New staff cyber security is one of the most overlooked gaps in business protection. When a new employee joins, there is a great deal to arrange. Equipment, system access, introductions, and the many practical details of getting someone up and running. Cyber security awareness, however, rarely makes it into those first few days with the urgency it deserves. New research suggests that is a significant oversight, and that businesses are paying a real price for it.
Why New Employees Are a Prime Target for Cyber Criminals
Research has found that 71% of new hires fall for phishing or social engineering attacks within their first 90 days in a role. That figure is striking. It means that across three new starters, two are likely to be successfully targeted during that initial period.
The reason is straightforward when you consider the psychology of starting a new job. A new employee is keen to make a good impression. They are unfamiliar with internal processes, unsure about who contacts them and why, and motivated to be helpful and responsive. They have not yet built up the pattern recognition that tells an experienced colleague when something feels off.
Cyber criminals understand this dynamic and exploit it deliberately. They craft messages that arrive during those early weeks and appear to come from a senior manager, an HR system, or the IT department. The request might be to update login details on an unfamiliar portal, approve an urgent invoice, or share a piece of information as a quick favour. To an experienced team member, these requests might immediately raise suspicion. To someone new who has not yet learned the normal patterns of communication, they can feel entirely plausible.
The numbers bear this out. New employees are 44% more likely to click on a phishing link than colleagues who have been in the business for some time. When the attack involves impersonating a company executive, new starters are 45% more likely to be deceived than experienced staff. That gap is significant, and it represents a specific and predictable vulnerability that most businesses are not addressing adequately.
What Social Engineering Attacks on New Starters Look Like
Social engineering is the practice of manipulating people rather than systems. Rather than exploiting a technical vulnerability, an attacker exploits human behaviour, specifically the desire to be helpful, the reluctance to appear difficult, and the uncertainty that comes with being new.
Common scenarios include a fake message from the IT department asking a new employee to verify their credentials on a link provided. Another involves what appears to be an urgent email from a senior manager asking for sensitive information or a quick action before a deadline. A third presents a realistic-looking HR portal asking the new starter to update their bank details or personal information ahead of their first payroll.
Each of these scenarios is designed to feel routine and pressure the recipient into acting without taking time to verify. A new employee who does not yet know the normal channels for IT requests, payroll updates, or executive communications is poorly placed to recognise that the request is unusual. Our article on business email compromise covers how attackers use impersonation of trusted figures to bypass caution across a wider team.
New Staff Cyber Security Must Begin on Day One
The most common mistake businesses make with new staff cyber security is treating it as something that can wait until the employee has settled in. The idea is understandable: there is a lot to cover in the first few days, and it seems like awareness training can follow once the basics are in place. However, the research makes clear that those first 90 days are exactly when the risk is highest. Waiting until the employee has settled is waiting until after the most dangerous period has already passed.
Businesses that introduce security awareness training as part of the onboarding process, rather than as a later addition, see meaningful results. The same research found that companies providing tailored security training and running phishing simulations for new starters reduced their phishing risk by 30% during the onboarding period. That is a substantial reduction achieved through a targeted and relatively simple intervention.
The training does not need to be lengthy or technical. New starters need to understand a small number of clear principles: how to recognise a phishing email, why urgency in an unexpected request is a warning sign rather than a reason to act quickly, and what to do if something feels uncertain. They also need to know who to contact if they are unsure, without fear that raising a question will reflect badly on them.
Our article on employee cyber security covers how to build this kind of awareness across a whole team, including the cultural elements that make staff feel comfortable reporting concerns rather than staying quiet.
Phishing Simulations: A Practical Tool for New Starters
Phishing simulations involve sending realistic but safe fake phishing emails to staff to test how they respond. For new employees in particular, these are a highly effective learning tool. They provide concrete experience of what a phishing attempt looks like without the consequences of a real attack, and the immediate feedback when a simulated link is clicked creates a memorable and impactful lesson.
Businesses in Haywards Heath and across Sussex that have introduced phishing simulations as part of their onboarding process consistently report that new starters who receive simulated phishing emails early in their tenure are significantly better prepared to recognise real attacks later. The simulation removes the abstract quality of security training and replaces it with direct, personal experience.
Running simulations alongside brief training sessions creates a reinforcing loop. The training explains what phishing looks like and why it works. The simulation demonstrates it in practice. Together, they build a level of awareness that a policy document or onboarding checklist cannot achieve on its own.
The Role of Clear Processes in New Staff Cyber Security
Awareness training reduces the risk that a new employee will be deceived. However, clear internal processes provide an additional layer of protection that operates independently of whether any individual recognises an attack in the moment.
If your business has a defined process for verifying unusual requests, such as a phone call to confirm any payment instruction that arrives by email, or a designated person to contact when something seems unexpected, a new employee who follows that process is protected even when they are unsure whether a request is genuine. The process provides the safety net that individual judgement alone cannot always supply.
Making these processes explicit during onboarding, and ensuring new starters know them from the start, is a straightforward and practical investment. Our article on phishing scams tripling covers the broader rise in phishing frequency and why clear processes matter alongside awareness for the whole team.
What This Means For Businesses
New staff cyber security is a specific and addressable risk. The research identifies the onboarding period as the highest-risk window, the 71% attack success rate during the first 90 days as the scale of the problem, and a 30% reduction in phishing risk as the measurable benefit of targeted training during this period. The evidence is clear.
For business owners and directors, the practical response is to treat security awareness as a first-day priority rather than a later addition. Include a brief and focused security briefing in your standard onboarding process. Introduce phishing simulations early. Make sure new starters know who to contact when something feels uncertain. And create a culture where asking before acting is encouraged rather than seen as a sign of weakness or inexperience.
If your business does not currently have a structured approach to new staff cyber security, your managed IT provider can help you develop one that fits your onboarding process. Our managed IT services include security awareness support and phishing simulation programmes for businesses across Sussex and the South East.
Final Thoughts
New employees are a predictable and specific target for cyber criminals. Their unfamiliarity with processes, their eagerness to help, and their uncertainty about what is normal in a new environment make them significantly more vulnerable than experienced colleagues during those first few months.
Addressing new staff cyber security from day one, through focused training, phishing simulations, and clear verification processes, turns the onboarding period from a security liability into a foundation for a security-aware team. The investment required is modest. The benefit, a 30% reduction in phishing risk during the highest-risk period, is significant.
New starters are unfamiliar with internal processes, communication styles, and the normal patterns of requests in a new organisation. They are motivated to be helpful and responsive, and they have not yet developed the pattern recognition that helps experienced colleagues identify unusual requests. Cyber criminals specifically exploit these characteristics during the onboarding period.
As early as possible, ideally on the first day or within the first week. Research shows the highest risk period is the first 90 days. Waiting until an employee has settled in means the most vulnerable window passes without appropriate preparation in place. Security awareness should be treated as a standard part of the onboarding process alongside equipment setup and system access.
At minimum, new starters should understand how to recognise a phishing email, why urgency in an unexpected request is a warning sign, what to do if they receive something suspicious, and who to contact when unsure. They should also know the business’s verification processes for financial requests or sensitive information, so they have a clear action to take when something feels uncertain.
Phishing simulations involve sending realistic but harmless fake phishing emails to staff to test their response. They are particularly valuable for new employees because they provide direct, personal experience of what a phishing attempt looks like, without the consequences of a real attack. The feedback from clicking a simulated link creates a memorable lesson that abstract training cannot replicate.
Research indicates that businesses providing tailored security awareness training and phishing simulations for new starters reduce their phishing risk during the onboarding period by 30%. That is a meaningful reduction achieved through a targeted and relatively straightforward intervention that does not require significant time or technical investment.