{"id":106984,"date":"2019-11-01T17:26:08","date_gmt":"2019-11-01T17:26:08","guid":{"rendered":"https:\/\/www.internetsociety.org\/?post_type=resources&#038;p=106984"},"modified":"2025-06-24T16:58:40","modified_gmt":"2025-06-24T16:58:40","slug":"security-factsheet-keeping-your-workplace-safe-online","status":"publish","type":"resources","link":"https:\/\/www.internetsociety.org\/resources\/doc\/2019\/keeping-your-workplace-safe-online\/","title":{"rendered":"Security Factsheet: Keeping Your Workplace Safe Online"},"content":{"rendered":"<p><em>Note: This factsheet was written in collaboration with <a href=\"https:\/\/nextcenturycities.org\/\">Next Century Cities<\/a>.<\/em><\/p>\n<div class=\"green-highlight\" style=\"background: #40b2a4; color: white;\">\n<p><strong>For many of us the Internet is a staple in our day-to-day lives \u2013 especially at our jobs. But did you know that by simply connecting your device to WiFi or delaying computer and software updates can put you and your workplace at risk of a cyberattack?<\/strong><\/p>\n<p>Any time you go online you\u2019re using a gateway to the Internet. At work, this is usually either a WiFi or ethernet connection. When you connect a device to that gateway, it has a path to all other devices using that same gateway. That\u2019s why your mobile phone can sync with your smart watch. However, if gateways and devices are not secure, bad actors could also get access to your laptop and other devices using the same connection.<\/p>\n<p>Don\u2019t put yourself or your coworkers at risk!<\/p>\n<p>If you work for a company or agency that has sensitive or private information stored on its devices (especially in government or related services), it is critical to make sure that only secure, trusted devices have access to that network.<\/p>\n<p>Here are 8 easy ways to help keep you, your colleagues, and your workplace network safe online.<\/p>\n<\/div>\n<h6>1. Don\u2019t connect your Internet-connected smart devices to your work WiFi network.<\/h6>\n<p>If you connect an insecure or vulnerable device (like an knock-off watch or smart assistant) to your work WiFi network, it can be used to infiltrate the network as a whole.<\/p>\n<div class=\"green-highlight\">\n<p><strong>Example<\/strong>: A fish tank thermometer was <a href=\"https:\/\/www.businessinsider.com\/hackers-stole-a-casinos-database-through-a-thermometer-in-the-lobby-fish-tank-2018-4\">used by hackers<\/a><a href=\"#_ftn1\" name=\"_ftnref1\"><sup>[1]<\/sup><\/a> to steal a casino\u2019s database!<\/p>\n<p><strong>Fix<\/strong>: Leave your smart devices at home. If you need them for work, either connect them to a guest network or one that doesn\u2019t have access to the same devices where sensitive information is stored.<\/p>\n<\/div>\n<h6>2. Don\u2019t use smart assistants in the same room where sensitive or private meetings take place.<\/h6>\n<p>Smart assistants are inherently insecure because their job is to constantly listen for a \u201cwake\u201d word that gives a command. They can also record what they hear \u2013 without your knowledge\u2013 and store it in company databases to help improve the service. If you\u2019re having sensitive conversations, they may be picked up, saved, and heard by employees of the smart assistant\u2019s parent company.<\/p>\n<div class=\"green-highlight\">\n<p><strong>Example<\/strong>: Amazon Alexa employees may be <a href=\"https:\/\/www.bloomberg.com\/news\/articles\/2019-04-10\/is-anyone-listening-to-you-on-alexa-a-global-team-reviews-audio\">listening to your conversations<\/a>.<a href=\"#_ftn2\" name=\"_ftnref2\"><sup>[2]<\/sup><\/a><\/p>\n<p><strong>Fix<\/strong>: Leave personal assistant devices at home. If you need to bring a smart assistant to work, disable the listening mode or make sure your colleagues are aware and place it in a place where conversations are public like a lobby.<\/p>\n<\/div>\n<h6>3. Do your homework before buying a new smart device.<\/h6>\n<p>With the ever-growing number of connected devices hitting store shelves each year, it can be hard to tell which products were designed to keep you and your data safe online. Here are two tip sheets to help you keep security and privacy in mind when buying and setting up new devices.<\/p>\n<ul>\n<li><a href=\"https:\/\/www.internetsociety.org\/wp-content\/uploads\/2019\/04\/smart-device-checklist.pdf\">Smart Device Purchase and Setup Checklist<\/a><a href=\"#_ftn3\" name=\"_ftnref3\"><sup>[3]<\/sup><\/a><\/li>\n<li><a href=\"https:\/\/www.internetsociety.org\/wp-content\/uploads\/2019\/04\/iotchecklist.pdf\">Enhancing the Security, Privacy, and Safety of Connected Devices<\/a><a href=\"#_ftn4\" name=\"_ftnref4\"><sup>[4]<\/sup><\/a><\/li>\n<\/ul>\n<h6>4. Use unique passwords.<\/h6>\n<p>Using the same password for everything may be easy to remember, but it puts you at huge risk of a data breach and account hijack. If even one of your services is hacked and your password is discovered, it can also expose bad actors to your social media accounts, online banking, email, work systems, and more.<\/p>\n<div class=\"green-highlight\">\n<p><strong>Example<\/strong>: Millions of passwords and corresponding usernames (email addresses) <a href=\"https:\/\/www.forbes.com\/sites\/kateoflahertyuk\/2019\/04\/21\/these-are-the-worlds-most-hacked-passwords-is-yours-on-the-list\/#666b4f82289c\">have already been hacked<\/a><a href=\"#_ftn5\" name=\"_ftnref5\"><sup>[5]<\/sup><\/a> and can be used to unlock the owners\u2019 accounts.<\/p>\n<p><strong>Fix<\/strong>: Use a password manager to create strong and unique passwords for your accounts. The system will save them for you and can auto input them when you log in to your accounts. To access the database of passwords, you only need to remember one master password that you create yourself. This way, you stay safe without having to keep a rolodex of passwords in your brain! Where possible, you should also use <a href=\"https:\/\/twofactorauth.org\/\">two-factor authentication<\/a><a href=\"#_ftn6\" name=\"_ftnref6\"><sup>[6]<\/sup><\/a> (e.g. password plus a code from an app like Google Authenticator).<\/p>\n<\/div>\n<h6>5. Don\u2019t click on links in emails or messages unless you\u2019re 100% sure they\u2019re safe.<\/h6>\n<p>Phishing scams are some of the most common ways online criminals can get access to your network and contacts. Hackers will spoof or mimic an email address or messaging account you trust (usually family, friend, or a coworker) with an attachment or a link to something for you to click on. When you do, the hacker can use it to download malicious software to your computer, steal your information, and get your passwords and other sensitive information.<\/p>\n<div class=\"green-highlight\">\n<p><strong>Example<\/strong>: Check out <a href=\"https:\/\/www.consumer.ftc.gov\/articles\/how-recognize-and-avoid-phishing-scams\">this guide<\/a><a href=\"#_ftn7\" name=\"_ftnref7\"><sup>[7]<\/sup><\/a> on how to avoid phishing schemes from the Federal Communications Commission.<\/p>\n<p><strong>Fix<\/strong>: Turn off automatically loaded remote content. Only click on links (in messages, emails, or even social media) if you\u2019re absolutely confident that the person that sent it actually sent it. If the URL looks suspicious, that\u2019s a red flag. When in doubt, don\u2019t click on the link. Use bookmarked URLs to log on to your bank, medical practices and other sensitive sites instead of links within an email.<\/p>\n<\/div>\n<h6>6. Promote the use of strong, encrypted devices and resources at work.<\/h6>\n<p>Unencrypted or weakly-encrypted devices and services can put your personal and work data and systems at risk. Encryption is one of the strongest tools to protect our data, privacy and critical systems online. Encrypted devices and systems are much harder for malicious actors to access, and even if they did, it makes the information unreadable without your personal \u201ckey\u201d to unlock its contents.<\/p>\n<div class=\"green-highlight\">\n<p><strong>Example<\/strong>: In 2014 <a href=\"https:\/\/time.com\/3639907\/sony-hack-data-security\/\">Sony was hacked<\/a><a href=\"#_ftn8\" name=\"_ftnref8\"><sup>[8]<\/sup><\/a> and all of its employees unencrypted private emails, passwords, and in some cases Social Security Numbers were publicly released.<\/p>\n<p><strong>Fix<\/strong>: Use services that promote their use of strong encryption, especially end-to-end encryption. When transferring or beginning your use of a new service or software, be sure to check if they automatically encrypt your data and messages, or if you can turn on that feature. If not, consider using another service.<\/p>\n<\/div>\n<h6>7. Keep your software up to date.<\/h6>\n<p>Updates don\u2019t just come with new features. They are a developer\u2019s way of fixing any known bugs or security vulnerabilities in their software. Companies are constantly working to keep their software stronger than the best hackers out there. Waiting for your computer and devices to download, install, and reboot after an update may be annoying, but it is a critical way to protect yourself from the most current security threats. Delaying software updates can unnecessarily put you, your devices, and your entire network at risk of a cyberattack.<\/p>\n<div class=\"green-highlight\">\n<p><strong>Example<\/strong>: Every day there are reports of security vulnerabilities that need to be patched. Take Microsoft <a href=\"https:\/\/thenextweb.com\/security\/2019\/09\/24\/microsoft-issues-emergency-windows-patch-to-address-internet-explorer-zero-day-flaw\/\">for example<\/a>.<a href=\"#_ftn9\" name=\"_ftnref9\"><sup>[9]<\/sup><\/a><\/p>\n<p><strong>Fix<\/strong>: Set aside time for updates \u2013 they are important. Use the time to organize your desk or get some face time with colleagues.<\/p>\n<\/div>\n<h6>8. Back up your files.<\/h6>\n<p>We\u2019re increasingly hearing stories of government departments, municipalities, hospitals and other critical institutions falling victim to ransomware attacks. This is when a hacker blocks access to your files, systems, and saved information until a ransom is paid.<\/p>\n<div class=\"green-highlight\">\n<p><strong>Example<\/strong>: A 2018 <a href=\"https:\/\/www.govtech.com\/security\/What-Can-We-Learn-from-Atlanta.html\">ransomware attack<\/a><a href=\"#_ftn10\" name=\"_ftnref10\"><sup>[10]<\/sup><\/a> in Atlanta, Georgia impacted City Hall and law enforcement departments for nearly five days. In 2019, <a href=\"https:\/\/www.bbc.com\/news\/technology-49905226\">three hospitals<\/a><a href=\"#_ftn11\" name=\"_ftnref11\"><sup>[11]<\/sup><\/a> in Alabama had to turn away patients.<\/p>\n<p><strong>Fix<\/strong>: Regularly back up your files, preferably with both a cloud provider and an external physical storage device. Disconnect the backups from the computer and the network, and remember to check that your systems can recover from those backups. This is especially important for those working with irreplaceable, private, or time-sensitive information in places like government offices, medical professions, and critical infrastructure.<\/p>\n<\/div>\n<hr \/>\n<p class=\"small-text\"><strong>Endnotes<\/strong><\/p>\n<p class=\"small-text\"><a href=\"#_ftnref1\" name=\"_ftn1\">[1]<\/a> <a href=\"https:\/\/www.businessinsider.com\/hackers-stole-a-casinos-database-through-a-thermometer-in-the-lobby-fish-tank-2018-4\">https:\/\/www.businessinsider.com\/hackers-stole-a-casinos-database-through-a-thermometer-in-the-lobby-fish-tank-2018-4<\/a><\/p>\n<p class=\"small-text\"><a href=\"#_ftnref2\" name=\"_ftn2\">[2]<\/a> <a href=\"https:\/\/www.bloomberg.com\/news\/articles\/2019-04-10\/is-anyone-listening-to-you-on-alexa-a-global-team-reviews-audio\">https:\/\/www.bloomberg.com\/news\/articles\/2019-04-10\/is-anyone-listening-to-you-on-alexa-a-global-team-reviews-audio<\/a><\/p>\n<p class=\"small-text\"><a href=\"#_ftnref3\" name=\"_ftn3\">[3]<\/a> <a href=\"https:\/\/www.internetsociety.org\/wp-content\/uploads\/2019\/04\/smart-device-checklist.pdf\">https:\/\/www.internetsociety.org\/wp-content\/uploads\/2019\/04\/smart-device-checklist.pdf<\/a><\/p>\n<p class=\"small-text\"><a href=\"#_ftnref4\" name=\"_ftn4\">[4]<\/a> <a href=\"https:\/\/www.internetsociety.org\/wp-content\/uploads\/2019\/04\/iotchecklist.pdf\">https:\/\/www.internetsociety.org\/wp-content\/uploads\/2019\/04\/iotchecklist.pdf<\/a><\/p>\n<p class=\"small-text\"><a href=\"#_ftnref5\" name=\"_ftn5\">[5]<\/a> <a href=\"https:\/\/www.forbes.com\/sites\/kateoflahertyuk\/2019\/04\/21\/these-are-the-worlds-most-hacked-passwords-is-yours-on-the-list\/#666b4f82289c\">https:\/\/www.forbes.com\/sites\/kateoflahertyuk\/2019\/04\/21\/these-are-the-worlds-most-hacked-passwords-is-yours-on-the-list\/#666b4f82289c<\/a><\/p>\n<p class=\"small-text\"><a href=\"#_ftnref6\" name=\"_ftn6\">[6]<\/a> <a href=\"https:\/\/twofactorauth.org\/\">https:\/\/twofactorauth.org\/<\/a><\/p>\n<p class=\"small-text\"><a href=\"#_ftnref7\" name=\"_ftn7\">[7]<\/a> <a href=\"https:\/\/www.consumer.ftc.gov\/articles\/how-recognize-and-avoid-phishing-scams\">https:\/\/www.consumer.ftc.gov\/articles\/how-recognize-and-avoid-phishing-scams<\/a><\/p>\n<p class=\"small-text\"><a href=\"#_ftnref8\" name=\"_ftn8\">[8]<\/a> <a href=\"https:\/\/time.com\/3639907\/sony-hack-data-security\/\">https:\/\/time.com\/3639907\/sony-hack-data-security\/<\/a><\/p>\n<p class=\"small-text\"><a href=\"#_ftnref9\" name=\"_ftn9\">[9]<\/a> <a href=\"https:\/\/thenextweb.com\/security\/2019\/09\/24\/microsoft-issues-emergency-windows-patch-to-address-internet-explorer-zero-day-flaw\/\">https:\/\/thenextweb.com\/security\/2019\/09\/24\/microsoft-issues-emergency-windows-patch-to-address-internet-explorer-zero-day-flaw\/<\/a><\/p>\n<p class=\"small-text\"><a href=\"#_ftnref10\" name=\"_ftn10\">[10]<\/a> <a href=\"https:\/\/www.govtech.com\/security\/What-Can-We-Learn-from-Atlanta.html\">https:\/\/www.govtech.com\/security\/What-Can-We-Learn-from-Atlanta.html<\/a><\/p>\n<p class=\"small-text\"><a href=\"#_ftnref11\" name=\"_ftn11\">[11]<\/a> <a href=\"https:\/\/www.bbc.com\/news\/technology-49905226\">https:\/\/www.bbc.com\/news\/technology-49905226<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>For many of us the Internet is a staple in our day-to-day lives \u2013 especially at our jobs. But did you know that by simply connecting your device to WiFi or delaying computer and software updates can put you and your workplace at risk of a cyberattack?<\/p>\n","protected":false},"author":46,"featured_media":0,"template":"","categories":[30,95,4738],"tags":[],"region_news_regions":[5931],"content_category":[6090],"ppma_author":[4057],"class_list":["post-106984","resources","type-resources","status-publish","hentry","category-trust","category-iot","category-security-1","region_news_regions-global","resource_types-resource","content_category-resources-type"],"acf":[],"uagb_featured_image_src":{"full":false,"thumbnail":false,"medium":false,"medium_large":false,"large":false,"1536x1536":false,"2048x2048":false,"post-thumbnail":false,"square":false,"gform-image-choice-sm":false,"gform-image-choice-md":false,"gform-image-choice-lg":false},"uagb_author_info":{"display_name":"Ivana Trbovic","author_link":"https:\/\/www.internetsociety.org\/author\/trbovic\/"},"uagb_comment_info":0,"uagb_excerpt":"For many of us the Internet is a staple in our day-to-day lives \u2013 especially at our jobs. But did you know that by simply connecting your device to WiFi or delaying computer and software updates can put you and your workplace at risk of a cyberattack?","_links":{"self":[{"href":"https:\/\/www.internetsociety.org\/wp-json\/wp\/v2\/resources\/106984","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.internetsociety.org\/wp-json\/wp\/v2\/resources"}],"about":[{"href":"https:\/\/www.internetsociety.org\/wp-json\/wp\/v2\/types\/resources"}],"author":[{"embeddable":true,"href":"https:\/\/www.internetsociety.org\/wp-json\/wp\/v2\/users\/46"}],"wp:attachment":[{"href":"https:\/\/www.internetsociety.org\/wp-json\/wp\/v2\/media?parent=106984"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.internetsociety.org\/wp-json\/wp\/v2\/categories?post=106984"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.internetsociety.org\/wp-json\/wp\/v2\/tags?post=106984"},{"taxonomy":"region_news_regions","embeddable":true,"href":"https:\/\/www.internetsociety.org\/wp-json\/wp\/v2\/region_news_regions?post=106984"},{"taxonomy":"content_category","embeddable":true,"href":"https:\/\/www.internetsociety.org\/wp-json\/wp\/v2\/content_category?post=106984"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/www.internetsociety.org\/wp-json\/wp\/v2\/ppma_author?post=106984"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}