IT Security do’s and don’ts

Security is the responsibility of us all. Follow the tips below and you’ll be helping to keep yourself, your colleagues and your business safe.

DO Seek advice from OnIT if you are unclear about any aspect of information security.

DO use hard-to-guess passwords or passphrases. A password should have a minimum of 10 characters using uppercase letters, lowercase letters, numbers and special characters. To make it easy for you to remember but hard for an attacker to guess. Also when did you last change the password.

DO keep your passwords or passphrases confidential.

DON’T post any private or sensitive information, such as credit card numbers, passwords or other private information, on public sites, including social media sites, and DON’T send it through email unless authorised to do so.

DO use privacy settings on social media sites to restrict access to your personal information.

DO pay attention to phishing traps in email and watch for tell tale signs of a scam.

DON’T open mail or attachments from an untrusted source. If you receive a suspicious email, the best thing to do is to delete the message.

DON’T click on links from an unknown or untrusted source. Cyber attackers often use them to trick you into visiting malicious sites and downloading malware that can be used to steal data and damage networks.

DON’T be tricked into giving away confidential information. It’s easy for an unauthorised person to call and pretend to be an employee or business partner.

DO lock your computer and mobile phone when not in use. This protects data from unauthorised access and use.

DON’T plug in portable devices without permission from your company management. These devices may be compromised with code just waiting to launch as soon as you plug them into a computer.

DON’T install unauthorised programs on your work computer. Malicious applications often pose as legitimate software. Contact your IT support staff to verify if an application may be installed.

DON’T leave devices unattended. Keep all mobile devices, such as laptops and mobile phones physically secured. If a device is lost or stolen, report it immediately to your manager, internal IT and / or OnIT.

DON’T Plug in any personal devices without the OK from OnIT, your line manager or internal IT department.

DO Report all suspicious activity and Cyber incidents to your manager and OnIT

Remember – cyber security is everyone’s responsibility!