Skip to content
COR Intelligence
Back to latest

Staff tech essentials: the minimum every UK business should provide

Pete Gypps20 May 2026 · updated 27 August 2026
6 min read1,157 words

A short, opinionated list of the security and tooling decisions every employer owes their staff in 2026. Phishing training, password managers, the no-emailed-link rule, and MFA explained plainly for people who don’t spend their day thinking about this.

A clean desk with a laptop and phone, the two devices most office staff use to authenticate every day
The two devices most office work passes through every day. Both need a process.

When a UK business hires someone, the employer hands over kit, a logon, and an email address. What gets handed over less reliably is the bit that actually keeps the business safe, the training and tooling that turns the new starter from "another attack surface" into "a member of staff who knows what to do when an email looks wrong".

This piece is the minimum we think every UK employer should provide. It is not exhaustive. It is the bar.

1. Phishing awareness training

The single biggest source of business losses we see (invoice fraud, mailbox takeover, ransomware) starts with an email someone in the office opened and acted on. Training does not need to be a half-day workshop. It needs to be ten minutes of "here is what a phishing email looks like, here is the forward-button check that catches most of them, and here is who to tell if you think you got one".

We wrote about the forward-button trick and the rules around it separately, that piece is worth handing to every new starter on day one. Phishing training stops being optional the day you hire your first employee.

2. A sanctioned password manager

Reused passwords across a dozen sites is how a small breach at one supplier turns into a full takeover of your business. The fix is a password manager that generates and remembers unique passwords for every account. Nobody can do this in their head; everybody should have a tool that does it for them.

Three sensible paths, depending on the business:

  • If you run Microsoft 365: Microsoft Edge with the staff member signed in to their work Microsoft account. Edge will securely back up website usernames and passwords to their work account. Free, included, and the work credentials stay tied to a work-managed identity, when they leave, you revoke the account and the passwords go with it.
  • If you run Google Workspace: Google Chrome with the staff member signed in to their work Google account. Same model, same security guarantees. Works exactly the same way Edge does for the Microsoft camp.
  • If you want a single tool independent of your email provider (or you want stronger features like secure sharing across the team) a third-party manager such as 1Password, Bitwarden or Dashlane. Pick one, pay for the team plan, get it onto every device on day one.

This is the simplest possible rule a staff member can learn, and it defeats most phishing on its own. The rule: never log in to anything by clicking a link in an email. Ever.

If the email says you need to log in somewhere, open a fresh browser tab, type the website address you already know, and log in from there. The link in the email might be fake. The website you typed isn’t.

The rule that defeats most phishing on its own

This applies to "your password is about to expire", "your account has been suspended", "you have a new invoice", "your colleague shared a document", the whole list. The rule is the same: do not click the link. Go to the website yourself. If the notification was real, it will be there waiting for you.

Train this once. Repeat it whenever a new starter joins. Write it on the staff handbook page. It is the highest-return security training your business will ever do, and it takes thirty seconds to explain.

4. MFA, and what it actually means

MFA stands for "multi-factor authentication". 2FA is the same idea ("two-factor"). The acronyms are dull and put people off. The idea is not.

In practice, this means: after you type your password, the website asks for a six-digit code that arrived as a text message, or appeared in an app on your phone (Microsoft Authenticator, Google Authenticator, or a built-in one inside 1Password). Sometimes it is a fingerprint or face unlock on the phone instead of a code. Either way, an attacker who steals your password from a data breach still cannot log in unless they also have your phone in their hand. That is the whole point.

It adds about ten seconds to logging in. Those ten seconds are the difference between a leaked password being inconvenient and a leaked password being a six-figure recovery operation.

Where to turn MFA on

Turn it on everywhere it is available. As a minimum:

  • Email: Microsoft 365 and Google Workspace both support MFA. Make it mandatory across the business. This is the most important single account to protect; nearly every other account can be reset via email, so an attacker with your email has everything.
  • Banking: every UK bank offers MFA. Turn it on.
  • Anything that handles money: Stripe, PayPal, your accounts package, payroll, HMRC.
  • Anything that handles client data: the CRM, the file-share, the case management system.
  • Social media: especially anything tied to the business name. A hijacked company LinkedIn is a long week.
  • Domain registrar and DNS: losing control of your domain is losing control of your email and your website.

For a more secure setup, recommended for the business owner and anyone with admin rights to the email or finance systems, use a physical hardware key (YubiKey is the common one) instead of, or in addition to, the phone app. Costs about £45 per key. Worth it for the small number of accounts that, if lost, end the business.

Make it a handbook, not a memo

The four items above (phishing training, a sanctioned password manager, the no-emailed-link rule, MFA everywhere) are the bar. They are not optional. They are not "we’ll get round to it". They are the contents of the staff tech handbook every UK business should hand a new starter on day one alongside the laptop and the door key.

These four basics will not stop every attack. Nothing does. They will stop the attacks that put small UK businesses out of pocket every week, and they will mean that when something gets through anyway, your staff know who to tell, what to switch off, and what your business expects of them. That is the bar to clear.

Useful? See more of us on Google.

One click adds COR Intelligence to your preferred sources in Search and its AI features.

Read next

More from COR Intelligence