8.6 Workplace Security Risks: Theft, Equipment Damage, Cyber Crime & Password Practices
Key Takeaways
Workplace security risks include theft of data, materials, or equipment, deliberate or careless damage, and cyber crimes such as phishing, business email compromise, and ransomware.
Payroll diversion fraud uses fake emails that appear to come from employees asking HR or payroll to change bank details, so every change should be verified through a known, separate channel.
NIST SP 800-63B-4 guidance requires single-factor passwords to be at least 15 characters, favors length over forced complexity, and says not to force periodic password changes without evidence of compromise.
HR reduces insider risk by granting least-privilege access at hire, adjusting it at transfer, revoking it promptly at exit, and recovering all equipment.
Under the GDPR, a personal data breach must generally be reported to the supervisory authority within 72 hours of the employer becoming aware of it, unless it is unlikely to result in a risk to individuals.
Workplace Security Risks: Theft, Equipment Damage, Cyber Crime & Password Practices
Quick Answer: The aPHRi outline lists security risks in the workplace (for example, data, materials, or equipment theft; equipment damage or destruction; cyber crimes; password usage). HR matters here for two reasons: HR holds some of the most sensitive data in the organization (identity, bank, pay, and health information), and HR controls people processes - hiring checks, access at onboarding and exit, policies, training, and discipline - that prevent or detect insider threats. Good practice combines clear policies, least-privilege access, verification procedures, strong authentication, training, and fast incident reporting.
Section 8.5 covers physical security design and violence prevention. This section focuses on theft, damage, and cyber risks, and on the practical steps an early-career HR professional must follow.
1. Types of Security Risk
| Risk | Examples | Who may be responsible |
|---|---|---|
| Data theft | Copying customer or employee files to a personal drive, selling data to a competitor | Insiders or external attackers |
| Material and inventory theft | Stock or supplies taken from warehouses or shops | Employees, contractors, visitors |
| Equipment theft | Laptops, phones, tools, or vehicles stolen from offices, cars, or homes | Opportunistic thieves or insiders |
| Equipment damage or destruction | Careless handling, vandalism, or sabotage by a disgruntled employee | Insiders or outsiders |
| Cyber crime | Phishing, business email compromise, ransomware, account takeover | Mostly external criminals, sometimes helped by insider mistakes |
| Time and expense fraud | False timesheets or expense claims | Insiders |
An insider threat is a risk from people with legitimate access: current or former employees, contractors, or partners. It can be malicious (deliberate theft or sabotage) or accidental (a lost laptop or a clicked phishing link).
2. Cyber Crimes that Target HR
- Phishing: emails or messages that trick people into clicking malicious links, opening infected attachments, or entering passwords on fake login pages. Spear phishing targets specific people, such as HR staff, using personal details.
- Business email compromise (BEC): criminals impersonate an executive, supplier, or employee to request payments or sensitive data.
- Payroll diversion fraud: a message that appears to come from an employee asks HR or payroll to change the employee's bank account "before the next payday." The next salary goes to the criminal.
- Employee data requests: fake "executive" emails asking for a file of all employees' identity numbers, salaries, or tax forms.
- Fake job postings and recruitment scams: criminals pose as the employer to collect applicants' personal data or fees.
- Ransomware: malware that encrypts files, including HR systems, and demands payment.
Verification procedures that stop fraud
- Never change bank details based on email alone. Confirm through a separate, known channel (for example, calling the employee on the number already on file or asking them to change details themselves in the secure HRIS portal).
- Verify unusual requests for bulk personal data directly with the requester through a known channel, and check that the request is authorized.
- Look for warning signs: urgency, secrecy, a slightly different email address, requests to bypass normal steps, or pressure from a supposed executive.
- Report suspected phishing to IT security instead of deleting it silently.
3. Password and Authentication Practices
Weak or reused passwords are a leading cause of account compromise. The United States National Institute of Standards and Technology (NIST) published updated digital identity guidelines, SP 800-63B-4, which many organizations worldwide use as a reference. Key points:
- Length over complexity: passwords used as the only authentication factor must be at least 15 characters; passwords used within multi-factor authentication must be at least 8. Long passphrases are encouraged, and systems should allow at least 64 characters.
- No arbitrary composition rules: do not force mixtures of symbols, numbers, and capitals; they lead to predictable patterns.
- No forced periodic changes: do not require routine password changes unless there is evidence of compromise.
- Block weak passwords: check new passwords against lists of common or previously breached passwords.
- Use multi-factor authentication (MFA), preferably phishing-resistant methods, for HR systems that hold sensitive data.
Employee behaviors HR should reinforce through policy and training:
- Never share passwords or MFA codes, even with IT or a manager.
- Use a different password for each system, ideally stored in an approved password manager.
- Lock screens when away, and never write passwords on notes near the computer.
- Report any suspected account compromise immediately.
4. Protecting Equipment and Materials
- Asset register: record each laptop, phone, tool, and vehicle, with a tag number and the employee it is issued to.
- Sign-out and return: employees acknowledge receipt and responsibility; items are checked back in at transfer or exit.
- Physical controls: locked storage, access badges, CCTV where lawful and proportionate (Section 3.4), and inventory counts.
- Device protection: encryption, remote locking and wiping of lost devices, and rules for traveling with equipment.
- Clean desk and secure printing: no confidential documents left out; collect printouts promptly.
5. HR's People Controls Across the Employee Lifecycle
| Stage | Control |
|---|---|
| Hiring | Job-related background checks for sensitive roles (Section 6.3); confidentiality agreements |
| Onboarding | Least-privilege access (only what the role needs); security and acceptable-use training; equipment sign-out |
| Transfer | Remove access the old role needed and grant only what the new role needs |
| During employment | Regular refresher training, phishing simulations, access reviews, and clear reporting routes |
| Exit | Revoke access on or before the last day (immediately for a high-risk dismissal), recover equipment and badges, remind the employee of continuing confidentiality duties (Section 8.1) |
Access that is never removed after transfers ("access creep") and accounts left active after people leave are two of the most common insider-risk gaps.
6. Responding to a Security Incident
- Report immediately to IT security or the designated incident contact.
- Contain: for example, disable a compromised account or disconnect an infected device, following IT instructions.
- Preserve evidence: do not delete emails or files; keep logs and records.
- Assess personal data impact: if employee or candidate data is affected, the privacy team decides on notifications. Under the GDPR, a personal data breach must generally be notified to the supervisory authority within 72 hours of becoming aware of it (unless unlikely to result in a risk to individuals), and affected people must be told without undue delay when the risk to them is high.
- Investigate fairly if an employee may be responsible (Section 7.2), and apply discipline consistently.
- Learn: update controls and training.
Scenario
An email that looks like it comes from a sales employee asks payroll to switch the salary account to a new bank "urgently, today." The payroll assistant calls the employee on the phone number in the HRIS and learns the employee sent no such request. The assistant reports the email to IT security, which blocks the sender and warns staff. A single verification call prevented the loss of a month's salary and protected the employee's data.
Payroll receives an email that appears to be from an employee, asking to change the bank account for this month's salary. What is the correct response?
Make the change immediately because the email includes the employee's name.
Reply to the email asking the sender to confirm the request.
Verify the request through a separate, known channel, such as calling the employee on the number on file or having them update details in the secure portal.
Forward the email to the whole department to ask whether anyone knows the sender.
An IT policy requires 8-character passwords with a symbol and forces every employee to change passwords every 60 days. Based on NIST SP 800-63B-4 guidance, which change would improve it?
Shorten passwords to 6 characters so they are easier to remember.
Require longer passphrases (at least 15 characters when a password is the only factor), drop forced periodic changes unless there is evidence of compromise, and add multi-factor authentication.
Require employees to share passwords with their managers for emergencies.
Force changes every 30 days instead of every 60 days.
An audit finds that several employees who transferred between departments still have access to their old department's confidential files. What does this indicate, and what should HR and IT do?
Access creep; remove access the new roles do not need and add an access review to the transfer process.
Nothing, because employees who stay with the company can be trusted with all files.
A payroll error; adjust their salaries.
A reason to dismiss the transferred employees immediately.
Sections you finish are checked off in the contents.