About this module
Your work devices are gateways into your company's systems, and this device security training module sets out the five rules that keep them secure.
You'll build the half-second habit of locking your screen every time you step away, learn why every deferred update is a day of exposure to a known exploit, and see how unauthorized software bypasses your company's security scanning.
You'll also check that full-disk encryption is protecting your data if a device is stolen, and learn why a lost laptop must be reported in minutes, not hours, while remote wipe is still possible. Five rules, every device, every day.
Key takeaways
Your work laptop, phone, and tablet are company assets containing sensitive data. How you treat them, at your desk, at home, and on the road, determines whether they stay secure. Five rules.
No exceptions.
Rule one: lock your screen every single time you step away from your device. Use Win+L on Windows or Cmd+Control+Q on Mac, it takes half a second.
An unlocked laptop in an open office, a café, or a conference room is an instant vulnerability. Anyone passing by can access your files, your email, your applications.
Make locking automatic. Build the muscle memory today.
Rule two: install security updates the moment they're available. Software patches close vulnerabilities that attackers are actively exploiting. Every day you defer an update is a day you're exposed to a known risk.
Enable automatic updates, and when I.T. pushes an update, apply it promptly, don't delay it two weeks by clicking 'remind me later'.
Rule three: never install software that I.T. hasn't approved. This includes browser extensions, free utilities, file converters, media players, and anything a colleague forwards you.
Unauthorized software bypasses your company's security scanning. It can contain malware, open backdoors, or exfiltrate data, often without any visible sign.
If you need a tool, request it through I.T.. If they say no, there's a reason.
Rule four: ensure full-disk encryption is active on your laptop and any external drives containing work data. If your device is stolen and encrypted, the thief gets hardware, not data.
Check with I.T. that BitLocker or FileVault is enabled. For external drives, use only I.T.-approved encrypted drives. Never store sensitive work data on a personal USB stick.
Rule five: if your work device is ever lost or stolen, report it to I.T. security immediately, not after you've searched for an hour, not the next morning.
Remote wipe is only possible while there's time. Every minute of delay is a minute a thief potentially has to access your device. I.T. can lock the device, wipe it remotely, and revoke access, but only if you tell them fast.
Five rules: lock your screen every time you step away. Update software without delay. Only install I.T.-approved software.
Encrypt sensitive files and drives. Report any loss immediately.
Every device. Every day. Lock your screen.
Apply updates promptly. Report loss immediately. Your work device is a gateway into your company's systems: treat it that way.



