One Click Cost MGM Resorts $100 Million
In September 2023, a threat actor called Scattered Spider called MGM Resorts' IT help desk, impersonated an employee, and gained access to internal systems. The result? Over $100 million in losses, days of disrupted operations, and a data breach affecting millions of guests. The attack didn't start with a sophisticated zero-day exploit. It started with a phone call.
That's why cybersecurity best practices for employees aren't optional — they're your actual first line of defense. Every ransomware attack, every credential theft incident, every business email compromise traces back to a human decision. This post covers the specific, practical steps your employees need to follow right now to stop being the weakest link.
Why Employees Are the #1 Attack Surface
The 2024 Verizon Data Breach Investigations Report found that 68% of breaches involved a human element — whether through social engineering, errors, or misuse of credentials. That number has hovered above 60% for years. Your firewalls and endpoint detection tools matter, but they can't stop an employee from handing over their password to a convincing phishing email.
Threat actors know this. They don't waste time trying to brute-force your perimeter when they can send a well-crafted email and get an employee to do it for them. I've seen organizations with seven-figure security budgets get compromised because one person in accounts payable clicked a link and entered their credentials on a spoofed login page.
The fix isn't just technology. It's behavior change. And that starts with clear, actionable cybersecurity best practices for employees that people can actually remember and follow.
The 10 Practices That Actually Prevent Breaches
1. Treat Every Unexpected Email as Suspicious
Phishing remains the top initial access vector for data breaches. Train your employees to pause before clicking any link or opening any attachment they weren't expecting — even if it appears to come from a known contact. If the CEO is suddenly asking for gift cards via email, that's not the CEO.
Organizations should run regular phishing awareness training with simulated attacks. Simulations build muscle memory. Employees who've been tested are significantly less likely to fall for the real thing.
2. Use Strong, Unique Passwords Everywhere
Credential theft is the gateway to everything else. If your employees reuse passwords across personal and work accounts, a breach at some random consumer app can hand attackers the keys to your corporate network.
Mandate a password manager. Require passwords of at least 16 characters. And never, ever allow password reuse across accounts.
3. Enable Multi-Factor Authentication on Everything
Multi-factor authentication (MFA) stops the vast majority of credential-stuffing and password-spraying attacks cold. According to CISA's MFA guidance, enabling MFA can prevent more than 99% of account compromise attacks.
Push-based MFA or hardware security keys are far stronger than SMS codes. If your organization still relies on SMS-based MFA, you're vulnerable to SIM-swapping attacks — exactly the technique used in the MGM breach.
4. Lock Screens and Devices — Always
This sounds basic. It is basic. And I still walk through offices where people leave laptops unlocked and unattended. Set auto-lock to 60 seconds or less. Make it policy. Enforce it.
5. Verify Unusual Requests Through a Second Channel
Business email compromise (BEC) caused over $2.9 billion in losses in 2023, according to the FBI's IC3 Annual Report. The defense is simple: if someone emails you asking for a wire transfer, a password reset, or sensitive data, pick up the phone and verify. Use a known number — not the one in the email signature.
6. Never Use Public Wi-Fi Without a VPN
Hotel Wi-Fi, airport Wi-Fi, coffee shop Wi-Fi — they're all hunting grounds for attackers running man-in-the-middle attacks. Your employees should either use a corporate VPN or avoid accessing work systems on public networks entirely.
7. Report Incidents Immediately — Even "Small" Ones
I've investigated breaches where the initial compromise happened weeks before anyone reported it. An employee clicked a phishing link, realized it looked wrong, closed the tab, and said nothing. By the time the security team discovered lateral movement, the attacker had exfiltrated thousands of records.
Build a culture where reporting a potential incident is rewarded, not punished. Speed is everything in incident response.
8. Keep Software Updated — No Exceptions
Unpatched vulnerabilities are the second-most common initial access vector after phishing. When your laptop says "Update available," don't click "Remind me later" for three months. Those patches exist because someone found a way to exploit the old version.
9. Understand Social Engineering Beyond Email
Phishing emails get all the attention, but social engineering happens over phone calls (vishing), text messages (smishing), LinkedIn messages, and even in person. The MGM attack was pure social engineering over the phone. Your employees need to understand that threat actors are trained manipulators who exploit trust, urgency, and authority.
A comprehensive cybersecurity awareness training program covers all of these vectors — not just email.
10. Follow Zero Trust Principles in Daily Work
Zero trust isn't just a network architecture buzzword. It's a mindset. Employees should operate with the assumption that any account, device, or network could be compromised. That means verifying identities before sharing information, limiting data access to what's needed for the task, and questioning anything that feels off.
What Are Cybersecurity Best Practices for Employees?
Cybersecurity best practices for employees are the specific behaviors and habits that reduce the risk of a data breach, credential theft, or ransomware attack. They include using strong unique passwords, enabling multi-factor authentication, recognizing phishing and social engineering attempts, reporting suspicious activity immediately, keeping software updated, and following zero trust principles. These practices are most effective when reinforced through ongoing security awareness training and regular phishing simulations.
The $4.88M Lesson Most Organizations Learn Too Late
IBM's 2024 Cost of a Data Breach Report put the global average cost of a data breach at $4.88 million. For U.S. organizations, the number was even higher. And here's the part that should keep you up at night: organizations with untrained employees and no incident response plan paid significantly more than those with mature security awareness programs.
Training isn't a checkbox. It's a financial decision. Every dollar you invest in teaching your people to recognize a phishing simulation, question a suspicious request, or lock their workstation is a dollar that could save you millions in breach costs, regulatory fines, and reputational damage.
Building Habits, Not Just Awareness
The difference between security awareness and security behavior is practice. Your employees can know that phishing exists and still click the link when they're stressed, busy, or distracted. That's human nature.
Effective training programs use repetition, realistic scenarios, and immediate feedback. They don't just lecture — they test. They make security habits automatic, like putting on a seatbelt.
I recommend starting with a structured cybersecurity awareness training course that covers the fundamentals, then layering in phishing simulations for your organization to keep skills sharp over time.
Your Employees Are Either Your Biggest Risk or Your Best Defense
There's no middle ground. Every person with a corporate email address, a login credential, or access to sensitive data is a potential entry point for threat actors. But with the right training and the right habits, those same people become sensors — detecting threats that your technology stack misses.
The organizations that get this right don't just avoid breaches. They build a security culture where every employee understands that cybersecurity isn't IT's job. It's everyone's job.
Start today. Review the practices above with your team. Identify the gaps. And invest in training that changes behavior — not just slides that check a compliance box. The NIST Cybersecurity Framework provides an excellent foundation for building a comprehensive approach, and your employees are the most critical component of that framework.
Because the next attack won't start with a firewall bypass. It'll start with a phone call, a phishing email, or a reused password. And your employees will either stop it — or let it in.