One Click Cost MGM Resorts $100 Million
In September 2023, a threat actor called Scattered Spider social-engineered an MGM Resorts employee through a simple phone call to the IT help desk. That single conversation — not a sophisticated zero-day exploit, not a nation-state attack — led to a ransomware incident that shut down slot machines, hotel room keys, and reservation systems across Las Vegas. MGM later disclosed the breach cost roughly $100 million.
That's the reality I keep coming back to when organizations ask me about cybersecurity best practices for employees. The firewall didn't fail. The endpoint detection didn't fail. A human interaction failed. And until your employees understand exactly how threat actors exploit them, your security stack is just expensive decoration.
This post breaks down the specific, actionable practices every employee — from the front desk to the C-suite — needs to follow right now. Not theory. Not a compliance checklist. The stuff that actually stops breaches.
Why Employees Are the Primary Attack Surface
The 2024 Verizon Data Breach Investigations Report found that 68% of breaches involved a non-malicious human element — someone clicking a phishing link, reusing a password, or misconfiguring a system. That number has hovered above 60% for years. It's not a trend. It's a constant.
I've worked incident response cases where organizations had millions invested in security tooling but zero investment in their people. The pattern is always the same: a well-crafted phishing email, a moment of inattention, and suddenly a threat actor has valid credentials inside the network.
Your employees aren't your weakest link because they're careless. They're the weakest link because nobody trained them to think like an attacker. That changes today.
The Core Cybersecurity Best Practices for Employees
1. Treat Every Email Like a Potential Attack
Phishing remains the number one initial access vector. According to the FBI's Internet Crime Complaint Center (IC3), phishing and its variants generated more complaints than any other cybercrime category in their most recent annual report.
Here's what I tell every employee I train: before you click anything, ask three questions. Who sent this? Were you expecting it? Does the action it's requesting make sense? If any answer is uncertain, pick up the phone and verify through a known number — not the one in the email.
Running regular phishing simulations is essential to building this muscle memory. Our phishing awareness training for organizations gives your team realistic scenarios so they practice spotting credential theft attempts before real ones land in their inbox.
2. Use Strong, Unique Passwords With a Password Manager
Credential stuffing attacks work because people reuse passwords. Period. If your employees use the same password for their corporate email and their fantasy football league, you've got a problem.
Every employee should use a password manager to generate and store unique passwords of at least 16 characters. No exceptions for "low-priority" accounts — attackers use those as stepping stones.
3. Enable Multi-Factor Authentication Everywhere
Multi-factor authentication (MFA) stops the vast majority of automated credential theft attacks. CISA has been shouting this from the rooftops for years, and the data backs them up.
But not all MFA is equal. SMS-based codes are better than nothing, but phishing-resistant MFA — hardware security keys or passkeys — is the standard your organization should aim for. After the MGM breach, even Okta recommended phishing-resistant MFA for help desk verifications.
4. Lock Down Your Devices — All of Them
Every employee device that touches company data is a potential entry point. The basics matter:
- Enable automatic OS and software updates. Unpatched systems are low-hanging fruit.
- Use full-disk encryption on laptops.
- Set screen locks to activate after 60 seconds of inactivity.
- Never connect to public Wi-Fi without a company VPN.
Remote work has expanded the attack surface dramatically. If your employees work from coffee shops and airport lounges, these practices aren't optional — they're survival.
5. Report Suspicious Activity Immediately
In my experience, the difference between a contained incident and a catastrophic breach often comes down to reporting speed. The employee who flags a suspicious email within five minutes gives your security team a fighting chance. The one who ignores it or tries to handle it alone gives the attacker time.
Build a culture where reporting is rewarded, never punished. If someone clicks a phishing link and reports it immediately, that's a win — not a write-up.
What Does a Zero Trust Mindset Look Like for Employees?
Zero trust isn't just a network architecture concept. It's a mindset every employee can adopt. In practical terms, it means: never assume any request, person, or system is legitimate just because it appears to come from inside the organization.
That means verifying unexpected requests from your boss through a second channel. It means questioning why an IT support call is asking for your password (legitimate IT will never do this). It means treating internal emails with the same skepticism as external ones, because once a threat actor compromises one account, they use it to phish colleagues.
Zero trust for employees boils down to one rule: verify everything, trust nothing by default.
Social Engineering Goes Far Beyond Email
Voice Phishing (Vishing) Is Surging
The MGM breach happened over the phone. So did multiple incidents tied to the Scattered Spider group throughout 2023 and 2024. Threat actors are calling employees, impersonating IT support, vendors, or executives, and extracting credentials or convincing staff to take actions that compromise security.
Train your employees to handle unexpected calls with the same caution they'd apply to emails. Establish callback verification procedures. If someone calls claiming to be from IT and asks you to install software or share a one-time code, hang up and call IT directly.
Physical Security Still Matters
Tailgating — following an authorized person through a secured door — remains one of the simplest social engineering techniques. I've seen penetration testers walk into server rooms simply by carrying a box and looking like they belonged.
Employees should challenge unfamiliar faces in secure areas, never hold doors for people they don't recognize, and report propped-open doors immediately.
The $4.88M Lesson Most Organizations Learn Too Late
IBM's 2024 Cost of a Data Breach Report pegged the global average breach cost at $4.88 million — the highest ever recorded. Organizations with comprehensive security awareness training and incident response planning consistently saw lower costs and faster containment.
The math is simple. Investing in employee training costs a fraction of a breach. Not investing is a gamble with seven-figure consequences.
Our cybersecurity awareness training program covers all the practices in this post and more, giving your team the knowledge to recognize and resist real-world attacks. Pair it with our phishing simulation training to measure and improve your organization's resilience over time.
Building Cybersecurity Best Practices Into Daily Habits
Knowing the rules isn't enough. Your employees need to live them daily. Here's how to make that happen:
- Quarterly training refreshers. Annual compliance training doesn't change behavior. Short, frequent sessions do.
- Simulated phishing campaigns. Test employees monthly. Track who clicks, who reports, and coach accordingly.
- Clear escalation paths. Every employee should know exactly who to contact and how when something looks suspicious.
- Leadership modeling. When executives follow the same rules — using MFA, reporting phishing, attending training — it signals that security is everyone's job.
Cybersecurity best practices for employees aren't a one-time initiative. They're an ongoing discipline, like physical fitness. Skip the gym for six months and you'll feel it. Skip security awareness for six months and a threat actor will make you feel it.
Start With What You Can Control
You can't control what threat actors do. You can't predict the next zero-day vulnerability. But you can control how prepared your employees are when — not if — an attack targets them.
Every practice in this post is something your team can implement this week. Strong passwords with a manager. MFA on every account. A healthy suspicion of unexpected requests. A reporting culture that treats vigilance as a core value.
The organizations that get breached aren't always the ones with the worst technology. They're the ones that never taught their people how to fight back. Refer to NIST's Cybersecurity Framework for a structured approach to building these practices into your organization's DNA.
Don't wait for your own $100 million lesson.