10 ways to keep your employees safe online
Ten practical controls and habits that cut day-to-day risk, ordered by how much difference they make.
By the Telappliant team

Staff are not the weakest link; they are the largest attack surface, which is a different problem with a different fix. These ten measures are ordered by impact, and every one is achievable in a small IT team.
The ten, in order of impact
- Multi-factor authentication on every account that faces the internet
- A password manager, so unique passwords stop being an aspiration
- Blocked legacy authentication and conditional access on Microsoft 365
- Patching within 14 days for critical fixes, on devices as well as servers
- No standing local administrator rights on user devices
- Managed endpoint protection with detection and response, not just antivirus
- Verified out-of-band checks before any payment or bank detail change
- Short, frequent awareness training with realistic phishing simulation
- A simple, blame-free way to report a suspected phishing email in one click
- Tested backups, held offline or immutable, with a restore rehearsed each year
Training that changes behaviour
Annual hour-long modules are forgotten by the following week. Five minutes a month, tied to a simulated phish that reflects what your sector actually receives, changes reporting rates within a quarter. Measure reporting speed, not just click rate: fast reports are what buy the response team time.
Make reporting effortless
A report button in Outlook that files the message with your security team removes the hesitation. Thank people for false alarms in public; the moment reporting feels risky, it stops.
Remote and hybrid specifics
- Company-managed devices wherever data is handled
- Encrypted disks and screen locks as enforced policy, not guidance
- A clear rule on personal devices and what is never allowed on them
- Guidance on home router basics and public Wi-Fi
What to measure
- Percentage of accounts with MFA enforced
- Median time to report a simulated phish
- Devices patched within the 14-day window
- Accounts still using reused or breached passwords
- Time to remove access for a leaver



