New member of staff… new security risk? • Blisstech Solutions

When you hire someone new, do you think about how secure your business really is?

Most business owners focus on making sure their new starter has what they need. You know, a laptop, email account, access to the right systems… maybe a quick intro to the team.

But those first few months of a new employee’s journey are one of the most dangerous times for your business’s cybersecurity.

And it often flies completely under the radar.

New research has revealed a worrying truth. Nearly three-quarters of new hires (71% to be precise) fall for phishing or social engineering attacks within their first 90 days on the job.

That means cyber criminals are actively targeting your newest team members. And too often, they succeed.

Why is this happening?

Well, think about how it feels to start a new job. You’re trying to make a good impression. You don’t know all the processes yet. You’re keen to follow instructions and do the right thing.

Cyber criminals know this. They take advantage of that uncertainty with cleverly written emails or messages that look like they come from the boss, HR, or even tech support.

These scams might ask your new hire to update their details on a fake HR portal. Or they might send a bogus invoice that looks urgent. Sometimes it’s as simple as an email pretending to be from a senior manager, asking for sensitive information or for a quick favour.

Because that new employee hasn’t yet learned who’s who and what’s normal, they’re much more likely to fall for it. In fact, new employees are 44% more likely to click on these traps than colleagues who’ve been around a while.

It’s not just theory. The stats back it up. When attackers pose as company executives, new starters are 45% more likely to be fooled than experienced staff.

That’s a big gap, and it shows just how vulnerable your business can be during the onboarding period.

So… what can you do about it?

The key is to recognise that cybersecurity training shouldn’t wait until your new hire has “settled in”. Those early days are exactly when they need clear guidance on spotting phishing emails, understanding how cyber criminals operate, and knowing what to do if something seems off.

Businesses that take this seriously see real results. The same report found that companies offering tailored security awareness training and running realistic simulations for new staff saw their phishing risk drop by 30% after onboarding. That’s a massive difference. It shows that a bit of extra effort at the start pays off.

Of course, tools like good security software and firewalls are still essential. But on their own, they’re not enough. People are your first line of defence.

And right now, your newest people might just be your weakest link. Unless you give them the tools and knowledge to help protect your business from day one.

If you’d like help setting up simple, effective cybersecurity training for new starters, or want to talk about making your business more secure overall, we can help. Get in touch.

More Content

The anatomy of a cyber ready business

Cyber Readiness: How to Build a Business That’s Tough to Hack

Why Cyber Readiness Matters Cyberattacks aren’t just a problem for big corporations — cybersecurity for small businesses a growing threat too. A single breach can disrupt operations, damage your reputation, and cost you money. The good news? You don’t need a huge...
How to free up disk space on Windows title image

Tech Tip: 3 ways to free up disk space on Windows

Running low on disk space can make your computer run slowly and can cause other problems such as being unable to run applications, install important updates and in some cases cause your computer to crash. This tech tip will show you three ways that you can free up...

Charging in public places? Watch out for “juice jacking”

Airports, hotels, cafés, even shopping centres, offer public charging points where you can boost your phone or laptop battery on the go. They’ve been in the news after the FBI recently tweeted advice to stop using them. Crooks have figured out how to hijack USB ports to install malware and monitoring software onto devices as they charge. The security risk …
Read More

Teams update: No more accidental quitting

Teams update: No more accidental quitting

Ever noticed how it’s the tiny software quirks that cause the most frustration?
If you live in Microsoft Teams meetings, there’s a subtle change rolling out that could make things feel noticeably smoother.
It’s one of those updates everyone will appreciate…

How future-ready is your business’s IT?

How future proof is your business’s IT?

Your business’s tech might be working well today, but is it ready for tomorrow? A new study has found more than 60% of business leaders aren’t confident about theirs. What about yours?

Relying on Windows 10 extended support? Time to upgrade

Relying on Windows 10 extended support? Time to upgrade

Still relying on Windows 10 with Extended Security Updates?
Your safety net has an end date and it’s approaching fast.
When it disappears, so does your protection.
If Windows 10 is still part of your business setup, now’s the time to start thinking ahead…

Say goodbye to hours wasted on PowerPoint slides

Say goodbye to hours wasted on PowerPoint slides

PowerPoint presentations still hold a firm place in many business meetings. But, let’s be honest, they’re a real pain to create. If you regularly use PowerPoint, Microsoft’s got a solution you’ll love…

Microsoft Remove Delay Windows 10 Updates in version 2004

We recently wrote an article on how to delay Windows 10 updates so that you can wait until issues are resolved before you install new updates.  However, in the Windows 10 2004 update, Microsoft has removed the ability to delay Feature Updates for up to 365 days in the...
How to create secure passwords

How to create secure passwords

Weak passwords are one of the biggest security risks to your business.
Why?
Because cyber criminals are getting smarter than ever before. If they manage to crack just one password, they could gain access to your sensitive business data, financial information, or even gain control of your entire system.
Cyber criminals use automated tools to guess passwords, allowing them to try out millions of combinations in seconds. So, if you’re using something like “Password123” or “CompanyName2025”, you’re practically handing them the keys to your business.
A compromised password can lead to big issues, such as:
• Data breaches
• Financial losses
• Identity theft
• Reputation damage
But how do you create strong passwords without driving yourself (and your team) mad?
Think of your password like a secret recipe, where only you should know the ingredients. It should:
• Be at least 14 characters long (the longer, the better)
• Include a mix of uppercase and lowercase letters
• Contain a few numbers and symbols (like @, $, %, or &)
• Not contain any common words or easily guessable information (like birthdays, names, or the word “password”)
Instead of using a single word, you could try a passphrase – a short, random sentence that only you would understand. For example, instead of “Sailing2025”, try something like “Coffee&CloudsAreGreat9!”. This is much harder to crack, yet still easy to remember.
You should also steer clear of these common mistakes:
• Using personal info (your name, birthday, business name, etc.)
• Reusing the same passwords across multiple accounts
• Using simple sequences (“123456” or “abcdef”)
• Storing passwords in an easily accessible place (like a sticky note on your desk)
If remembering unique passwords for every account sounds impossible, there is another option: Password managers. These generate strong passwords, store them securely and autofill them for you.
With a password manager, you only need to remember one strong master password for the manager app itself. The rest are encrypted and stored safely, reducing the risk of data breaches.
Even the strongest password isn’t foolproof, which is why multi-factor authentication (MFA) is also important. MFA requires a second form of verification, like a one-time code sent to your phone or generated from an authentication app.
If you have employees accessing your business systems, it’s a good idea to have a password policy in place to explain your rules and why they’re important. This should include:
• Unique passwords for each system and account
• Regular security training on password best practices
• Business-wide use of MFA for critical systems
• Scanning for compromised passwords regularly
By making password security a priority, you can reduce the chances of a cyber attack creating a nightmare for your business.
And if you need help making your business more secure, get in touch.

Are your younger employees experiencing ‘tech shame’?

Gen Z and even some Millennial employees are less tech savvy than many employers might expect. It’s an assumption that’s leading to a sense of ‘tech shame’.

Share This
Contact
Love Lane
Cleobury Mortimer
Shropshire DY14 8PE

01299 382 321
[email protected]
Copyright © Blisstech Solution Ltd
Registered No: 08125391 VAT No : 307 5490 05