Training

General cyber security

Good security is built into daily habits. These best practices for computer use make you and your organisation noticeably safer — without taking any real effort.

Do your updates! (video by Tip ICT, video in Dutch)
Food for thought, first

Picture your office in your mind: how many unlocked screens, loose documents and post-its with passwords could a visitor see right now?

The basics: six habits

1. Lock your screen — always

Stepping away from your desk, even for just a minute? Lock your screen with Windows key + L (Windows) or Ctrl + Cmd + Q (Mac). An unlocked screen gives anyone walking by access to your email, files and systems. Also set automatic locking after a maximum of 5 minutes of inactivity.

2. Clear desk & clear screen
  • Don't leave documents with sensitive information on your desk; store them away or shred them.
  • No passwords on post-its — use a password manager.
  • Make a clear desk your starting point at the end of the day.
  • Watch out for people looking over your shoulder on the train or at the office; consider a privacy screen on your laptop.
3. Install updates right away

The vast majority of successful attacks exploit vulnerabilities for which an update already existed. Set Windows/macOS, your browser and your apps to update automatically, and restart your computer whenever asked. Putting off that quarter-hour "restart later" is exactly the gap attackers crawl through. Also check out the video above.

4. Make sure you have backups

Ransomware or a stolen laptop is annoying; losing your data is a disaster. Make sure company data is kept in the agreed location (Microsoft 365, Google Workspace or the NAS) so it's backed up automatically — not just stored locally on your desktop. Periodically test that a file can actually be restored.

5. Handle company information consciously
  • Share files through the official company environment, not via personal email, WeTransfer or USB sticks.
  • Be cautious with company information in public AI tools; see our working better with AI training.
  • Don't use USB sticks you found or were given — hand them in to IT.
  • Working from home or on the go? Don't use public wifi without a VPN, or use your phone's hotspot instead.
6. Secure your devices
  • Secure your phone and laptop with a PIN/biometrics and encryption (BitLocker/FileVault — often already arranged by your administrator).
  • Only install software you actually need, from official sources.
  • Don't use your work account for personal matters, or vice versa.
  • Report a lost or stolen device to your IT administrator right away.

✔ Do

  • Windows + L every time you walk away
  • Install updates and restart right away
  • Save files in the agreed company location
  • Report incidents immediately — however small

✘ Don't

  • Passwords on post-its
  • Connecting USB sticks you found
  • Public wifi without a VPN for work
  • Keeping an incident quiet out of embarrassment

Report incidents right away

Seen something odd? A suspicious email, a pop-up, a lost device, an accidental click on a link? Report it to your IT administrator or Tip ICT right away. Speed limits the damage, and reporting is never "silly" — staying quiet is.

Test yourself

Question 1 · self-test

You step away from your desk for two minutes. What do you do?

Question 2 · self-test

An update is ready for your laptop, but you're busy. What do you do?

Question 3 · food for thought

Do you know what to do first — and who to call — if your laptop is encrypted by ransomware this afternoon?

Question 4 · self-test

You find a USB stick in the car park. What do you do?

Question 5 · self-test

Someone in work clothes walks in behind you without a badge. What do you do?

Question 6 · food for thought

What information on your desk or screen could a passing visitor read right now?

Further reading

Want to know how cyber secure your organisation is?

Request an IT security quickscan