When you bring a new person into your business, the focus is usually on making sure they feel welcome and have the tools they need to get started. A laptop, email account, access to systems: maybe even a quick coffee with the team.
But there is one area that often gets overlooked: cyber security.
Keepnet’s research shows nearly three-quarters of new hires fall victim to phishing or social engineering attacks within their first 90 days. That makes the onboarding period one of the most dangerous times for your business’s security, and many owners do not realise it.
Think back to when you started a new job. You were keen to impress, did not fully know the processes, and probably second-guessed whether to question an instruction.
Cyber criminals exploit this uncertainty. They know your new starter has not yet learned what is “normal”. A cleverly written email that looks like it is from HR or a senior manager can be all it takes.
Examples we often see include:
Because your new employee has not built up that workplace instinct, they are 44% more likely to click on these scams compared to longer-serving colleagues. And when the attacker pretends to be a senior executive, that figure jumps even higher. As the National Cyber Security Centre explains in its phishing guidance, these attacks are carefully designed to look authentic and prey on moments of doubt.
We often hear from businesses that only realise the risk when it is too late. A new member of staff might click a link, share credentials, or process a false payment: not because they were careless, but because they were not trained to spot the warning signs.
Attackers know onboarding is a weak point, and research from Proofpoint shows they deliberately target employees during their first few months. Without the right preparation, your newest people could accidentally open the door to a data breach or financial loss.
The good news is that the risk can be reduced significantly. The key is to start cyber security training from day one, not weeks later once the employee has “settled in”.
Practical steps include:
Businesses that embed security into onboarding see phishing risk drop by up to 30%. It shows that a small investment of time upfront can prevent far bigger problems later. To support this, we include security awareness in our cyber security training, making it a natural part of the induction process.
If you are not sure where to begin, our IT support services also cover practical protections such as managed firewalls and secure email filtering, so your technology and people work together to defend your business.
People are always your first line of defence. But without the right guidance, new employees can become your biggest vulnerability. The difference comes from how you prepare them.
If you’d like help setting up simple, effective cyber security training for new starters or want to review your wider business security, get in touch or fill out the form below to speak to our support team.
"*" indicates required fields
June 23, 2026
Does your business have Web filtering set up? Web filtering is a security tool that...
April 1, 2026
What is Cyber Essentials and why does your business need it? Cyber Essentials is a...
February 16, 2026
Microsoft Is Adding AI Search to the Windows 11 Taskbar https://sjsystems.co.uk/wp-content/uploads/2026/01/Ask-Copilot-is-coming-to-your-Taskbar.mp4 The Windows search...
Say hello