Cyvora / Cyber Learning Hub
Cyber security awareness checklist
Make security practical: pause before acting, protect account access and know how to report a concern.
Everyday habits for individuals and teams
By Cyvora · Published and updated 6 October 2026
01 / Accounts and sign-in
Use a different strong passphrase or password for each account and consider a reputable password manager. Enable multi-factor authentication where available. Never share passwords or approve an unexpected sign-in prompt.
02 / Messages and payment requests
Pause when a message creates urgency or asks you to change payment details, share a code or open an unexpected attachment. Verify important requests through a trusted contact method you already know, rather than details supplied in the message.
03 / Devices and information
Keep devices and software updated. Lock your screen and restrict access to sensitive information. Before sharing a document, check the recipient, permissions and whether the information is needed.
04 / AI and collaboration tools
Use approved tools for work. Do not paste confidential business information or personal information into an AI service without understanding its approved use and data handling. Review generated output before relying on it.
05 / Reporting and reinforcement
Know the reporting path for suspicious messages, lost devices and unusual account activity. Encourage early reporting without blame. Practise with short, role-relevant scenarios and revisit the habits regularly.
Practise: an unexpected payment change
A message appears to come from a supplier and asks you to use a new bank account for an invoice. The practical action is to pause and verify the change using a contact method your organisation already trusts. Do not rely on the phone number or link in the message. Follow your payment approval process and report the message through your agreed channel if anything seems unusual.
Questions for a team discussion
- Who can approve a change to supplier payment details?
- Where can staff find a trusted supplier contact?
- How can someone report a concern without delaying an urgent business task?
Use the answers to improve the process as well as the training. A staff member needs a workable path for checking a request, not just an instruction to be careful.
Choose your next step
Use the business cyber security checklist to connect these habits to account access, recovery and ownership. Organisations planning a structured program can explore cyber security awareness and role-specific training. Review AI security assessment scope where AI tools handle business information.
Continue learning
This is a general starting point. Adapt the actions to your environment and responsibilities.
Read the official supporting guidance