Stay connected.   Subscribe  to our newsletter

6 common onboarding mistakes that can create cyber risk

By David Hollingworth | August 31, 2026|2 minute read
6 Common Onboarding Mistakes That Can Create Cyber Risk

Bringing in new hires might be a great sign that a company is growing, but it can also lead to growing cyber risk, according to experts.

Editor’s note: This story first appeared on HR Leader’s sister brand, Cyber Daily.

Getting the onboarding of new hires right can be challenging, but when done well, it can lead to a new employee fitting in and being a productive part of the team.

 
 

Getting it wrong, however, can lead to all manner of poor outcomes, and not necessarily in terms of performance and employee satisfaction – it can also potentially open the door for hackers and other cyber criminals.

“New joiners, especially those in their first job, haven’t yet developed an instinct for what looks suspicious. They might struggle to identify phishing emails, fake login pages, bogus password reset requests, fake IT help desk messages, and malicious attachments disguised as onboarding documents,” Karolis Arbaciauskas, head of product at cyber security firm NordPass and its parent organisation Nord Security, said in a statement.

“The first few weeks, before cyber security training kicks in, are the most dangerous because newcomers are more likely to make mistakes and follow instructions without asking too many questions.”

One of the most egregious mistakes – and most common – is the use of temporary passwords built around a consistent model and which, once known, can make guessing other passwords incredibly easy. Making matters worse, these credentials are often shared via emails or text messages, and sometimes included on sticky notes attached to new staff laptops.

These may seem like easy methods for onboarding new hires, but they add greatly to the risk of credential theft.

“Those first-day credentials are often simple and created using a company name, new employee name, or an easy-to-remember phrase, like ‘Welcome2026,’ because they’re meant to be changed,” Arbaciauskas said.

“Unfortunately, those temporary credentials often become permanent and get reused across accounts. It’s best to generate unique credentials, deliver them through a secure channel, such as a password manager, and force a reset on first login.”

Here are another five common onboarding habits to avoid:

  • Giving new hires broad or administrative access instead of applying the principle of least privilege.
  • Failing to promptly revoke access when employees change roles or leave, including during probation.
  • Waiting weeks to provide phishing and cyber hygiene training – or skipping security awareness training altogether.
  • Failing to give new employees clear guidance on acceptable technology use, data handling, and reporting suspicious activity.
  • Allowing personal devices onto corporate networks without appropriate endpoint security or mobile device management.

RELATED TERMS

Onboarding

Onboarding is the process of integrating new hires into the company, guiding them through the offer and acceptance stages, induction, and activities including payroll, tax and superannuation compliance, as well as other basic training. Companies with efficient onboarding processes benefit from new workers integrating seamlessly into the workforce and spending less time on administrative tasks.

Recruitment

The practice of actively seeking, locating, and employing people for a certain position or career in a corporation is known as recruitment.

HR LeaderWant to see more stories from trusted news sources?
Make HR Leader a preferred news source on Google.