Secure Onboarding: How to Avoid Password Mistakes for New Employees?

MarGib June 25, 2026
🌐 🇵🇱 Polski · 🇬🇧 EN

A new employee gains access to company systems, and just days later falls victim to phishing. Sounds abstract? CERT and NIST reports prove this is an everyday reality. Errors in the onboarding process—especially those related to passwords—cost companies millions, not just financially but also in terms of reputation. How can you avoid them?

Ilustracja przedstawiająca nowoczesne biuro z ekranem logowania otoczonym ikonami ochrony danych, w stylu futurystycznym
Modern login screen secured with data protection icons

As new employees join companies, the risk of cyberattacks also rises. According to the Verizon DBIR 2023, a staggering 81% of identity theft incidents stem from weak passwords or human error. The problem isn’t the technology itself but the processes surrounding it. All it takes is one poorly secured account to turn an entire network into an easy target.

The biggest paradox is that many companies spend millions on advanced security systems while neglecting the basics. Errors in onboarding new employees aren’t minor oversights—they’re a direct path to data breaches, intellectual property theft, or even operational shutdowns. What specific pitfalls await companies, and how can they be avoided?

Most common mistakes that open the door to cybercriminals

The onboarding process, though seemingly straightforward, is an area where companies repeatedly make systematic errors. Some stem from a lack of awareness, others from underestimating risk, and some from excessive bureaucracy. Here are the most frequent ones:

  • Low-complexity temporary passwords – New hires often receive simple combinations like “Password123!” or birthdates, which can be cracked in seconds using attacker dictionaries.
  • Manual password sharing – Sending login credentials via email, SMS, or even phone calls invites attackers to intercept communications.
  • Lack of two-factor authentication (2FA/MFA) – Despite its availability, many companies implement MFA only after the first incident. Password + SMS code is the bare minimum.
  • Long-lasting temporary passwords – One-time passwords (OTPs) or session-based credentials aren’t replaced with permanent ones, remaining active for weeks or even months.
  • Failure to rotate passwords with role changes – An employee who gets promoted or switches departments continues using the same old password, often weak and unused for years.

These mistakes aren’t just theoretical threats. According to the Ponemon Institute, 57% of companies don’t enforce password rotation when an employee changes roles, and 61% of employees reuse the same passwords for work and personal accounts. This is a straightforward path to attack escalation.

Statistics that should chill the blood of managers

Data collected by leading cybersecurity institutions leaves no room for doubt: weak passwords of new hires are a gateway for attacks.

Reports worth knowing

  • IBM Cost of a Data Breach Report 2023:
    • Average cost of a data breach: $4.45 million.
    • 16% of incidents result from weak passwords or access management errors.
    • Companies lose an average of $1.24 million on incidents linked to inadequate passwords.
  • CERT Poland 2023:
    • 34% of phishing incidents targeted newly hired employees.
    • Attacks were successful in 72% of cases because victims were unaware of security procedures.
  • NIST SP 800-63B (password guidelines):
    • Recommends abandoning requirements like “at least one uppercase letter and a digit,” which lead to predictable passwords.
    • Promotes long, random passphrases (e.g., “purpleelephantdancesatmidnight!”) instead of complex combinations.

These numbers show that the issue isn’t a lack of tools but their improper implementation. Companies that ignore these statistics risk not only financial losses but also the trust of customers and business partners.

How to secure the onboarding process? Proven mechanisms

Securing passwords for new hires shouldn’t be just a theoretical exercise for the IT department. The key is implementing consistent, automated procedures that minimize human error. Here are the mechanisms that work in practice:

1. Password policy aligned with NIST guidelines

Instead of enforcing complex combinations that are easy to remember (and crack), it’s better to use a long, random passphrase approach. Examples of strong passwords:

  • “purpleelephantdancesatmidnight!”
  • “CorrectHorseBatteryStaple2024”
  • “BlueSkyOverTheMountain2024!”

Avoid:

  • Passwords based on public information (name, surname, birthdate).
  • Simple sequences (e.g., “123456”, “QWERTY”).
  • Previously used passwords (checked via tools like Have I Been Pwned).

2. Enforcing MFA (Multi-Factor Authentication) from the first login

Two-factor authentication is no longer an option but a necessity. The most commonly used methods include:

  • SMS codes or authenticator apps (Google Authenticator, Authy).
  • Hardware keys (YubiKey, Titan Security Key).
  • Push notifications (e.g., Duo Mobile).

According to CISA, implementing MFA reduces the risk of a successful attack by 99.9%.

3. Temporary passwords with limited validity

Instead of manually granting access, consider using one-time passwords (OTPs) or session-based credentials that expire after a few hours. Examples:

  • Password valid for only 12 hours, after which the user must change it.
  • Code sent to a trusted device (e.g., company phone).

4. Automation via IAM (Identity and Access Management) systems

Tools like Okta, Microsoft Entra ID (formerly Azure AD), or JumpCloud enable:

  • Automated access provisioning based on roles (e.g., a new sales employee gains access to CRM and sales tools).
  • Enforcing password rotation when an employee changes roles.
  • Periodic access reviews (e.g., every 3 months).

5. Education and simulated phishing attacks

Security isn’t just about technology—it’s also about employee awareness. According to the SANS Institute, companies that regularly conduct training and phishing tests reduce the risk of successful attacks by 70%.

Best practices include:

  • Simulated phishing messages sent to new employees in their first weeks.
  • Training on recognizing suspicious links and attachments.
  • Regular reminders about password policies (e.g., via internal newsletters).

Cases that should serve as a warning to every company

Errors in onboarding aren’t just theoretical threats. There are numerous real-world cases where negligence in this area led to serious incidents. Here are two of them:

1. Uber (2022) – Phishing targeting a newly hired employee

Incident: A hacker gained access to company systems through phishing targeting a newly hired employee who shared their credentials.

Consequences:

  • Theft of customer and employee data.
  • Incident cost: $1.1 million (including fines and damage repair).
  • Loss of customer and partner trust.

Source: [BleepingComputer]

2. Twilio (2021) – Phishing attack on new employees

Incident: Attackers impersonated the IT department and sent fake notifications about the need to change passwords. New employees shared their credentials, leading to the theft of SMS data.

Consequences:

  • Customer data exposed to potential leaks.
  • Threat of a $10 million fine for GDPR violations.
  • Loss of reputation and market trust.

Source: [TechCrunch]

These cases show that errors in onboarding aren’t just a technical issue but a real threat to the entire organization. Companies that ignore these signals risk not only financial losses but also a loss of competitiveness.

Tools that simplify secure onboarding

Choosing the right tools is a critical step in building a secure onboarding process. Here are solutions that have proven effective in practice:

1. IAM (Identity and Access Management) systems

  • Okta – Automated access provisioning, built-in password policies, and MFA.
  • Microsoft Entra ID – Integration with the Office 365 suite, hardware key support.
  • JumpCloud – Cloud-based solution with device management capabilities.

2. Password managers

  • Bitwarden – Open-source password manager with a generator and rotation policy.
  • 1Password – Secure password storage with a Travel Mode feature (hiding data during travel).
  • Keeper – Enterprise solution with password audit capabilities.

3. Data breach detection tools

  • Have I Been Pwned – Checking if a password or email has been compromised.
  • Dehashed – Monitoring the dark web for leaks of company data.

4. Phishing simulation systems

  • KnowBe4 – Platform for conducting phishing tests and training.
  • PhishMe – Tool for creating realistic attack simulations.

Legal and financial consequences of negligence

Errors in onboarding don’t come without consequences. Companies that neglect password security expose themselves to serious financial, legal, and reputational risks.

1. Fines for GDPR violations

The General Data Protection Regulation (GDPR) mandates that companies ensure an adequate level of security. Violations can result in:

  • Fines up to 4% of global revenue or €20 million (whichever is higher).
  • Obligation to notify the supervisory authority and affected individuals within 72 hours.
  • Compensation claims from affected parties.

Examples of fines:

  • Amazon€746 million fine (2021) for insufficient protection of customer data.
  • Meta (Facebook)€1.2 billion fine (2023) for transferring data to the U.S.
  • British Airways£20 million fine (2020) for the leak of 500,000 customer records.

2. Civil and criminal liability

In some jurisdictions (e.g., the U.S.), companies can be held civilly liable for negligence in security. Examples:

  • Employers may be required to pay compensation to affected customers.
  • In cases of deliberate negligence, liability may also include criminal penalties.

Example from the U.S.:

  • The Equifax breach resulted in a $700 million fine (2019) for exposing data of 147 million customers. Part of the fine stemmed from negligence in the onboarding process of contractors.

3. Loss of reputation and customer trust

The costs associated with reputational damage are hard to quantify but often exceed financial penalties. According to PwC, 63% of customers discontinue services with a company after a data security incident. Additionally, difficulties in acquiring new customers and business partners can last for years.

Summary: Secure onboarding checklist

To minimize the risk of errors in the onboarding process, use the following checklist. Adapt it to your company’s specifics and existing procedures:

Before hiring

  • Define roles and permissions – Create an RACI matrix (Responsible, Accountable, Consulted, Informed) for each role.
  • Prepare a password policy – Specify password requirements (length, complexity, rotation) aligned with NIST guidelines.
  • Plan security training – Develop educational materials for new employees covering phishing, password management, and MFA.

On the first day

  • Automate access provisioning – Use an IAM system to assign permissions based on role.
  • Enforce MFA – Require a second authentication factor on the first login.
  • Provide a temporary password – Use a one-time password (OTP) or session-based credential valid for only a few hours.

In the first week

  • Change to a permanent password – The new employee must change the temporary password to a personal one compliant with company policy.
  • Simulated phishing attack – Test the new employee’s awareness using tools like KnowBe4.
  • Reminder about password policy – Send an email summarizing rules and best practices.

Regular reviews

  • Password rotation – Enforce password changes every 90 days (or more frequently if necessary).
  • Access audits – Check if employees have excessive permissions.
  • Ongoing training – Organize quarterly cybersecurity workshops.

Remember: Security isn’t a one-time action but an ongoing process. Companies that treat onboarding as an opportunity to strengthen protection—not just a formality—build lasting competitive advantages.

Sources

Facebook X E-mail

Comments

Dodaj komentarz

Explore

Labels

artificial intelligence 11 news 11 Windows 10 browsers 10 Opera 9 Security 9 facebook 8 web applications 8 Automation 7 Software 7 Technology 7 chrome 7 coaching 7 curiosities 7 www 7 Docker 6 Microsoft 6 Mind 6 Web browser 6 entertainment 6 new technologies 6 technology 6 Cybersecurity 5 God 5 Red Hat 5 automation 5 books 5 Anthropic 4 CentOS 4 LLM 4 Open Source 4 Productivity 4 Programming 4 RedHat 4 Vivaldi 4 Windows 10 4 Windows system administration 4 applications 4 containers 4 education 4 health 4 people 4 photography 4 trivia 4 Android 3 BIG DATA 3 Business 3 Claude 3 FAQ 3 FIFA 3 Firefox 3 Google projects 3 Local AI 3 OpenAI 3 Personal Development 3 Privacy 3 Programs 3 Ubuntu 3 algorithms 3 bash 3 communication 3 computer science 3 extensions 3 faith 3 games 3 good movie 3 help 3 human 3 interesting websites 3 interface 3 media 3 money 3 n8n 3 network 3 opensource 3 personal competencies 3 personal development 3 programming 3 psychology 3 reading 3 religion 3 security 3 system administration 3 tools 3 virtualization 3 web browser 3 websites 3 AI assistant 2 Administration 2 Asus 2 Career 2 Centos 2 Claude AI 2 Cloud 2 Configuration 2 Debian 2 DevOps 2 Docker Machine 2 Drones 2 Education 2 Free Red Hat 2 Hardware 2 Intel 2 Intelligence 2 Job Market 2 Machine Learning 2 Performance 2 Personal Finance 2 Psychology 2 RHEL7 2 RSS 2 Rocky Linux 2 Servers 2 Software Engineering 2 Windows administration 2 Windows errors 2 ansible 2 better life 2 brain 2 chat 2 children 2 cloud storage 2 communicator 2 communities 2 computer intelligence 2 computers 2 conferences 2 creativity 2 curl 2 cyberattacks 2 cybersecurity 2 data 2 death 2 documentary 2 earning 2 emotions 2 file storage 2 fix 2 free application 2 free courses 2 free knowledge from the internet 2 free training 2 genius 2 hacker 2 investments 2 knowledge 2 learning 2 local AI 2 machine learning 2 mind manipulation 2 mind programming 2 mindfulness 2 mobile 2 mobile apps 2 mobile phones 2 motivation 2 movie 2 multimedia 2 open-source 2 personal thoughts 2 photos 2 plugin 2 podcast 2 privacy 2 prompt 2 shell 2 software 2 terminal 2 torrent 2 trick 2 wealth 2 weather 2 web 2 wisdom 2 youtube 2 (Treści etykiet nie zostały podane w treści wejściowej) 1 120B models 1 21st Century Skills 1 64 bit 1 7 1 ACT therapy 1 AGI 1 AI Agents 1 AI Frameworks 1 AI History 1 AI Safety 1 AI benchmarks 1 AI censorship 1 AI ethics 1 AI future 1 AI governance 1 AI in healthcare 1 AI in sports 1 AI superchips 1 AIMP 1 AMD ROCm 1 Acquisition 1 Alan Watts 1 Alexander Gerst 1 AlmaLinux 1 Alpine Linux 1 Andrej Karpathy 1 Anonymous 1 Apache 1 Apple 1 Apple Silicon 1 Aria AI 1 Audacity 4 1 Banking 1 Bash 1 Bill Warner 1 Biotechnology 1 Black Mirror 1 Blackwell B100 1 Blockchain 1 Bonding 1 Bono 1 Business and Finance 1 C++ 1 CPU 1 CUA 1 CUDA 1 Career Development 1 Chat GPT 1 ChatGPT 1 Chemtrails 1 ChildOnlineSafety 1 Claude Fable 1 Coaching 1 Codex 1 Computer-Using Agent 1 Constitutional AI 1 Copilot 1 Couching 1 Cryptocurrencies 1 Cyberbullying 1 Dario Amodei 1 Darwin 1 Data Science 1 Debugging 1 Deep Learning 1 DeepSeek 1 Deepseek 1 Deluge 1 Diagnostics 1 Digitalization 1 Docker containers 1 Drivers 1 Dystrybucje 1 EA GAMES 1 EA SPORTS 1 Economics 1 Email 1 Emigration 1 Enterprise Linux 1 Entrepreneurship 1 Error 1 Excel 1 FIFA 16 1 Fable 1 Fact-checking 1 Fake News 1 Flannel 1 Flynn Effect 1 Football 1 Foundation 1 Free 1 Free Software 1 Free software 1 Fugu Ultra 1 Future 1 Future of Finance 1 Future of Work 1 GDPR 1 GLM-5.2 1 GPT 1 GPT-4 1 GPT-4.5 1 GPU Cloud 1 GUI 1 Gemini 1 Generation Z 1 GitHub 1 Golden Gate 1 Google Assistant 1 Google Gemma 4 12B 1 Google activity 1 GoogleFamilyLink 1 Got Talent 1 Gregory Kurtzer 1 Guide 1 Guides 1 HTML 1 Hardware Requirements 1 Homelab 1 Hygge 1 IAM 1 IBM 1 IDE 1 IQ 1 ISIS 1 ISS 1 IT 1 IT history 1 Intelligent email 1 Internet Browser 1 Internet browser 1 InternetEducation 1 Interview 1 Islam 1 Islamic State 1 Jacquard 1 Japan 1 JavaScript 1 Jboss 1 Jetson Thor price 1 Joel Pearson 1 Kali Linux 1 Kernel 1 Khan Academy 1 Kylian Mbappé 1 LLM Deployment 1 Labor Market 1 Legal regulations 1 LibreOffice 1 Linux diagnostics 1 Londoners 1 MFA 1 MLX 1 Maps 1 MarGib_Film 1 Marek Jankowski 1 Mars helicopter 1 Material Design 1 Medicine 1 Microsoft 365 1 Military 1 Mindfulness 1 Miłosz Brzeziński 1 MrBallen 1 My take 1 Mythos 1 NTFS 1 NVIDIA 1 NVIDIA Blackwell 1 NVIDIA Jetson Thor 1 National security 1 Navy SEALs 1 Netflix 1 Neural Networks 1 New 1 Nginx 1 No comment 1 Node.js 1 Non-profit 1 Notion 1 Nvidia 1 Odysseus 1 Opera Air 1 Opera Neon 1 Opera Touch 1 P2P 1 Pac-Man 1 Pekao S.A 1 Peperclips 1 Perceptron 1 Personal development 1 Philosophy 1 Photoshop 1 Poland 1 Poles 1 PowerShell 1 Project TANGO 1 Proton Drive 1 Puppeteer 1 PyTorch 1 Qt Creator 1 Quotes 1 RHEL8 1 Raspberry PI 1 Raspbian 1 Red Hat 8 1 Red Hat Enterprise Linux Developer Suite 1 RedHat 8 1 Regex 1 Robo-advisors 1 Rust 1 SUSE 1 SafeInternet 1 SaferInternetDay 1 Safety 1 Sakana AI 1 Search 1 Security Auditing 1 Self-hosting 1 September 23 2017 1 Server Administration 1 Smart City 1 Snip. 1 Social Media 1 Soli 1 Solo Projects 1 Solopreneurship 1 Something from myself 1 Sound 1 Sovereign AI 1 Sport 1 Steam Deck 1 SysAdmin 1 System Administration 1 Tech 1 TensorFlow 1 The Shack 1 Time Management 1 Tips 1 Tokenomics 1 Tools 1 Tribler 1 Tutorial 1 U2 1 USB 1 Ubuntu 26.04 1 Ubuntu Server 1 VentuSky 1 WBC 1 WSL 3 1 WWDC 2026 1 WWDC26 1 Warsaw 1 Weave 1 Web Scraping 1 Websites 1 Windows update 1 Work 1 Workflow 1 World Cup 1 World Cup 2026 1 World Wide Web 1 X-Files 1 X-files 1 YouTube 1 ZUS 1 ZenFone 1 a drop of motivation 1 about this blog 1 achieving goals 1 ad blocking 1 addiction 1 administrator 1 aids 1 animations 1 assertiveness 1 audio 1 audio editing 1 automateit 1 autonomous cars 1 awareness 1 bank 1 bash on windows 1 bat files 1 batch 1 battery 1 beliefs 1 beta 1 better living 1 better quality 1 bin/bash 1 blocking 1 blogger 1 body language 1 bookmarks 1 boot 1 bootable usb 1 boxing 1 brain-computer interfaces 1 business intelligence 1 c# 1 calc 1 campaign 1 cards 1 centralized platforms 1 chemistry 1 clearance 1 clothing industry 1 cmd 1 code editor 1 cognitive psychology 1 coldplay 1 command history 1 command line 1 command prompt 1 comments 1 computer interaction 1 concentration 1 configuration management 1 conntrack 1 console 1 conspiracy 1 conspiracy theories 1 controversial 1 converter 1 corporate world 1 courses 1 courses for free 1 dark mode 1 data security 1 date and time 1 deep learning 1 developer tools 1 digital clothing 1 disqus 1 document 1 dreams 1 drop of motivation 1 dubai 1 dying 1 e-book 1 eBPF 1 economy 1 end of the world 1 end of world 1 energy 1 energy efficiency 1 environment and health 1 ethical AI 1 evolution 1 excel 1 exploitation 1 extreme 1 file sharing 1 file size 1 film zone 1 flash drive 1 flat earth 1 flying 1 food 1 football 1 for sale 1 format change 1 free 1 free software 1 friend location 1 future of humanity 1 future of transport 1 future of work 1 game 1 geoengineering 1 google chat 1 graphics 1 graphics editors 1 growing up 1 hacking 1 happiness 1 hard-link 1 hashing 1 hedonic adaptation 1 helion 1 history 1 hobby 1 home hosting 1 hostname 1 hostnamectl 1 how many people live on earth 1 humanity 1 humor 1 iOS 1 iftop 1 immortality 1 influencer criticism 1 infrastructure 1 innovation 1 installation 1 intelligence 1 internet applications 1 investing 1 javascript 1 kuba wojewódzki 1 labor market 1 language models 1 light 1 login 1 macOS 1 magic 1 make life harder 1 making money 1 material design 1 meditation 1 memory 1 messenger 1 meteorology 1 mobile applications 1 mobile photography 1 mounting 1 mp3 player 1 music 1 music player 1 mysteries 1 net use 1 nethogs 1 network monitoring 1 network resources 1 network security 1 networking 1 neurobiology 1 neuropsychology 1 neurotechnology 1 new life 1 new player 1 new things 1 nftables 1 office 1 onboarding 1 onestep4red 1 online 1 online courses 1 open source 1 operating systems 1 outage 1 paper clips 1 paradox of the fulfilled dream 1 parenting 1 parents 1 password 1 password change 1 password policy 1 password recovery 1 password security 1 pdf 1 penetration testing 1 performance 1 personal data 1 philosophy 1 phishing 1 php 1 plague 1 player 1 poison 1 police 1 predictions 1 promissory notes 1 protection 1 questions 1 radar 1 red 1 relax 1 relaxation 1 remote work 1 reportage 1 rest 1 robotaxi 1 root 1 science 1 scientific facts 1 screen 1 screenshot 1 series 1 show 1 skydive 1 sleep 1 small big company 1 smart clothing 1 smartphone 1 social engineering 1 social media 1 society 1 space 1 sport 1 sports 1 spreadsheet 1 stalking 1 statistics 1 sub-millimeter sensor 1 success 1 symbolic link 1 syngrapha 1 system acceleration 1 tablet 1 talk show 1 technological innovations 1 television 1 terrorism 1 testing 1 the world in numbers 1 threats 1 time management 1 time travel 1 timelapse 1 tips 1 ubuntu 1 upbringing 1 users 1 viral 1 virtualbox 1 walking 1 walking meetings 1 weather forecasting 1 webmaster 1 windows automation 1 word processing 1 work 1 world 1 world cup 2026 1 world wide web 1 you are a miracle 1 zeitgeist 1

Blog archive

Table of contents