Cyber Security for Administrative Professionals

We hear people in the Information Technology (IT) arena speak of cyber risks and security. We hear on the news about cyber-attacks. When you hear this, do you think, “Nah, it won’t happen to me.” As administrative professionals, we hold the key (literally) to a lot of information. We have access to office systems, our bosses’ credit cards and a variety of sensitive company information, making us a target for possible cyber-attacks. So, what do we do to protect ourselves, our bosses, and our company from getting attacked?


Be informed: Step one is to be informed and accept that we are indeed targets for cyber-attacks. These attacks can come via phone calls, messages, emails and even in-person. In today’s digital world, we communicate with our bosses and colleagues not only in-person or via emails, but also via social media, text messages and mobile applications like WhatsApp. We regularly access office emails, intranet and other office resources via iPad and mobiles; all of which are prone to possible attacks.


Be safe: Now we know we are vulnerable to attacks, learn ways to be safe. Here are a few.

  • Set strong passwords (not pet’s name, partner’s or kid’s birthdays). Use two-factor authentication where possible.

  • Periodically change passwords, use a password manager like True key. With so many passwords, it can be challenging to remember them all and writing it down may not always be the best solution.

  • Always have an active anti-virus on all devices.

  • If you have smart devices at home or work (like Alexa or home security devices), make sure they are protected well and control the level of information. They too are susceptible to potential hacks as they carry IP addresses and store and share data.

  • Be cautious about which public WIFI you connect to. If possible, use a VPN when connecting to public WIFI.

  • Don’t accept free USB sticks from people or organizations you don’t know. They can come with hacking programs or viruses. 

  • With emails, be sure to check the complete email address to make sure it is from the intended person. Most email programs truncate the email address on display and without a complete view; a reply or link can lead to an unknown download or program carrying a virus. Even when the email address seems valid, ensure it is correct prior to clicking any links within the email. Hackers use smart ways to cheat up. They use ‘rn’ on an email address instead of ‘m’, especially when viewing on a mobile device as it may not be clearly viewed nor detected.  

  • When responding to request via message or call, especially if it involves making a payment or sharing some sensitive information, always double-check. Contact the same person through another method (email or call from another line) to make sure it is the right person who is asking for that sensitive information.

  • Always ensure that your software updates on your devices are current. 


Many companies are now making cybersecurity part of their culture. Companies train all employees on cyber-attack awareness and ways to be safe. It is not all gloom with technology. Technology is beneficial; ever-evolving, and like all things, we need to ensure we are all aware and to be cyber safe.


Published: Toronto chapter of the Canadian Association of Administrative Professionals Spring 2020 Edition newsletter 'The Connection' 

Comments