There is a moment in a company’s life when passing on a security rule costs almost nothing: a new employee’s first day.

That day, the person listens. They discover the tools, the house habits, the coffee machine and how files are organised. They have not yet invented their own way of getting around what annoys them. Whatever they are told settles in as the normal way of doing things.

Six months later, the same instruction becomes a correction. It arrives after the fact, targets a habit already formed, and is experienced as a reproach. The content is identical, the effect is not.

Why is day one so effective?

A new arrival has no reason to resist. They have no seniority to defend, no procedure they found more convenient before, no password they have been reusing on this particular tool for four years.

What they mostly observe is what the team does. If on the first day someone sets them up with a password manager and explains why, they will understand that this is how things are done here. If instead they are handed a shared password on a piece of paper and told it is “simpler for now”, they will understand that just as clearly.

Onboarding does not just pass on instructions. It passes on the company’s standard of rigour. This is the direct continuation of what we describe in our article on why raise your employees’ awareness: awareness-raising does not start at the first training session, it starts when the badge is handed over.

What needs to be settled on the first day?

Five points are enough. They fit into half an hour if the technical side has been prepared before the person arrives.

Accounts created with the right rights, and no more. Each person has a named account, never a shared one, and accesses only what their role needs. An accountant has no reason to open HR files, and a salesperson does not need administrator access to the server. This principle has a name, least privilege, and it is detailed in our article on access management.

Two-factor authentication enabled right away. This is the second identity check, usually a code on the phone, added to the password. Enabled on day one, it feels like a given. Imposed a year later, it feels like a new constraint. It is the measure that blocks the largest number of automated attacks, and we devote a full article to two-factor authentication.

The password manager installed and explained. This is a software vault that remembers passwords on the user’s behalf. Installed on day one, it prevents the person from getting into the habit of reusing their personal password on company tools. Once that habit is formed, it no longer goes away.

The IT policy handed over and explained. Not just signed. Three minutes are enough to say what is allowed on company equipment, what is not, and above all why. Our article on the IT policy details what it should contain.

Who to tell when in doubt. A name, a number, one sentence. “If a message seems odd to you, call me, even if you are wrong, even on a Sunday.” This is the shortest point on the list and the most cost-effective. An employee who knows who to turn to reports within ten minutes; one who hesitates reports the next day, or never.

The mistake that costs the most

It is not visible on the day it is made.

Access granted "for now" is never restricted

On the day someone arrives, no one knows exactly what they will need. To avoid holding them up, they are given broad access: every shared folder, administrator rights on their computer, sometimes an existing account lent to them. Everyone tells themselves they will restrict it later. That later never comes. Three years on, the person still holds rights they have never used, and these become a problem the day their account is compromised.

The opposite approach costs less. Open access sparingly, and add on request. An employee who has to ask for a missing access point costs you ten minutes. An overly broad account that gets hacked costs you far more, because the attacker inherits everything the person could reach, including what they never used.

Should trainees and temporary staff be treated differently?

This is the most common blind spot in SMEs.

Someone arrives for three months. Creating a dedicated account, setting up two-factor authentication and defining precise rights seems disproportionate for such a short period. So an existing account gets lent out, or a generic access point is opened that three successive trainees will pass along to one another.

Two consequences follow. First, the least trained person in the company ends up with someone else’s rights, often broader than their own. Second, nothing is traceable any more: if a file is deleted or an invoice goes to the wrong place, no one can say who did what.

Typical scenario: the account that survived

An SME takes on a summer trainee. Short on time, they hand over the access of an employee on maternity leave. The placement ends, and no one thinks to change the password. Eighteen months later, that password turns up in a data breach from a website unrelated to the company, where it had been reused. The access still works. This scenario is illustrative, but it describes a mundane chain of events: a temporary access point that was poorly closed remains exploitable for a very long time.

The rule is simple: any temporary access is named and carries an end date. The same precautions apply to external contractors, a subject we cover in our article on supply-chain attacks.

Leaving is the same list, in reverse

A well-prepared arrival is useless if the departure is rushed. Yet departures almost always happen under poor conditions: a busy last day, handover to complete, sometimes a tense separation.

The principle fits in one sentence. Everything opened on day one closes on the last day, not the following week. An account disabled on Friday evening is not excessive caution, it is basic hygiene, and this applies even to the most amicable departures.

StepOn arrivalOn departureWhen
AccountsCreate a named account, rights limited to the roleDisable all accounts, including online toolsDay 1 / last day
AuthenticationEnable two-factor authenticationRemove the trusted device, revoke sessionsDay 1 / last day
PasswordsInstall the password manager, explain its useChange shared passwords the person knewDay 1 / last day
EquipmentHand over the computer and phone, note serial numbersRecover the equipment, wipe professional accessDay 1 / last day
RulesExplain the IT policy and the reporting channelRemind them of confidentiality obligations that continue after the contractDay 1 / last day

This template can be reused as it is. Print it, tick it off, date it, and keep it in the employee’s file. Ticking the box is not just an administrative formality: it is what lets you know, six months later, whether the step was actually done or merely assumed to have been done.

Where the checklist is no longer enough

An onboarding template can be written in-house. You do not need anyone’s help to decide that a new employee receives a named account and that their account closes on the day they leave.

The hard part lies elsewhere, and it does not appear in the table. Deciding which rights to give to which role requires knowing what exists in the company and what is sensitive within it. How many online tools are actually in use, including those subscribed to directly by a department without going through management? Which folders hold data whose disclosure would cause a real problem? What access does a contractor currently still hold?

Few SMEs can answer these questions from memory. This is not a failure of organisation, it is the normal outcome of ten years of activity, tools added as needs arose, and people who have come and gone. An inventory of access points almost always turns up surprises, and it works better with an outside perspective, because that perspective does not assume it already knows what is supposed to be there.

These measures form a solid foundation, they do not replace a review of your actual situation. To gauge your current level, the cyber check-up devotes several questions to account and departure management. The other awareness topics are grouped under the Training pillar.