Use your organisation’s rules as the starting point
A work computer connects to information and services other people depend on. Your acceptable-use policy should explain permitted personal use, approved tools and how to ask for help. Safe working should be practical, with clear instructions and an IT contact, rather than relying on people to guess.
1. Mixing personal and work accounts
Signing a personal account into a work browser can synchronise passwords, history or files to places your organisation does not manage. Keep the approved work profile separate and check which account is active before saving or sharing information.
Use an approved password manager where provided. Do not copy work credentials into personal notes or reuse your work password for unrelated websites. If a service needs shared access, ask IT for an approved arrangement instead of sharing a colleague’s password.
2. Installing unapproved apps or moving work data into personal tools
A useful-looking browser extension, file converter or AI assistant may receive the information you put into it. Ask whether the tool is approved before installing it or entering client records, confidential documents or personal information.
Keep business files in approved locations. A personal cloud drive or email account may make a task convenient but can leave access, retention and recovery outside the organisation’s controls. If the approved route does not work, report the obstacle rather than creating an unofficial workaround.
3. Trusting unexpected links, downloads or prompts
Pause when a message asks you to open an unexpected attachment, sign in again or approve an authentication request you did not initiate. Verify unusual requests through a known contact route, especially changes to payment details or access permissions.
Do not enable document macros, install a browser update from an unfamiliar page or bypass a blocked download to finish a task. Let IT check legitimate files that have been stopped. The secure file-sharing guide explains safer ways to handle different types of information.
4. Letting someone else use your signed-in session
Lock the screen when you step away. Another person using your account may be able to read messages, send files or make changes recorded in your name. Do not let a visitor or family member use a signed-in work session.
Follow the organisation’s rules for shared devices and personal use. If a colleague needs access, they should have their own authorised account or an approved shared-device arrangement. Report a lost device promptly through the agreed route.
5. Disabling managed protections
Do not turn off endpoint protection, encryption, filtering or update controls to make a problem disappear. Report the error and its effect on your work. IT can investigate compatibility issues and agree a safe resolution.
Allow required restarts within the agreed process. Tell IT if a device repeatedly fails to update, prompts for unexpected administrator access or behaves unusually. Managing patches is an IT responsibility; recognising and reporting problems is part of everyone’s role.
If you have already made a mistake
- Stop interacting with the suspicious message, site or app.
- Contact IT through a known route promptly. Explain what happened and when, without including passwords or recovery codes.
- Follow the incident instructions. Do not delete evidence, reset the device or contact a suspected attacker on your own.
- If credentials or information may have been exposed, let the responsible team coordinate account recovery and any further response.
What managers and IT should provide
Give people approved tools, clear reporting routes, useful awareness training and a workable process for requesting access. Review recurring workarounds to find the underlying problem. A policy on its own cannot replace device management or timely support.
See the NCSC password guidance, try our free cyber security training or explore managed cyber security support.
About this guide
The earlier article at this address was supplied through MSP Marketing Edge and credited to The Technology Press, republished with permission. This updated guide retains that source acknowledgement and replaces outdated advice. It is not presented as original CompTech reporting.
Use this guidance alongside your organisation’s policies and agreed IT support arrangements. Product features and licence terms can change; check the linked supplier guidance before making a purchase or changing settings.
