Create your own
Lesson illustration

Identifying Workplace Security Risks and Unsafe Practices

Welcome back. In the previous lesson, you examined harmful insider actions—sabotage, theft, unauthorised access, and accidental disclosure—and linked each action to the asset affected and the impact on confidentiality, integrity, or availability.

This lesson moves one step earlier in the chain: what allows these incidents to happen? You will learn to spot unsafe staff practices and weak organisational security measures in workplace scenarios. This is a key distinction-level skill because strong answers do not merely say “the employee made a mistake”; they identify the specific behaviour, explain the missing or weak control, and show how both increased the risk.


Two things to identify in every scenario

A workplace cybersecurity scenario often contains two connected problems:

  1. An unsafe staff practice — something a person does, fails to do, or ignores.
  2. A weak organisational security measure — a missing, badly configured, poorly enforced, or insufficient control.

For example:

A staff member leaves a laptop unlocked in a shared office. Another person accesses customer records.

  • Unsafe staff practice: Leaving the device unlocked.
  • Weak organisational measure: Perhaps no screen-lock policy, weak staff training, no automatic screen lock, or poor physical access control in the shared office.
  • Possible impact: Confidentiality of customer records is lost.

Do not assume that every incident proves a control was completely absent. An employee may ignore a perfectly reasonable policy. In an exam answer, use careful wording:

  • “This suggests that staff training was ineffective or not followed.”
  • “The organisation may lack an enforced screen-lock policy.”
  • “The automatic lock period may be too long.”
  • “The control did not prevent or quickly detect the unsafe action.”

This is more accurate than claiming “there was no security at all.”

The National Cyber Security Centre poster shows four connected areas of workplace security: strong passwords, phishing awareness, device security, and prompt incident reporting. These are common areas in which unsafe staff behaviour and weak organisational controls can combine.

A useful distinction is:

TypeMeaningExample
Unsafe staff practiceAn individual’s insecure behaviour.Sharing a password with a colleague.
Weak organisational security measureA control that is absent, inadequate, misconfigured, or not enforced.No multi-factor authentication, shared accounts allowed, and no password policy enforcement.
Threat/attackThe harmful event or attempted event.An attacker uses the shared password to access payroll data.
ImpactThe resulting harm.Personal data breach, fraud risk, investigation costs, loss of trust.

A phishing email itself is not an unsafe staff practice: it is an external threat. Clicking its link without checking it, however, is an unsafe staff practice. If the organisation provides no training, filtering, reporting route, or multi-factor authentication, those are weak measures that make a successful attack more likely or more damaging.


Common unsafe staff practices

Unsafe practice is not limited to deliberate wrongdoing. It is often rushed, careless, or based on a misunderstanding of security procedures. The following categories appear frequently in BTEC-style scenarios.

1. Weak password and account behaviour

Examples include:

  • using short, predictable passwords such as names, dates of birth, or keyboard patterns;
  • reusing one password across personal and work accounts;
  • writing passwords on paper beside a monitor;
  • saving passwords in an unprotected document;
  • sharing an account or password with a colleague;
  • approving a multi-factor authentication prompt without checking why it appeared.

These practices weaken authentication: the process of proving a user is really who they claim to be. Password sharing also destroys accountability. If three people use the same account, log records may show that an account made a change, but not which person made it.

2. Unsafe email and phishing behaviour

Examples include:

  • clicking a link because the message looks urgent;
  • opening an unexpected attachment;
  • entering credentials on a website reached from an email link;
  • trusting a message just because it uses familiar branding;
  • paying an invoice after only an emailed request rather than independently verifying it;
  • failing to report a suspicious message.

Phishing relies on social engineering: manipulating someone into acting before they carefully check the situation. Urgency, authority, fear, and familiarity are common tactics.

Information Security Awareness Employee Training: Protect Your Company's Data and Reputation

Watch “Information Security Awareness Employee Training: Protect Your Company's Data and Reputation” from Vyond. It gives a short overview of why technical controls alone are not enough when staff do not follow security procedures.

Watch the opening for the link between staff actions, legal consequences, and reputational damage. Then watch unsafe examples, noting the unlocked screen, exposed file, and social-engineering phone call. Finish with safer habits; treat these as controls that an organisation should support through policy, training, and technical enforcement.

3. Leaving devices, documents, or information exposed

A device is not secure merely because it is inside an office. Unsafe behaviour includes:

  • walking away from an unlocked computer;
  • leaving a phone, laptop, or USB drive unattended;
  • leaving confidential papers on a printer;
  • throwing sensitive paperwork into normal waste rather than securely disposing of it;
  • displaying confidential records while travelling or working in a public space;
  • discussing confidential work where unauthorised people can hear;
  • sharing a screen in an online meeting while private documents, notifications, or passwords are visible.

These can create accidental disclosure without any sophisticated hacking. If an unauthorised person can simply read a screen, collect a printout, or use an unlocked device, the organisation has lost control of confidential information.

4. Unsafe software and device behaviour

Employees can also increase risk by:

  • delaying operating-system or application updates;
  • installing unapproved software, browser extensions, or mobile apps;
  • disabling security software because it is inconvenient;
  • using personal USB drives or cloud-storage accounts for work files;
  • connecting to insecure public Wi-Fi without an approved secure connection;
  • using an unmanaged personal device to store customer or business data.

Some of these actions may be deliberate policy breaches; others happen because the employee is trying to work quickly. Either way, they can introduce malware, expose data, or create systems the organisation cannot monitor or update.

5. Failing to report an error or warning

A mistake becomes much more serious when it is hidden or ignored. Examples include:

  • deleting a suspicious email instead of reporting it;
  • not reporting that a device has been lost;
  • ignoring an antivirus or security alert;
  • waiting until the end of the day to report a suspected breach;
  • assuming that somebody else will deal with a warning;
  • hiding an error through fear of blame.

Fast reporting does not undo an incident, but it can allow the organisation to reset passwords, disable an account, isolate a device, remove public access to a file, or contact a mistaken email recipient. This limits the scale of the harm.


Organisational controls: preventing, detecting, and limiting harm

Staff should behave securely, but an organisation must not place all responsibility on individuals. Good cybersecurity uses layers of defence. If one layer fails, another should prevent a small mistake from becoming a major incident.

Practical ways to keep your IT systems safe and secure

Read the Information Commissioner’s Office guidance to connect everyday staff behaviours with practical organisational controls for protecting personal and business information.

In the numbered sections from “1. Back up your data” to “11. Dispose of old IT equipment and records securely,” read the practical guidance. Focus especially on password and multi-factor authentication, suspicious emails, unattended devices, least-privilege access, screen sharing, backups, and secure disposal. For each measure, notice whether it mainly prevents an incident, detects it, or reduces its impact.

The most useful controls for identifying weaknesses in a scenario are below.

Security areaStrong organisational measureWeakness to identify in a scenario
PasswordsPassword policy, unique strong passwords, password manager support, multi-factor authentication.Staff can use simple passwords; accounts have no multi-factor authentication; passwords are shared.
Access controlIndividual accounts, least privilege, role-based permissions, prompt removal of leavers’ accounts.All staff can access HR or payroll folders; former employees still have active accounts.
DevicesAutomatic screen lock, encrypted laptops, approved software, updated operating systems.Devices remain unlocked; software updates are ignored; personal devices are unmanaged.
Malware defenceUpdated endpoint protection, restricted admin rights, safe download controls.Antivirus is out of date, alerts are ignored, or ordinary users can disable protection.
Email and phishingStaff training, email filtering, anti-spoofing controls, clear reporting procedure.No training, no phishing-report route, or staff are punished for reporting mistakes.
Data handlingClear-data classification, encryption, secure printing, clear-desk policy, secure disposal.Sensitive documents are left on printers; old devices are discarded without secure wiping.
Backup and recoveryRegular tested backups, stored separately from live systems.Backups are never tested or permanently connected to the main network.
Monitoring and responseSecurity logs, alert monitoring, an escalation procedure, timely investigation.Alerts are not reviewed, incident reports have no owner, or warnings are not acted upon.

Notice that controls have different purposes:

  • Preventive controls attempt to stop an incident: multi-factor authentication, permissions, email filtering, locked doors.
  • Detective controls identify that something may be wrong: alerts, logs, antivirus warnings, monitoring.
  • Corrective or recovery controls reduce damage after an event: incident response, isolated backups, password resets, restoring data.

A distinction-level answer often identifies more than one layer. For example, an employee opening a malicious attachment might be the immediate cause, but weak email filtering, no multi-factor authentication, excessive permissions, and ignored alerts may explain why the attacker was able to cause widespread damage.


Worked scenario: identify the full chain, not just one mistake

The ICO describes a real-world phishing compromise involving a construction company. An attacker sent an urgent-looking email to an accounts mailbox. One employee forwarded it, and the employee responsible for invoices downloaded a linked ZIP file, extracted it, and opened a script file. Malware was installed.

Phishing | ICO

Read the ICO’s phishing case study as a model for analysing how a staff mistake, technical design choices, and a weak response process can combine into a serious breach.

Under “Example: Phishing compromise leads to loss of personal information and a monetary penalty notice,” read the attack chain. Then, under “What could have been done differently?”, read the improvement list, followed by the “What might help reduce the risks from phishing?” section. Focus on the difference between an employee opening the malicious file and organisational weaknesses such as bypassed protection, excessive privilege, insufficient investigation, and inadequate training.

Here is how to analyse that scenario.

Evidence from the scenarioWhat to identifyWhy it matters
An employee downloaded and opened an unexpected ZIP file and script.Unsafe staff practice: The employee acted on a phishing email without adequate checking.Malware gained an initial foothold on the workstation.
The email was designed to look urgent.Phishing/social engineering: This explains how the employee was pressured into acting.It is an attack technique, not an excuse to ignore verification procedures.
The employee was using split tunnelling while working from home, bypassing the company internet gateway.Weak organisational measure: The remote-access configuration did not ensure web traffic went through the protective gateway.The organisation’s malicious-site restrictions did not protect this user in the normal way.
Endpoint protection reported that some malware files had been removed, but no further action was taken.Weak detection and response: A security warning was not properly investigated.The attacker kept access and had more time to move through the organisation.
The attacker compromised privileged accounts and removed antivirus software.Weak access control / least privilege: Privileged access was too widely available or insufficiently protected.The attacker could spread further, disable defences, and affect more systems.
HR databases were encrypted and unavailable.Impact: Availability was lost; confidentiality and integrity may also be at risk.The organisation could not use personal data, faced recovery work, and risked major operational and legal consequences.

A precise point matters here: opening the malicious file does not prove that all staff training was absent. The employee might have received training but failed to follow it. A well-supported answer would say that the event indicates training was insufficient, not remembered, or not reinforced by other controls.

The case also shows why blaming only the employee is a weak analysis. A strong organisation assumes that somebody may eventually click a convincing phishing message. It uses several layers to contain the error:

If all these layers are weak, a single unsafe action can develop into a large-scale breach.


A reliable method for scenario questions

When you see a workplace scenario, use this five-step method.

Step 1: Underline actions and omissions

Look for phrases such as:

  • “used the same password”
  • “left the laptop on the train”
  • “opened the attachment”
  • “shared their login”
  • “did not install updates”
  • “ignored the warning”
  • “sent the spreadsheet to the wrong address”
  • “still had access after leaving the company”

These are likely unsafe staff practices.

Step 2: Find the missing safety net

Then ask: What should the organisation have had in place to prevent, detect, or limit this?

Possible answers include:

  • multi-factor authentication;
  • staff training and phishing simulations;
  • restricted permissions;
  • encryption;
  • automatic screen locking;
  • antivirus and endpoint protection;
  • patch management;
  • email filtering;
  • secure disposal procedures;
  • an incident-reporting route;
  • timely review of security alerts.

Step 3: Explain the link

Do not list controls without connecting them to the scenario.

Weak:

The company should use multi-factor authentication and training.

Stronger:

Because the employee’s password was reused and exposed through phishing, multi-factor authentication could have reduced the chance that the attacker could access the account using the password alone. Training should also tell staff to verify unexpected password-reset emails through the normal company website rather than following the link.

Step 4: State the security objective and likely impact

Use confidentiality, integrity, and availability accurately.

  • Confidentiality: unauthorised viewing, copying, or disclosure.
  • Integrity: unauthorised changes, deletion, or corruption.
  • Availability: systems or data cannot be used when needed.

Then link this to realistic business harm: service disruption, recovery cost, fraud, legal investigation, loss of customer trust, or loss of intellectual property.

Step 5: Make a proportionate recommendation

Recommend measures that directly address the weakness. Avoid vague statements such as “improve cybersecurity.”

For example:

The organisation should give each worker an individual account, remove shared credentials, and use role-based permissions. This would improve accountability because logs could link actions to a specific person, while least privilege would reduce the amount of payroll data exposed if one account were compromised.


Key takeaways

  • An unsafe staff practice is insecure behaviour by an individual, such as sharing a password, opening a suspicious attachment, leaving a device unlocked, or failing to report a warning.
  • A weak organisational security measure is a missing, inadequate, poorly configured, or unenforced control, such as no multi-factor authentication, excessive access rights, outdated protection, or no reporting process.
  • A successful incident often results from both: a staff mistake creates an opening, while weak layers of defence allow the harm to spread.
  • For a high-quality BTEC response, identify the specific evidence, explain why it is unsafe, name the relevant missing or weak control, and link it to confidentiality, integrity, availability, and business impact.
  • Avoid overclaiming. One mistake may show that a policy was ignored or ineffective; it does not automatically prove that no policy existed.

Next, you will examine the motives of different threat actors—commercial, government, terrorist, and individual—and use those motives to make more convincing judgements about why an organisation may be targeted.

Can't find a good explanation? Sign up and we'll make it for you

Sign up