Digital security basics for non-technical teams
Practical digital protection comes from understandable habits and supportive systems. Focus on sign-in, sharing, devices, verification, and a clear way to ask for help when something seems wrong.
Staff should not need to become security specialists to use everyday technology responsibly. They do need clear expectations, manageable tools, and someone to contact when a situation is uncertain. Advice that depends on constant vigilance is difficult to sustain, especially when teams are busy, remote, or working with changing groups of volunteers.
Useful digital protection combines sensible administration with a few repeatable habits. The organisation provides supported accounts, devices, access rules, and recovery arrangements. People learn the decisions that matter in their own work. Neither side can replace the other, and mistakes should lead to prompt support rather than silence or blame.
1. Make sign-in safer without making it mysterious
Use individual work accounts and keep passwords unique to each service. An organisation-approved password manager can help people generate and store passwords without relying on reused phrases or informal shared lists. Give practical guidance on setting it up, protecting access, and recovering an account through the approved process.
Enable multi-factor authentication where available and help staff enrol an appropriate method. Prefer phishing-resistant options where supported and suitable for the team. Explain that a code or approval prompt is a request to authorise access, not an ordinary message to pass on. An unexpected prompt should be declined and reported through the agreed route.
- Do not approve a sign-in request you did not initiate.
- Do not share passwords, authentication codes, or recovery codes with someone contacting you.
- Use the documented recovery process if a device or sign-in method is lost.
- Ask an administrator to provide delegated access instead of sharing a colleague's login.
2. Verify consequential requests through another route
Messages about payments, bank details, credentials, or urgent information deserve a deliberate verification step. A familiar name, convincing tone, or existing conversation does not prove that a request is genuine. Accounts can be misused, and sender details can be imitated. Avoid asking staff to judge trustworthiness only by spotting spelling mistakes.
For a change to payment details or an unusual disclosure, contact the person through a route already known to be reliable. Use an established number or directory entry, not contact details supplied in the message being checked. Keep the organisation's normal approval process even when a request claims to come from a senior colleague.
Provide a clear way to report suspicious messages. If someone has already clicked, shared information, or approved access, ask them to report what happened promptly. Early, accurate information is more useful than making them feel they must solve the problem alone or hide it.
3. Share information deliberately
Before sending a file or granting access, check the recipient, the purpose, and the amount of information needed. Use approved organisational storage and sharing tools rather than moving records into a personal account for convenience. Where practical, share a controlled link to the authoritative document instead of circulating multiple attachments.
Understand the difference between access for named people and a link that can be passed on. Choose viewing rather than editing when that meets the task, and review access when a project or partnership ends. Permissions should follow the work people need to do, not assumptions about who might find something useful.
- Check autocomplete suggestions before sending sensitive information.
- Keep beneficiary, customer, and staff information in approved locations.
- Confirm a new recipient's access using a non-sensitive test when needed.
- Report a mistaken share promptly so the responsible person can limit further exposure.
4. Keep devices supported and everyday work recoverable
Use supported devices and applications, and follow the organisation's update process. Updates may require a restart or a planned interruption, so provide staff with a realistic way to complete them rather than leaving repeated prompts unexplained. Report persistent update failures instead of disabling the mechanism or ignoring it indefinitely.
Lock screens when stepping away, keep devices physically secure, and report loss through a route people can access without the missing equipment. Device encryption, management, and protection tools are organisational responsibilities that should be configured and checked, not assumed from a staff reminder.
Store important work where the organisation's recovery arrangements apply. A file saved only on a local desktop may fall outside them. Staff should know where to save records and how to request restoration; administrators should verify that recovery works. A convenient synchronised folder is not, by itself, evidence of an independent backup.
5. Make getting help an ordinary part of work
Publish a simple reporting route for suspicious activity, lost devices, unexpected access, and accidental disclosure. Include an alternative if normal email or sign-in is unavailable. Tell people what to provide: what they noticed, when it happened, the service or device involved, and whether they took any action. Do not ask them to circulate sensitive material widely as evidence.
Explain what happens next and who will coordinate the response. Staff should avoid deleting messages, resetting equipment, or attempting their own investigation unless directed by the responsible support person. The appropriate action depends on the situation; a short reporting guide should connect people to help rather than pretend to cover every incident.
Respond constructively when concerns turn out to be harmless. People are more likely to raise the next useful warning if previous reports were welcomed. Clear support ownership also prevents urgent reports being lost between a manager, a supplier, and an unmonitored mailbox.
6. Practise the habits in familiar situations
Use short, relevant exercises rather than a catalogue of threats. Walk through checking a changed supplier payment request, sharing a project file with a partner, or reporting a lost work phone. Discuss the correct route and let staff try the approved tools with safe example information.
Include these practices in onboarding and revisit them when working arrangements change. Make guidance accessible to different language, confidence, and accessibility needs. Managers should follow the same processes as everyone else; exceptions made for seniority can undermine otherwise sensible expectations.
Review the support requests and points of confusion that arise. If staff repeatedly choose an unapproved workaround, investigate whether the official process is too difficult or missing a necessary capability. Improve the system as well as the instructions. Sustainable protection comes from making the appropriate action understandable and practical during ordinary work.
The practical takeaway
Agree a small set of everyday practices: use individual accounts and stronger sign-in, verify unusual requests independently, share through approved tools, keep work recoverable, and report concerns early. Pair each expectation with usable guidance and a named support route. Confidence grows when people know both what to do and where to get help.
General guidance, not a substitute for an assessment of your organisation's systems, responsibilities, or legal requirements.