Printable reading version for individual or assisted learning

The Working Day

Workplace security awareness for UK small businesses.

Published by William Baptist | Tidy Desk Digital
Version 1.0.31 · Law and guidance checked 6 October 2026

This reading version supports reading or a route led by the person running the session. Read each scenario. If someone is helping you, you can read it aloud together. Choose an option, then follow its numbered next step. Discuss why the safer route helps. It does not record completion or replace an employer's local assessment arrangements.

Before use, agree the real reporting contact, urgent route, approved tools and payment/sharing processes. Scenarios are fictional. This does not give an officially recognised qualification or approval.

Open the interactive course

Contents

  1. Your workspace is part of security
  2. Read the request, not the polish
  3. Protect how you sign in
  4. Pressure does not replace permission
  5. New tool, new destination
  6. Keep protections in place
  7. Report early, report clearly
  8. Know your part, know the limits
  9. Task cards and possible outcomes
  10. Sources

Module 1

Your workspace is part of security

Learning goal: Choose an approved connection and a suitable place for work.

Start with the approved setup

Use your approved work device and connection. A public network can copy a trusted network name. Use the protected connection your workplace requires, but remember that it does not make every website or download safe.

  • Do not ignore warnings that the site's identity or connection cannot be trusted.
  • Do not install a file that changes device settings because a page asking you to join the network asks you to.
  • Ask your work computer support team for an approved alternative if the normal connection is unavailable.

Protect what people can see and hear

A protected connection does not stop someone reading your screen or hearing a customer call. Choose a place private enough for the information. Lock the screen when you step away.

  • Keep work devices with you or locked away. Do not leave them unattended in public.
  • Do not let someone else use a work device while you are signed in.
  • Check your workplace rules before working in another country.

A deadline is not an exception

If work cannot be done safely, explain what is blocked and ask for an approved route. Personal email, unapproved devices and disabled protection can turn a small delay into a security problem.

  • Know an urgent and out-of-hours reporting route.
  • Use approved storage so work is not held only on a laptop.
  • Prioritise personal safety if equipment is stolen.

Useful habit: Approved device. Approved connection. Appropriate surroundings.

Sources: S5, S2, S13, S15

Module 2

Read the request, not the polish

Learning goal: Check a message without using the route supplied by the message.

A convincing message can still be unsafe

Criminals use messages and calls to trick people into sharing information, approving access, installing software or sending money. These requests can also arrive through square codes scanned by a phone camera. Good spelling, familiar names and expected timing do not prove the request is genuine. Someone else may have gained access to a real account.

  • Pause when a request is urgent, secret or changes the normal process.
  • A scanned code can open an unsafe website. The code itself is not proof of trust.
  • Ask for help even if you are unsure.

Use a route you already trust

Open the service using your usual bookmark or app. Contact the person using a number in your workplace contact list or an established conversation, not details supplied by the suspicious request. A padlock means the connection is protected while travelling between your device and the service; it does not prove the business or request is honest.

  • Do not open an attachment just to investigate it.
  • For payment changes, follow the checking and approval process.
  • Use the approved tool for reporting suspicious messages; avoid spreading attachments.

If you already clicked

Stop using the suspicious page and report as soon as you can. Say whether you opened it, entered a password, approved an extra sign-in check, downloaded a file or ran it. Opening a page does not always mean someone gained access, but the team needs the facts.

  • Never put passwords or sign-in codes in a report.
  • Use a known backup contact if someone else may have access to your normal account.
  • Training is only one protection. Nobody can spot every attack.

Useful habit: Unexpected action? Pause, check independently, report concerns.

Sources: S1, S2, S12, S13

Module 3

Protect how you sign in

Learning goal: Reject unexpected access requests and keep sign-in secrets private.

One account, one password

Use a different strong password for each account. A work-approved password manager, a tool that stores and creates passwords, can help. Protect that tool with a strong password and an extra sign-in check if available. A long phrase made from unrelated words can help with passwords you must remember; follow your workplace rules.

  • Do not base passwords on public details about you.
  • Do not install a personal password tool for work without approval.
  • Never share a password with a manager, colleague or caller.

An extra check when signing in

An extra sign-in check adds protection beyond a password. Criminals can still trick people into sharing some codes or approving a check. Approve only a sign-in you started, for the intended service. Where your workplace supports and approves them, sign-in methods that use your device or a physical key can protect against fake login pages.

  • Reject and report unexpected approval sign-in requests.
  • Do not read out a one-time code to a caller.
  • Repeated sign-in requests are not something to clear by approving one.

Use the approved way to regain access

A lost phone or locked account is a reason to get help, not to share someone else's account. Keep backup sign-in codes in the secure place your workplace approves. If you entered a password on a suspicious page, report it and change it through the genuine service or your work computer support team.

  • Your support team may also need to sign the account out on devices or apps where it is already signed in.
  • Do not paste backup sign-in codes into chat or a shared document.
  • Ask for an approved alternative if you cannot use the normal method.

Useful habit: Unique passwords. Approved tools. Only approve sign-ins you started.

Sources: S3, S4, S5

Module 4

Pressure does not replace permission

Learning goal: Handle impersonation and payment requests without bypassing checks.

People and authority can be imitated

An attacker may claim to be a director, supplier or your work computer support team technician. Names, job roles and project details can be public or stolen. Voice and video can be manipulated too. A convincing person is not the same as an approved request.

  • Urgency and secrecy are reasons to pause.
  • Use a known independent route to check.
  • A senior person's apparent request does not remove controls.

Protect the process

Check new bank details through the established supplier process and required approvals. Do not install software that lets someone control your device from elsewhere or disclose secrets because a caller claims to be helping. A smaller test payment is still a payment, not a safe substitute for checks.

  • Do not use the new phone number supplied in the payment email.
  • Do not buy gift cards to satisfy an urgent request you have not checked.
  • Ask the person with permission to approve an exception.

A safe refusal can be simple

Say: "I need to check this through our normal process." For unfamiliar visitors, use reception or the approved contact. Do not lend badges or permit access simply because a visitor carries equipment.

  • Be polite; do not put yourself at physical risk.
  • If money has already moved, report urgently so approved staff can contact the bank.
  • Do not send another payment to try to reverse the first.

Useful habit: Check the change through a known contact. Keep required approvals. Ask for help under pressure.

Sources: S2, S5, S14

Module 5

New tool, new destination

Learning goal: Check recipients, contents and access before sharing.

Check purpose, person and permission

Before sharing, ask what is needed, who is approved and which route is approved. Check the full recipient address, attachment contents and link permissions. A correct email can still contain the wrong file.

  • Share the minimum information needed.
  • Do not make a restricted link public just to fix access.
  • Address suggestions and display names can hide mistakes.

Tools also receive your information

Personal email, automatic writing tools, translation sites and file conversion websites receive the information you put into them. A familiar or free tool is not automatically approved for work. Removing names may still leave enough details to identify someone.

  • Keep work information out of unapproved tools.
  • Never put passwords or sign-in codes into a writing tool or document.
  • Follow workplace rules for how long information is kept, backup copies and how to remove information safely.

A security problem is more than theft

Personal information can be wrongly shared, lost, changed, damaged or made unavailable. These problems can affect people even if nothing was stolen. Report a suspected problem as soon as you can.

  • Asking to recall an email does not prove it was removed from the recipient's inbox.
  • A promise to delete a file is useful information, not proof that all risk is gone.
  • Let the responsible team assess the likely harm. Do not forward the file to a wider group.

Useful habit: Check the recipient, contents and access before you send.

Sources: S5, S7, S8

Module 6

Keep protections in place

Learning goal: Use approved software and report loss or unusual behaviour.

Managed settings have a purpose

Do not disable protection to finish a task. Use approved installation routes. Allow required security updates through the managed process and report repeated failures. Search results and pop-ups are not approval from your work computer support team.

  • Do not use permission to change important device settings for routine work unless approved.
  • Ask for an approved solution when a tool is blocked.
  • Different protections protect against different risks.

Protect the physical device

Lock your screen when stepping away. Keep devices, memory sticks and other equipment secure. Do not connect found memory sticks or unknown equipment to find the owner. Use your workplace process for found or lost equipment.

  • Use approved chargers and cables.
  • Do not leave equipment visible in a vehicle.
  • Do not lend a device while you are signed in.

Report the problem, do not experiment

Report a lost device immediately, even if you hope to find it. A message demanding money to unlock files, or files changing unexpectedly, needs urgent help. A slow device alone does not prove harmful software is present, but repeated problems need support.

  • Do not install repair tools, pay a demand or use an outside repair shop yourself.
  • Follow your workplace instructions about stopping work and disconnecting the device from networks.
  • Do not reset or erase it without approval. That can remove evidence of what happened.

Useful habit: Keep protections on. Use approved tools. Report loss or security concerns as soon as you can.

Sources: S1, S5, S9

Module 7

Report early, report clearly

Learning goal: Make a useful report without investigating or spreading the security problem.

You do not need proof

Report suspicious sign-ins, lost devices, wrong recipients and suspected harmful software as soon as you can. Reporting a problem caught before harm was done helps too. Give the facts and say what you do not know. Staff should be able to ask for help without blame.

  • Use the urgent contact when immediate help is needed.
  • Use a known backup contact if someone else may have access to your normal account.
  • Do not keep opening a suspicious file to prove there is a problem.

Stop further harm without destroying evidence

Stop the risky activity and follow your workplace instructions. If harmful software is suspected, follow the agreed steps for disconnecting the device. Do not reset it, erase evidence, decide to pay a demand or contact an attacker yourself. Decisions about demands for money need senior approval and specialist advice.

  • Record the time, device or account and what you did.
  • Keep the original message through the approved reporting tool.
  • Leave passwords, codes and unnecessary personal details out of the report.

A short report from the facts is enough to start

Say what happened, when, which device or service was involved, and what you did. "I entered my password at 14:10" is more useful than "I was hacked." The responsible team investigates and decides who else must be told.

  • Say whether you approved an extra sign-in check, downloaded or ran a file, or sent information.
  • Do not send suspicious material to everyone.
  • If money has already been sent to the wrong place, report it urgently.

Useful habit: Stop. Trusted reporting route. Facts, not secrets.

Sources: S2, S5, S6, S7, S8

Module 8

Know your part, know the limits

Learning goal: Report as soon as you can and leave legal decisions to the responsible team. Know what a course record does and does not prove.

The organisation assesses the problem

A personal-data breach is a security problem involving loss, destruction, change, damage, improper sharing or access to information about people who can be identified. It can also include that information being unavailable. The organisation deciding why and how the information is used assesses reporting to the UK data protection regulator and keeps the breach record. It must tell the regulator unless a risk to people's rights and freedoms is unlikely. This assessment includes possible harm to privacy, fraud, discrimination and other harm to the people affected. A required report must be made without unnecessary delay and, where possible, within 72 hours of that deciding organisation becoming aware. If the risk to those people is high, that organisation must also tell them without unnecessary delay.

  • Staff should report internally as soon as they can. The 72 hours is not permission to wait.
  • An organisation handling information for that deciding organisation, following its instructions, must tell it without unnecessary delay once it becomes aware of a personal-data breach. It must do this regardless of the risk threshold for reporting to the regulator. It must not wait 72 hours. The deciding organisation then assesses its own reporting duty.
  • The responsible team decides whether the regulator or affected people must be told.
  • The organisation deciding why and how the information is used records every personal-data breach and the reasons for its decisions, even when it does not need to tell the regulator.

Current rules, not a forecast

Law and guidance were checked on 6 October 2026. The Data (Use and Access) Act 2025 changes data protection law, but secure handling and quick reporting are still needed. A separate rule for public phone and internet service providers changed their reporting deadline from 24 to 72 hours. This is not a deadline for ordinary staff to wait before reporting.

  • Your sector rules and contracts may add duties. This course gives general information, not legal advice.
  • The proposed Cyber Security and Resilience law was still being considered by Parliament on 6 October 2026. It was not yet law. Its proposed main duties concern essential services and certain technology service providers, not ordinary small-business staff.
  • No unconfirmed rule for 2027 is presented as law. Check official guidance again before later use; a review after 26 October 2026 is recommended.

Learning is not formal approval

Cyber Essentials is a separate scheme that checks an organisation's security protections on computers and accounts. Passing this course does not give the organisation that approval or prove it meets every legal requirement. The completion record is made in your browser; nobody independently checks who completed it.

  • Managers still need suitable security protections and a plan for handling problems.
  • Know your workplace reporting contacts, sharing rules and approved tools.
  • Ask for help if workplace instructions are missing or disagree.

Useful habit: Report as soon as you can. Let the responsible team assess. A course record is not formal approval.

Sources: S7, S8, S9, S10, S11

Use this at work

After the session, explain your real reporting contact and backup to your manager or colleague. Choose one habit to use, discuss what might get in the way, and agree one practical fix and who will take it forward. Keep workplace details outside this course. This discussion is optional and unscored, not proof of safe behaviour at work.

Active exercises: assisted route

Prepare a workspace

Before the first task, check the approved device, approved connection, surroundings private enough for the work, and known contact/backup. A page asking you to join a network does not give permission to change device settings. Your organisation's approved private-network connection (VPN) does not stop someone nearby hearing a call.

Before the related scenario, let the learner inspect these details and explain what they would verify. A clue is not proof of fraud.

Action required: salary correction

Sender: payroll-alerts@workplace-pay.invalid

The display name says Payroll Team. This address alone cannot prove who sent it. Compare with a known route, not the logo.

Where the square scanning code leads: workplace-pay.invalid/verify

This is not your known payroll bookmark. A square scanning code hides the destination until inspected; open the genuine website yourself.

Urgency: Salary may be held. Act by 17:00.

Urgency can be legitimate, but is not permission to skip an independent check.

Approve the sign-in request to stop the alerts?

Did you start this sign-in?: Did you try to sign in? No.

Reject a sign-in request you did not start. If you already approved one, report it as soon as you can.

Caller identity: "Work computer support" knows your manager's name.

A name is not proof of identity. Use the known work computer support number, not one supplied by the caller.

Requested action: Approve a sign-in request or read out a code.

Both can enable sign-in. Do not share codes or approve unexpected requests.

New bank details, urgent payment

Conversation: An existing supplier conversation

An existing account may be accessed or controlled without permission. A familiar conversation does not check new bank details.

Voice: "Skip the call using an established phone number just this once."

A convincing voice can be imitated. Follow the established checking and approval process.

Number supplied for checking: A new number supplied in this request

Calling the sender's own number is not checking through a separate, trusted contact. Use your established contact.

Disable protection to install

Permissions: Run with permission to change important device settings

This gives software wider control. Ask for an approved tool, not a security workaround.

Protection: Disable protection that checks for harmful software as you work

Stop. A converter request is not permission to disable protection.

File destination: Upload a customer document

A new service is a new place receiving work information. Check approval before sending work information.

Choose how to handle the request

Jamie requests the usual three-point update using the approved work screen for the team allowed to receive it. No new link, sign-in, payment or access change. Decide: normal work, check first or report a security concern?

Facilitator feedback

Normal work fits these facts. Watch for later changes, such as a new automatic writing tool.

Build a first report from the facts

Taylor opened an unexpected email link at 15:32 on a work laptop and entered a work-email password. No extra sign-in check was approved and no file was downloaded or run. Page closed; account access unknown.

Choose the four useful facts and a known reporting contact or backup, not a broad forward or reply to the suspicious email.

Facilitator feedback

The first four items are observed facts. Leave guesses and passwords out. No real report is sent.

Optional contrast cases: when facts change

Choose normal work, check first or report quickly for the first request. Discuss it before revealing the changed facts. Repeat the decision after the change. These cases are unscored and do not replace local procedures.

An update request changes

Your managed work laptop offers an update through the normal organisation update process. No unusual permission or conflicting warning.

First-request feedback and changed facts

Use the approved update process. Ordinary approved work does not need to be reported as a security concern only because it is online.

Changed facts: Now a browser pop-up asks you to install new settings that change how the device connects or is managed from an unfamiliar website. You have not installed it.

Changed-facts feedback

The website and requested access changed. Stop this pop-up and use the known work computer support team route or approved update process. Do not install those settings.

A supplier change becomes a payment

An existing supplier conversation requests new bank details and provides a new phone number to check them. You have not paid.

First-request feedback and changed facts

Use the established supplier contact and required approvals. Use a trusted contact you already have, not a number supplied by this request.

Changed facts: A colleague now says the payment has already been sent to those new details without the established check.

Changed-facts feedback

Report urgently through the known reporting or payment concern route. Authorised staff may need to contact the bank. Do not send another payment; recovering the money is not guaranteed.

An unfamiliar link leads to possible account access

A chat account says your project files moved to a new service and asks you to sign in. You did not expect a move and have not opened it.

First-request feedback and changed facts

Check through the usual project service or established independent contact, not the supplied link. A familiar account can be accessed or controlled without permission.

Changed facts: You now learn a colleague entered their work password through that link and approved an unexpected sign-in request.

Changed-facts feedback

Report the actions and time as soon as you can through a trusted route. The team responsible for handling the concern directs restoring safe account access and signing the account out on devices or apps where it is already signed in. Never include the password or codes.

A routine update changes who receives it

Your manager requests the normal three-point summary from the approved work screen for the usual approved internal team.

First-request feedback and changed facts

Use the normal approved work screen and group of people. Stay alert if the task changes.

Changed facts: The next message asks you to upload the customer spreadsheet to a new free website that generates text or summaries automatically to make the summary. Approval for that tool or sharing information is not known.

Changed-facts feedback

A new tool receives the work information. Check approval for the tool and information first, or use the approved manual route. A routine request did not authorise this change.

Task cards and possible outcomes

Start at the starting step number shown on each card. Choose an option and move to the next step shown. Do not read every outcome before choosing. A facilitator can hide later outcomes until needed. Discuss recovery without blame.

1. 08:45: A quick start at the station

You are covering customer operations for a small UK business. Your train is delayed and you need to send a confidential proposal. A free page asking you to join the wireless network says: "Install our settings that can change how your device connects or is managed to continue."

Starting step: 1

Step: 1

The proposal is due at 09:00. What do you do?

  1. Install the requested settings and send the proposal. → 2
  2. Use an approved connection, or ask for a safe alternative. → 5
  3. Use a shared station computer. → 3

Step: 2

These settings can change how your device connects or is managed. A page asking you to join the network is not approval from your work computer support team. You stop before completing installation. What next?

Learning point: A deadline does not authorise new security settings.

  1. Ask your work computer support team for an approved route and mention the request to change settings. → 5
  2. Disable the warning and continue. → 4

Step: 3

A shared computer is not an approved work device. You cannot control its software or know whether someone else can see what you do. You have not entered any passwords or sign-in codes yet.

Learning point: A different device can introduce different risks.

  1. Return to the approved device and connection policy. → 5
  2. Email the file to your personal account instead. → 4

Step: 4

This workaround creates an unapproved route. Stop and explain the block to your manager or your work computer support team. If you already changed settings or sent data, report what happened.

  1. Stop the workaround and contact the known support route. → 5

Step: 5

Your approved connection works, but nearby passengers can see the screen. The proposal is due shortly. Both of these routes respect policy. Which suits the situation?

  1. Use the station's private work booth, confirm it is suitable, then send through the approved route. → 6
  2. Tell the manager the safe setup is unavailable and agree a short delay. → 7

Step: 6 · Outcome

You check the booth is private enough for the information, keep the laptop with you and send through the approved route. You spend a few minutes arranging the space, but the proposal goes out safely.

Learning point: A safe decision can include getting the work done, not only stopping it.

Step: 7 · Outcome

You tell the manager what is blocked and agree to send from a suitable location after arrival. The manager must update the customer, but there is no hidden workaround.

Learning point: A visible delay lets the business manage the deadline. It is a reasonable tradeoff when a safe setup is not available.

2. 09:10: Action required: salary correction

An email with a familiar logo says your salary may be delayed unless you scan a square scanning code and sign in. You expected a payslip this week.

Starting step: 1

Step: 1

The message looks professional. What do you do?

  1. Scan the square scanning code and enter your password. → 2
  2. Open the normal payroll website using your bookmark. → 4
  3. Reply asking whether it is genuine. → 3

Step: 2

You entered a password on a page reached through the message. Your password may have been given to someone else. Do not continue or wait for visible harm.

Learning point: A plausible request can still lead to a false sign-in page.

  1. Report what you entered, the service and time through the trusted route. → 8
  2. Wait to see whether the next payslip arrives. → 7

Step: 3

The reply goes to the same source that sent the request. A reassuring answer would not independently check it.

  1. Use the genuine payroll website or directory contact instead. → 4

Step: 4

There is no correction request on the genuine website. The email says your staff/payroll team is too busy for calls.

  1. Contact your staff/payroll team using the staff directory and report the message. → 9
  2. Use the urgent phone number in the email. → 5
  3. Delete it without reporting. → 6

Step: 5

The email supplied that number; it could lead to the sender. Checking needs a route you already trust.

  1. Use the staff directory and report. → 9

Step: 6

Deleting avoids this request, but a report can help protect other staff. You do not need to prove it is malicious.

  1. Use the approved route for reporting suspicious messages. → 9

Step: 7

Waiting gives a possible attacker more time. A quick report helps your work computer support team protect the account, including changing its password and signing it out on devices or apps where it is already signed in.

  1. Report the action and time now, without sending the password. → 8

Step: 8 · Outcome

You tell your work computer support team what you entered and when, without sharing the password itself. You follow the approved instructions for safely regaining access to the account. Your work computer support team can consider signing the account out on devices or apps where it is already signed in as well as a password change.

Learning point: If you acted on a suspicious request, report as soon as you can. A click, a password and a download need different responses.

Step: 9 · Outcome

Your staff/payroll team checks the request through its established route. Your report helps the team warn other staff without circulating the risky square scanning code.

Learning point: Expected timing and good design do not prove the identity of a message.

3. 09:40: Approve the sign-in request to stop the alerts?

Three sign-in requests arrive on your phone. You did not start a sign-in. A caller says they are from your work computer support team and asks you to approve one.

Starting step: 1

Step: 1

The caller knows your manager's name. What do you do?

  1. Approve one so the alerts stop. → 2
  2. Reject the sign-in requests and contact the known work computer support route. → 5
  3. Read a one-time code to the caller instead. → 3

Step: 2

An unexpected approval may grant account access. You cannot safely assume it was your work computer support team. Report the service, time and that you approved it.

  1. Use a trusted route to tell your work computer support team what happened. → 7
  2. Change the password and tell nobody. → 4

Step: 3

The code is also a sign-in secret. Knowing your manager's name does not prove who the caller is.

  1. Do not share it; contact the known work computer support contact. → 5

Step: 4

Changing a password does not always sign the account out on devices or apps where it is already signed in, or undo other changes. The team needs to know the account may have been accessed.

  1. Report the approval and follow instructions to regain access safely. → 7

Step: 5

The known work computer support team confirms it did not call you. Your report allows it to investigate attempted access. How will you protect future sign-ins?

  1. Use my approved sign-in method and approve only sign-ins I start. → 8
  2. Turn the extra sign-in check off because it is annoying. → 6

Step: 6

An extra sign-in check adds useful protection. The problem was an unexpected request, not a reason to turn off protection.

  1. Keep the approved method and use your work computer support team for problems regaining access. → 8

Step: 7 · Outcome

Your work computer support team investigates and directs steps to regain safe account access, including signing the account out on devices or apps where it is already signed in if needed. You keep codes and backup sign-in secrets out of the report.

Learning point: Reject unexpected approvals. Report any accidental approval as soon as you can.

Step: 8 · Outcome

You keep the approved sign-in protections. If a method becomes unavailable, you will use the approved process to regain access rather than a shared account.

Learning point: An extra sign-in check helps, but only approve a sign-in you started.

4. 10:30: New bank details, urgent payment

A message inside a familiar supplier email conversation gives new bank details. A voice note sounding like your manager says: "Pay today. Skip the check just this once."

Starting step: 1

Step: 1

The voice sounds right and the contract is important. What next?

  1. Pay because the two messages agree. → 5
  2. Check through the established supplier and payment approval process. → 3
  3. Call the new number in the email. → 2

Step: 2

The request supplied its own way to check it. A convincing call to that number would not provide independent confirmation.

  1. Use the existing supplier contact and required approval route. → 3

Step: 3

The established supplier contact is unavailable. The requester says the contract is at risk. Two approved routes are available; choose the one you would use here.

  1. Hold the payment and ask for help from the person authorised to approve payment, explaining the deadline. → 10
  2. Ask the person authorised to approve payment to use the agreed backup checking route. → 11
  3. Send a smaller test payment while waiting. → 4

Step: 4

A small payment is still a financial commitment and does not check the bank change.

  1. Return to checking and approval. → 9

Step: 5

Money has already moved. Acting quickly may help recover the money. What do you do?

  1. Report urgently with transaction details so approved staff can contact the bank. → 8
  2. Send another transfer to reverse it. → 6
  3. Wait for the supplier to complain. → 7

Step: 6

A second transfer does not reverse the first and may create more loss.

  1. Stop and report urgently. → 8

Step: 7

Delay can reduce the chance of recovering the money. You do not need to prove fraud before raising the concern.

  1. Report urgently through the known contact for payment concerns. → 8

Step: 8 · Outcome

The approved team contacts the bank and response staff with the transaction facts. You do not contact the suspected attacker or make further payments.

Learning point: After a possible fraudulent payment, quickly passing the concern to the right person matters.

Step: 9 · Outcome

The person authorised to approve payment uses an established contact to check the change. The process holds, even when the voice and conversation feel familiar.

Learning point: Pressure, familiar accounts and convincing voices do not replace approval.

Step: 10 · Outcome

You hold the payment and record the reason. The person authorised to approve payment agrees to contact the supplier when the established contact is available. The customer-facing team may need to explain a delay.

Learning point: Holding a payment is a valid choice when required checking cannot be completed. Make the delay visible.

Step: 11 · Outcome

The person authorised to approve payment uses the pre-agreed backup checking route, checks the bank change and keeps the required approval record. The checked instruction is processed without using the number in the suspicious request.

Learning point: A documented backup process can keep work moving. It must already be approved, not invented by the requester.

5. 11:30: The usual support update

Jamie asks you to prepare a three-point update from the usual customer support screen. You normally handle this each Wednesday. The record is in the approved work system, the request is in your established team chat, and the update goes to the usual approved team. No new sign-in link, payment, permission change or new recipient is involved.

Starting step: 6

Step: 1

Other details can still identify customers. Removing names does not always stop someone being identified from the other details.

  1. Use only an approved route and the smallest amount of information allowed for the task. → 3

Step: 2

A personal account still sends work information to the service. It does not remove the data-handling risk.

  1. Check the approved route. → 3

Step: 3

This automatic writing tool is not approved for these records. The colleague says it will take longer manually.

  1. Use the approved manual process and explain the time needed. → 5
  2. Paste only one record as a test. → 4

Step: 4

Sharing even one customer record gives information to the service. Testing is not permission to send it.

  1. Use the approved manual process. → 5

Step: 5 · Outcome

You complete the work through the approved route and raise the need for a safe tool with the manager. No customer records are put into an unapproved service.

Learning point: New tool, new destination. Check approval and share only the information needed.

Step: 6

This is expected work through the established route. What is a sensible next step?

  1. Open the approved work screen through the usual route and prepare only the needed summary. → 9
  2. Report it as a security problem only because it arrived in chat. → 7
  3. Send the full copy of the records to the whole business so nobody misses context. → 8

Step: 7

You can ask about any concern, but the provided facts do not identify an unusual security request. Treating every routine task as a security problem adds work without resolving a specific risk.

  1. Continue through the approved process, watching for any change in the request. → 9

Step: 8

Routine work does not justify a wider audience or more data than needed. Keep the update to the approved group and task.

  1. Prepare a limited summary in the approved process. → 9

Step: 9

You open the real work screen. The normal summary is possible. Jamie then suggests a new free automatic writing tool to speed it up, using the downloaded copy of the records that includes customer health details.

  1. Check the tool and data-handling approval before using the downloaded copy of the records. → 3
  2. Remove the names and paste the downloaded copy of the records into the new tool. → 1
  3. Use your personal account for the tool. → 2

6. 13:15: The nearly correct address

You sent a spreadsheet containing staff pay and bank details. The address suggestions selected the wrong external recipient. You notice one minute later.

Starting step: 1

Step: 1

What happens first?

  1. Delete the sent email and carry on. → 2
  2. Report immediately through the known person responsible for security or personal information concerns. → 4
  3. Wait to see whether the recipient opens it. → 3

Step: 2

Deleting your copy does not remove the recipient's copy. The wrong sharing still needs assessment.

  1. Report the facts as soon as you can. → 4

Step: 3

Waiting can make it harder to limit further harm and assess the risk.

  1. Report as soon as you can. → 4

Step: 4

A recall attempt fails. The recipient promises deletion. What do you tell the team responsible for handling the concern?

  1. The facts, the contents involved and what was done to limit further harm, through the approved secure route. → 7
  2. It is resolved, so no record is needed. → 5
  3. Forward the spreadsheet to all managers for advice. → 6

Step: 5

The deletion promise is useful information, not an automatic all-clear. The organisation still documents and assesses the event.

  1. Give the team responsible for handling the concern the facts. → 7

Step: 6

A broad forward creates more unnecessary sharing. Give the approved team only what it needs through the secure route.

  1. Limit the people who can receive it and follow the response instructions. → 7

Step: 7 · Outcome

The approved team assesses the risk to staff, records the personal-data breach and the reasons for its decisions and decides whether telling people outside the organisation is required. You do not contact affected people or the UK data protection regulator on your own.

Learning point: Report quickly. A recall or deletion promise does not end the decision process.

7. 14:10: Disable protection to install

You need a file in a different format. A free converter asks you to disable security protection and run an installation file with permission to change important device settings.

Starting step: 1

Step: 1

What is the safest next action?

  1. Run it because it is only a converter. → 3
  2. Stop and ask for an approved conversion route. → 7
  3. Move the customer document to a personal laptop. → 2

Step: 2

That creates an unapproved device and another place receiving work information. A blocked work tool is a support problem, not permission for a workaround.

  1. Ask your work computer support team for an approved route. → 7

Step: 3

You ran the tool. Files now have unfamiliar names and will not open. What next?

  1. Stop work, report urgently and follow the agreed steps for disconnecting the device as instructed so a problem cannot spread. → 6
  2. Install another free tool to repair them. → 4
  3. Reset the laptop before anyone sees it. → 5

Step: 4

Another unapproved tool may worsen the security problem. Do not keep experimenting.

  1. Stop and use the known urgent reporting route. → 6

Step: 5

Resetting can destroy evidence and make investigation or restoring safe work harder. Do not erase the device unless approved.

  1. Leave further action to the agreed steps for handling the concern. → 6

Step: 6 · Outcome

You use the known urgent route, describe what you ran and when, and follow instructions for disconnecting the device. The team responsible for handling the concern directs how to restore safe work. You do not pay a demand to unlock files or reset the device yourself.

Learning point: After unexpected file changes, stop experimenting and get urgent help.

Step: 7 · Outcome

Your work computer support team supplies an approved method. You complete the conversion without changing security settings or moving the data to a personal device.

Learning point: Keep protections in place and use approved software.

8. 15:00: A laptop left behind

A colleague thinks they left their work laptop in a taxi. They want to wait until tomorrow because it might turn up.

Starting step: 1

Step: 1

What do you suggest?

  1. Report the loss immediately and provide the last known time and place. → 4
  2. Wait until tomorrow because the laptop has a password. → 2
  3. Ask a local repair shop to track it. → 3

Step: 2

Device protection may reduce risk, but it does not remove the need for quick reporting. The support team can act to limit harm while the taxi search continues.

  1. Use the urgent loss reporting route now. → 4

Step: 3

An outside repair shop is not the organisation's approved reporting route and may introduce further possible access without permission.

  1. Use the known work computer support contact or backup contact. → 4

Step: 4

The colleague cannot access work email without the laptop. What now?

  1. Use the known backup phone/urgent contact route. → 6
  2. Ask a stranger to sign in to their work account for them. → 5

Step: 5

Do not disclose passwords and sign-in codes or use an unapproved shared computer to regain access. A backup reporting route should not require the missing device.

  1. Use the known backup contact. → 6

Step: 6 · Outcome

The team gets a factual report and directs how to limit further harm. The colleague follows safe steps to locate the taxi without putting themselves at risk.

Learning point: Report loss as soon as you can even when the device may be recovered.

9. 15:40: Write the useful first report

A team member clicked an unexpected login link and entered their password. You are helping them make a first report. They are worried about being blamed.

Starting step: 1

Step: 1

Which opening is most useful?

  1. "I entered my work password on a page from an unexpected email at 15:32." → 4
  2. "I was definitely hacked by an overseas group." → 2
  3. "Nothing happened. I only made a small mistake." → 3

Step: 2

That is a claim without evidence. The team responsible for handling the concern needs observed actions and timing first.

  1. State the action, time and service, and say what is uncertain. → 4

Step: 3

Minimising the facts can delay the right response. Thank the person for reporting; you do not need to assign blame.

  1. Describe the action and time clearly. → 4

Step: 4

What should the report include next?

  1. The service or device, whether an extra sign-in check was approved, any downloads and actions already taken. → 7
  2. The password so your work computer support team can test it. → 5
  3. The suspicious attachment forwarded to everyone. → 6

Step: 5

Do not disclose passwords and sign-in codes in a report. Your work computer support team needs to know a password was entered, not what it is.

  1. Give facts without secrets. → 7

Step: 6

Use the approved reporting tool to preserve the original. Do not spread risky material or private details.

  1. Share it only with the team responsible for handling the concern. → 7

Step: 7 · Outcome

The report gives the team enough to start. The person follows instructions for safely regaining access. You thank them for speaking up quickly.

Learning point: Useful reports describe actions, timing and uncertainty. Supportive responses encourage earlier reporting.

10. 16:30: We have 72 hours, right?

A customer file was shared outside the business. The manager suggests leaving it until Monday because "Data protection law gives us 72 hours".

Starting step: 1

Step: 1

What is the right response?

  1. Wait because the deadline allows it. → 2
  2. Raise it as soon as you can with the known person responsible for security or personal information concerns. → 4
  3. Email every customer personally now. → 3

Step: 2

The deadline for telling the regulator is not a staff waiting period. The organisation needs time to limit harm, find out what happened and assess the risk.

  1. Report internally as soon as you can. → 4

Step: 3

The approved team must decide who outside the organisation needs to be told. Staff should provide facts to the designated team, not act alone.

  1. Use the internal reporting route. → 4

Step: 4

The team assesses a personal-data breach for the organisation deciding why and how the information is used. It judges a risk to people's rights and freedoms unlikely. What is still needed?

  1. A record of the personal-data breach and the reasons for the deciding organisation's decisions, even when no regulator report is needed. → 7
  2. Nothing; it can be forgotten. → 5
  3. Every security problem must always be reported to the UK data protection regulator. → 6

Step: 5

The organisation deciding why and how the information is used records every personal-data breach and the reasons for its decisions, even when it does not need to tell the regulator.

  1. Record the decision through the approved process. → 7

Step: 6

The duty to tell the UK data protection regulator depends on the risk to people. Some security problems do not involve personal information. Some personal-data breaches do not need to be reported to the regulator. The organisation deciding why and how the information is used records every personal-data breach and the reasons for its decisions, even when it does not need to tell the regulator.

  1. Keep the record and risk assessment. → 7

Step: 7

The manager asks if everyone passing this course makes the business approved under the separate Cyber Essentials scheme.

  1. No. Awareness learning and formal approval are separate. → 9
  2. Yes, if completion records are printed. → 8

Step: 8

A printed record does not give official recognition, compliance or formal Cyber Essentials approval.

  1. Explain that security protections on computers and accounts and formal approval are separate. → 9

Step: 9 · Outcome

The manager confirms the person responsible for handling the concern and local reporting routes. You finish the day knowing how to ask for help, without promising never to make a mistake.

Learning point: Quick reporting, decisions based on the likely harm to people and security protections on computers and accounts work together.

Official sources

Checked 6 October 2026. Practical scenario details are original examples, not quoted rules. No unconfirmed 2027 legal rule is claimed. Recheck official guidance before future use, with a planned review after 26 October 2026.