Getting the onboarding of new hires right can be a challenge, but one that, if answered well, can lead to a new employee fitting in and being a productive part of the team.
Getting it wrong, however, can lead to all manner of poor outcomes, and not necessarily in terms of performance and employee satisfaction – it can also potentially open the door for hackers and other cyber criminals.
“New joiners, especially those in their first job, haven't yet developed an instinct for what looks suspicious. They might struggle to identify phishing emails, fake login pages, bogus password reset requests, fake IT help desk messages, and malicious attachments disguised as onboarding documents,” Karolis Arbaciauskas, head of product at cyber security firm NordPass and its parent organisation Nord Security, said in a statement.
“The first few weeks, before cybersecurity training kicks in, are the most dangerous because newcomers are more likely to make mistakes and follow instructions without asking too many questions.”
One of the most egregious mistakes – and most common – is the use of temporary passwords built around a consistent model and which, once known, can make guessing other passwords incredibly easy. Making matters worse, these credentials are often shared via emails or text messages, and sometimes included on sticky notes attached to new staff laptops.
These may seem like easy methods to onboard new hires, but they add greatly to the risk of credential theft.
“Those first-day credentials are often simple and created using a company name, new employee name, or an easy-to-remember phrase, like ‘Welcome2026,’ because they're meant to be changed,” Arbaciauskas said.
“Unfortunately, those temporary credentials often become permanent and get reused across accounts. It's best to generate unique credentials, deliver them through a secure channel, such as a password manager, and force a reset on first login.”
Here are another five common onboarding habits to avoid:
- Giving new hires broad or administrative access instead of applying the principle of least privilege.
- Failing to promptly revoke access when employees change roles or leave, including during probation.
- Waiting weeks to provide phishing and cyber hygiene training – or skipping security awareness training altogether.
- Failing to give new employees clear guidance on acceptable technology use, data handling, and reporting suspicious activity.
- Allowing personal devices onto corporate networks without appropriate endpoint security or mobile device management.
Want to see more stories from trusted news sources?Make Cyber Daily a preferred news source on Google.