The internet is every office employee’s primary work tool in 2026. That also means that a company’s security largely depends on the behaviour of specific individuals in front of specific screens. The best technical controls (firewall, EDR, e-mail security) fail when an employee clicks on a phishing link and enters their credentials there.

This article is a practical guide for employees and IT managers in SMBs. No technical jargon — just concrete rules and situations. For broader cybersecurity context, see the pillar Cybersecurity of Company Data.

The Most Common Threats When Browsing the Internet

According to EU cybersecurity agency (ENISA) and national CSIRTs for 2025, the dominant threats are:

  • Phishing (60% of all incidents begin with a click in an e-mail or SMS)
  • Drive-by malware (visiting an infected site installs malware without explicit consent)
  • Credential stuffing (leaked passwords from other services are tried against company e-mail)
  • Browser extension abuse (a browser extension with access to all visited pages exfiltrates data)
  • Malvertising (malicious adverts on legitimate websites)

Six Rules for Safe Online Behaviour

1. Password Manager + Unique Password for Every Service

The most common cause of company incidents in 2026 is not a sophisticated hack — it is password reuse. An employee uses the same password for their company Outlook, personal Spotify, and an aquarium hobby forum. The forum gets hacked, the password leaks, the attacker tries the same password on the company account — and gains access.

Solution: company password manager such as 1Password, Bitwarden, or Dashlane. It generates unique 20+ character passwords for every service. The employee remembers one master password; the manager handles the rest.

Cost: 4–8 €/employee/month. ROI is achieved at the first prevented incident.

2. 2FA / Passkey on All Critical Accounts

Even with a unique password, an attacker can gain access via phishing. A second authentication factor stops them. In order of preference:

  1. Passkey (FIDO2/WebAuthn) — strongest defence, phishing-resistant
  2. Hardware token (YubiKey, Titan Key)
  3. TOTP via app (Google Authenticator, Microsoft Authenticator, 1Password)
  4. Push notification (Microsoft Authenticator, Duo)
  5. SMS OTP — weakest, but better than nothing

Detail in the cluster article Two-Factor Authentication.

3. Verify the Sender for Every Request for Sensitive Information

In 2026, AI-generated phishing is indistinguishable from a legitimate e-mail at first glance. The rule “verify through a different channel”:

  • Request for payment / transfer via e-mail → call the person on a known number and confirm
  • Request for a password / access → not by e-mail, always in person or via internal chat
  • Adding a new bank account / supplier → physical approval procedure (manager, dual control)

This rule against Business E-mail Compromise (BEC) can save 10,000–50,000 in a typical incident.

4. Public Wi-Fi Always Via VPN

Public Wi-Fi networks (airport, café, hotel) are risky for three reasons:

  • Interception — the Wi-Fi provider or another user on the network can intercept traffic. HTTPS encryption mitigates this, but not completely.
  • Evil twin — an attacker creates a Wi-Fi network with the same name (e.g. “Hotel Free Wi-Fi”) as the legitimate one and intercepts communications.
  • Drive-by infection — a compromised router can inject malware into unencrypted pages.

Solution:

  • Company VPN (or ZTNA) — mandatory on every external connection.
  • Mobile hotspot (4G/5G from a company phone) — safer alternative to public Wi-Fi.
  • Rule “no business systems without VPN” — including e-mail, ERP, banking.

Detail on VPN in the glossary /en/glossary/vpn.

5. Updated Browser + Extensions Audit

The browser is the most exposed software in a business — it interacts with thousands of websites daily. Three measures:

  • Automatic updates enabled — Chrome, Edge, Firefox, Safari update themselves. Disabling this is a security anti-pattern.
  • Audit of installed extensions — every extension has access to the pages you visit. A compromised extension = data exfiltration. Rule: maximum 5 trusted extensions, no “free PDF converter” of dubious origin.
  • Work in a separate profile — company browser profile separate from personal. Cookies, passwords, and history do not mix.

6. Report Suspicious E-mails / Incidents Internally

If an employee receives a suspicious e-mail or clicks on something, the worst scenario is that they hide it. In that case the attacker has hours or days before monitoring detects them.

Create an internal channel for reports:

Policy: no penalties for reporting, even for your own mistake. Reward prompt reporting. Without this culture, incidents remain hidden.

Social Media and Professional Presence

LinkedIn, X (Twitter), Facebook, and Instagram are legitimate work tools, but also sources of risk:

  • Data from LinkedIn is a gold mine for attackers preparing spear-phishing — names of managers, colleagues, technologies, and projects.
  • Geotagged photos from a holiday signal that you are out of the office and less responsive to incidents.
  • Sharing company information (screenshots, screen-share videos) can inadvertently leak sensitive information.

A social media policy should define:

  • What must not be shared publicly (clients, NDA projects, financial figures)
  • How to separate personal and professional accounts
  • Responding to a PR crisis (no improvised employee statements on behalf of the company)

Mobile Devices and BYOD

Company data in 2026 largely lives on mobile phones — e-mail, Slack, ERP mobile app. Security minimum:

  • Lock screen with biometrics or PIN of at least 6 characters
  • Disk encryption (default in iOS and modern Android)
  • MDM (Mobile Device Management) — Microsoft Intune, Jamf — enables remote wipe if the device is lost
  • Separate business profiles on personal devices (BYOD)
  • No unofficial app stores (sideloading) — source of 90% of mobile malware

Summary and Employee Checklist

AreaActionFrequency
Password managerInstalled and activeAlways
2FA / PasskeyEnabled on e-mail, ERP, bankingAlways
PhishingVerify via different channel for sensitive requestsEvery request
Wi-FiPublic only via VPNEvery external access
BrowserAuto-update enabledAlways
ExtensionsAudit + remove unnecessary onesQuarterly
Incident reportingInternal channel immediatelyEvery anomaly
Mobile phoneLock screen + MDM enrolmentAlways
TrainingPhishing simulation + e-learning4× per year

The combination of these habits with an investment of 20–50/employee/year in training and a password manager reduces successful attacks by 80% or more. That is the best ROI in all of business IT security.

How Modulario Supports Safe Behaviour

Modulario has built-in technical controls that take some responsibility off the individual employee:

  • 2FA / Passkey mandatory for administrators, optional for all users
  • SSO via Azure AD / Google Workspace — one login point, easily revocable
  • Audit log of every action — anomalies are detected quickly
  • IP whitelisting for critical functions
  • Session timeout with configurable duration
  • Anomalous login detection (new device, new geo-location)

Detail in the security documentation. For the broader company cybersecurity agenda, see the pillar Cybersecurity of Company Data.

Frequently Asked Questions

What are the most common mistakes employees make when working online? Three dominant mistakes in 2026: (1) clicking a phishing link without verifying the sender — especially with ‘urgent’ messages, (2) reusing passwords across services — a breach of one compromises all, (3) connecting to public Wi-Fi without a VPN — especially at airports and hotels. Training and a password manager resolve 80% of incidents.

How do I recognise a phishing e-mail? Seven signs: (1) unexpected sender or unknown domain in the address, (2) urgency or fear in the subject line (‘your account will be blocked’), (3) grammar and style that does not match your business context, (4) a URL that when hovered looks different from the link text, (5) attachments in unexpected formats (.zip, .exe, .iso, macro-enabled .docx), (6) a request for sensitive information via e-mail (passwords, OTP, card details), (7) reply-to addresses that do not belong to the sender’s company. If you see 2 or more of these, it is very likely phishing.

Is public Wi-Fi safe for business work? Not without a VPN. Public Wi-Fi (airports, cafés, hotels) can be intercepted, but modern HTTPS encryption mitigates most risks. The real problem is the ‘evil twin’ — an attacker creates a Wi-Fi network with the same name as the legitimate one and intercepts all traffic. Solution: always-on company VPN for remote access, never log into business systems from public Wi-Fi without a VPN, mobile hotspot as a safer alternative.