety Pack is designed to be read in around 10 to 15 minutes.
Yes. It is specifically intended for ordinary employees and new starters. No technical or cyber security background is required.
No. Every employer should provide its own policies, reporting procedures and role-specific requirements. This pack provides general cyber safety awareness to complement those policies.
They should report it to their organisation’s IT team or designated contact immediately. Fast reporting gives the organisation the best opportunity to investigate, reset credentials where necessary and limit any impact.
Security incidents should be reported as quickly as possible. Organisations should encourage prompt reporting rather than creating a culture where employees hide mistakes because they fear blame.
Need help building a safer workforce?
Technology is only part of cyber security. Good procedures, sensible controls and confident staff make attacks much harder to succeed. System Force IT helps UK SMEs protect Microsoft 365, endpoints, networks, data and users, backed by practical cyber security guidance and ongoing support.
This guide provides general cyber security awareness information. Organisations should supplement it with their own policies, procedures, reporting routes and role-specific training. Explore more free downloads in our resources library.