TL;DR:

  • New hires are one of the most common sources of security incidents — through accident, phishing, or occasionally intent.
  • Create accounts with the minimum access needed for the role; don’t hand over an old employee’s login or an admin account.
  • Multi-factor authentication (MFA) should be set up on day one, before any other system access is granted.
  • Use this checklist before each new hire starts — set up security controls before they arrive, not after.

Cyber incidents involving new staff are more common than most small business owners realise. Some are deliberate — a disgruntled hire exports customer data before leaving. Most are accidental — a new employee clicks a phishing link because they aren’t yet sure what your company’s normal communications look like. Either way, the risk is highest in the first few weeks of employment, before habits are established and trust is built.

The good news is that most of the risk is controllable. Good security practices when a new person joins your business take about an hour to set up and significantly reduce your exposure.

Before They Arrive: Set Up Accounts With Minimum Access

The single biggest security mistake small businesses make with new hires is access creep — giving people more access than they need “to make things easy” or copying another employee’s account permissions wholesale.

Create fresh accounts rather than handing over a previous employee’s login. Shared credentials are a security problem: you don’t know what the previous employee did with them, and you can’t isolate the new person’s activity if something goes wrong.

Apply the principle of least privilege: give each new starter access only to what they need for their specific role. A bookkeeper doesn’t need access to HR records. A customer service rep doesn’t need admin access to your website. A salesperson doesn’t need read access to your accounts payable system. Permissions can be expanded later; starting with everything handed over is much harder to walk back.

Keep a written record of what each person has access to. A simple spreadsheet listing the employee, the systems they can access, and their permission level is enough. You’ll need this when they leave.

Day One: MFA Before Anything Else

Multi-factor authentication (MFA) is your most effective defence against stolen passwords. When MFA is enabled, a criminal who obtains your employee’s password still can’t log in without also having their phone or authenticator app.

Set up MFA on every account before the new starter receives their login details. The sequence matters: if they log in first and you add MFA later, there’s a window of vulnerability. Get MFA configured as part of the account setup process.

For Microsoft 365 accounts (the most common small business email and collaboration platform), MFA is enforced through the Microsoft 365 admin centre. Make it mandatory for all users — don’t leave it optional.

Preferred MFA methods, in order of security:

  1. Hardware security key (YubiKey, Titan Key) — most secure, consider for higher-risk roles
  2. Authenticator app (Microsoft Authenticator, Google Authenticator) — good balance of security and usability
  3. SMS/phone call — better than nothing, but vulnerable to SIM-swapping attacks

Avoid SMS as the primary MFA method if you can. Authenticator apps are the practical minimum for most small businesses.

Device Setup

If you’re providing a work device:

  • Set up device encryption (BitLocker on Windows, FileVault on Mac). This is often enabled by default but worth verifying.
  • Configure automatic updates — set Windows Update or macOS Software Update to install security patches automatically.
  • Install your business antivirus/endpoint protection before the employee starts using the machine.
  • Set a screen lock policy — devices should lock after 5–10 minutes of inactivity.

If the employee is using their own device (BYOD):

  • Require a minimum OS version before connecting to business systems.
  • Require a screen lock with PIN or biometric authentication.
  • Require business apps (email, collaboration) to be installed from official app stores, not side-loaded.
  • Consider whether BYOD is appropriate for roles handling sensitive customer or financial data.

Email and Phishing Awareness

New employees are prime phishing targets. Criminals send targeted spear-phishing emails timed to the first days of employment — “Hi, this is your IT department, please verify your new account by clicking here.” These work because new starters don’t yet know what legitimate company communications look like.

Brief your new hire on:

  • How your business communicates — which tools you use (Teams, Slack, email), what official IT communications look like
  • What to do if they receive a suspicious message (who to tell, not to click any links)
  • That your business will never ask for passwords by email or phone

Point them to the NCSC’s Cyber Aware guidance if they want to learn more — it’s written for non-technical people and covers the essentials well.

Access to Sensitive Information

Think carefully about what data the new person needs access to and when.

Trial period: consider restricting access to certain sensitive systems (customer financial data, employee records, legal documents) until the trial period is complete. This isn’t about distrust — it’s standard practice in well-run businesses.

Password manager: if your business uses a shared password manager (1Password Teams, Bitwarden Business, Keeper Business), add the new hire only to the vaults relevant to their role. Most team password managers support role-based vault access — use it.

Admin accounts: give admin access to systems only to people who actually need to perform admin tasks. “We’ll give you admin just in case” is how you end up with everyone having admin and no accountability when something changes.

The Quick Checklist

Print this out and run through it before each new hire’s first day:

  • Created a fresh account with role-appropriate access (no shared or inherited login)
  • MFA enabled and tested on email and core business systems
  • Device encryption confirmed active
  • Automatic security updates configured
  • Endpoint protection installed
  • Screen lock policy active
  • New starter added to password manager with appropriate vault access only
  • Access rights documented in your staff permissions register
  • Quick security briefing scheduled for day one (15 minutes is enough)
  • Offboarding process confirmed and documented before they start

The last point matters more than it sounds. Knowing in advance how you’ll remove access when this person eventually leaves means you won’t forget any accounts when that day comes.