All T3 Blog posts

5 Security Best Practices for Workstations

Five straightforward things anybody can do to keep a work computer out of trouble, from endpoint security through to locking the screen.

4 minute read security

Hopefully you have not yet had to face the intense frustration of being infected with malware. In most cases it can take hours to detect and delete every affected file on a system. For that reason many IT professionals prefer a clean install, which starts by erasing the drive and replacing everything on it. The downside of a clean install is that anything not backed up to an external drive or the cloud is gone. If only the workstation had been properly secured, none of this would have happened.

The good news is that you do not need to worry about it, because here are five easy ways to protect your workstation today and prevent the problem in the first place.

1. Use endpoint security

Good endpoint security should protect your computer from viruses, malware, spyware and network attacks. An antivirus product on its own is simply not enough these days. Some programs look useful but are spyware. A program that alerts you to discounts and deals, for instance, while also monitoring everything you do online. Your endpoint security should recognise that and disable it.

It is also very important to make sure your security software is actually running, and that you run a scan weekly at a minimum. If it is not running, turn it on and run a full system scan immediately.

2. Update your software

Update your operating system, your endpoint security and your programs regularly. Microsoft releases patches on the second Tuesday of every month, so if you update your own system, check then. If an IT professional manages your updates they may test Microsoft’s patches before applying them to your system, which means a short delay.

Many security vendors release new versions of their software every few hours. Those are normally downloaded and installed on your system automatically, to protect against threats that have only just been discovered.

Applications are worth attention too, especially the ones that connect to the internet, because they are a way for an attacker to reach your system. Java and Flash, for example, release frequent updates to address problems found in them. If you use an application, keep it up to date. If you do not, uninstall it. Check with your IT team before making any changes.

3. Leave it? Lock it

You should never leave your device logged in while it is unattended. Never, as in not in your office at work, not on your desk at home, and not at your favourite local coffee shop. Never.

If you are walking out of sight of your device, lock it or log out of it. On most Windows systems you can hold down the Windows key and press L. You can also set your system to lock and log out automatically after a few minutes of not being used.

4. Do not share your device

Do not share your device with anyone unless your IT team specifically tells you to. If you are the only person who uses it, you can keep it safe. If you hand it to Sophie in Accounting, she may put in a flash drive carrying malicious files. If you lend it to James in Marketing for a presentation, he may present you with an infected file.

Whenever you share a file, share it on the company’s shared file system, whether that is in the cloud or on your server. Cloud services actively scan for problems, and your document server is likely to do the same.

To keep it simple: do not share your device, unless your IT team says otherwise.

5. Back up your data

It is very important to back up every file and document you want to keep. It should not be necessary to back up your operating system or your applications, because your IT team should be able to replace and update those for you easily.

Your data is not replaceable, though. That means your emails, documents, photos, spreadsheets, presentations and videos. All of it should be backed up.

Any file that matters to you should be backed up. Most IT teams will set up something straightforward like OneDrive or SharePoint, which saves and backs up your documents to the cloud automatically. For genuinely crucial documents and important company information, a cloud to cloud backup is worth considering as well.

A backup keeps your data safe. If your device is infected, if you delete a file by accident, or if the hardware fails, a backup saves you the time, the money and the hassle of fighting a corrupted system. You can get another device set up, log in, and get back to work.

How are you going?

How well do you do each of these five? And what about the people you work with, how well do they do them?

If you would rather somebody else kept on top of all five, that is what we cover on the security side. Have a look, or get in touch if you would sooner just ask somebody.

Keep reading

More Tech Tip Tuesdays.

  1. 4 min

    What's Changing in Your Microsoft 365 This July

    Microsoft is lifting prices on most 365 plans from 1 July 2026. Business Premium is not one of them, and Cloud PCs just got cheaper. What it means for your bill.

  2. 3 min

    5 Signs Your Business IT Is a Ticking Time Bomb

    Five things that quietly make a small business an easy target, and the three you can fix this afternoon without spending anything.

  3. 2 min

    Pros and Cons of VoIP for your Business

    What VoIP genuinely gives a business, and the three things that go wrong with it, including the one most providers would rather not own.

Tech Tip Tuesdays

Get it in your inbox

One email a month with the new Tech Tip Tuesdays piece in it. No sequences, no sales emails, and one click to stop.

One email a month. Unsubscribe any time.

Want this looked at properly?

Thirty minutes, no obligation. We will go through what you are running and tell you straight what is worth doing something about and what is fine as it is.

Or ring us

1300 025 110 (07) 5638 1255

Monday to Friday, 9am to 5pm

Or send us a message

We get back to you within one business hour, Mon to Fri

Call now Book a call