Also on CyberFence: compare CyberFence to other VPNs side-by-side · the free CyberFence security tools .
You hired someone. The offer is signed, the start date is set, and you have a short list of things to do before Monday: laptop, email, a login or two, maybe a welcome lunch. Security is rarely on that list, and for a small business with no IT department it is easy to see why. The new person is busy learning names and systems, and you are busy running the company.
That first week is also when a new employee is at their most exposed. They do not yet know what a normal message from you looks like. They want to be helpful. And they are often working on a device and a home network you have never looked at. This checklist covers what to set up in the first five days, and how to know that it actually happened.
Why the First Weeks Are the Risky Ones
Security-training vendor Keepnet looked at data from 237 companies for its 2025 New Hires Phishing Susceptibility Report. As summarized by Help Net Security, it found that 71% of new hires click on phishing emails within three months, that new hires are 44% more likely to fall for phishing and social engineering than staff who have been there longer than 90 days, and that they were 45% more likely to click emails impersonating the CEO.
Treat those numbers as directional. They come from a vendor, and the summary does not spell out how the data was collected. But the reasons behind them are easy to believe. Help Net Security lists several: new hires are unfamiliar with how things work, onboarding is overwhelming so security steps get missed, they may comply with a suspicious request to make a good impression, and early security training is often delayed or too brief.
The scams that go after new people are not exotic. The report points to fake messages from the CEO, bogus HR portals, phony invoices and fake tech support. All of them lean on the same thing: a person who does not yet know what is normal.
Small Businesses Start From Behind
A larger company can lean on a security team and a formal training program. A small business usually cannot. In a CrowdStrike-commissioned survey of 291 U.S. small business professionals (organizations with 1 to 249 employees, surveyed in February and March 2025), 94% of leaders said they were somewhat or very knowledgeable about cyber threats, yet only 42% of SMBs provided regular employee security training. Only 47% of micro-businesses had a security plan, compared with nearly 90% of larger small businesses. Two-thirds said cost keeps them from upgrading security tools.
In other words, most owners know the risk is real. What is missing is a repeatable routine. A new-hire checklist is the cheapest place to build one, because every new person goes through it the same way.
Set up every new hire the same way. CyberFence Teams lets you invite your people, then shows you who has started and who needs a follow-up.
See CyberFence Teams →The First-Week Checklist
Before day one: decide what they will use
Write down which device the new person will work on, and which accounts they will need. If they will use a personal phone or laptop, say so plainly and set the same baseline for it as you would for a company device. The goal is to avoid the quiet default where someone starts work on whatever they have, with whatever settings it happens to have.
Day one: accounts and passwords
- Unique password for every work account. Reused passwords are what make credential stuffing attacks work, and a new hire is likely to reuse the one they already know.
- A password manager. Set it up with them, in person or on a video call, so they do not store logins in a notes app.
- Two-step sign-in on email and any system that holds client or financial data. Do this first, before the third or fourth app.
- Send access one account at a time. Give them what the job needs on day one, and add the rest as it becomes necessary.
Day one: protect the connection
New hires often start from a home network, a coffee shop or a shared workspace. A VPN encrypts the traffic between their device and the internet, which matters most on networks nobody on your team controls. If you want the longer version, see our guide on whether public Wi-Fi is safe. A VPN will not stop someone from handing over a password on a fake login page, which is why the next steps matter just as much.
Day two: turn on protection against bad sites and leaked credentials
Fake HR portals and fake invoice pages are websites. DNS-level blocking can stop a known malicious domain before the page loads, as explained in how DNS filtering works. It is not perfect, and it will not catch a brand-new site, but it removes a lot of easy mistakes. Also check whether the new person's work email already appears in known breaches. If it does, their password may already be circulating, and you want to know that in week one rather than month six. Our explainer on Breach Monitor covers what that check does and does not do.
Day three: teach the four scams, in plain words
Skip the hour-long course. Show the new person a real example of each of the four messages above, and agree on one rule: anything that involves money, gift cards, a login, or a change to payment details gets confirmed by a phone call or in person, using a number you already have. Not a number from the message. Phone-based versions of the same trick exist too, as we cover in our piece on vishing attacks.
Day five: follow up on who actually finished
This is the step most small businesses skip. Everyone agrees on the checklist, and then nobody checks. By Friday, confirm that each new person finished each item, and ask them what felt confusing. People are more likely to report a strange email in week two if week one went well.
Day thirty: review
Check in a month later. Ask whether they have seen anything suspicious, whether any tool is getting in their way, and whether anything on the checklist needs to change for the next hire.
Where CyberFence Teams Fits
Doing this for one person is easy. Doing it consistently for the third, fifth and tenth hire is where it slips. CyberFence Teams is built for that. You buy the team plan, invite your people, and they create their accounts, install CyberFence and connect. The dashboard shows who has started and who still needs a follow-up, so Friday's check does not depend on you remembering to ask.
Each seat includes the VPN, Web Shield DNS blocking, and Breach Monitor for the member's email, plus member and device management so you can adjust access when people join or leave. Our post on the offboarding gap covers the other end of the same process.
Teams pricing starts at $12 per person per month, billed annually. A team of two is $24 a month billed annually, and a team of five is $60 a month billed annually. For a fuller breakdown, see what it costs to protect a small team, and for why a managed plan differs from buying individual subscriptions, read team VPN vs. individual VPN subscriptions.
Make the first week the same every time. CyberFence Teams starts at $12 per person per month, billed annually, with a dashboard that shows who has started and who needs a follow-up.
Get Your Team Protected →What the Dashboard Does Not Do
It is worth being clear about the limits, because a tool that overpromises is worse than none. The Teams dashboard is about visibility, not surveillance. It shows setup and connection information, not anyone's browsing history, DNS queries or destination IPs. And a setup status is not a guarantee of continuous protection. It tells you someone has started, not that they will stay connected every minute of every day.
It also cannot replace judgment. A VPN, DNS blocking and breach alerts reduce risk. They do not stop a convincing phone call from a fake vendor, and they do not replace the conversation in the checklist above. Think of the platform as the part that makes the routine repeatable, and of the routine as your security program. Reports from a tool can support your internal reviews, but they are not a certification or a guarantee of compliance with any rule.
The Bottom Line
New hires are not careless. They are new, and attackers know it. A short, repeatable first-week routine, with one place to see who has finished it, turns onboarding from a risk into the moment you set good habits. Start with the five days above, check on Friday, and review again at thirty days.
If you are bringing on your next person soon, set the routine up before they start, not after the first strange email.
Want to go deeper? Read the CyberFence competitor comparison hub , our free privacy and security tools , or CyberFence plans and pricing .