Think about what happens when someone joins your business. A laptop is set up, an email account is created, they are added to the right systems, and someone walks them round the office. What almost never happens is a conversation about the message they are going to receive in week two, apparently from you, asking them to buy gift cards.
That gap is not an accident. Attackers deliberately target new starters, and they do it for reasons that have nothing to do with how careful the person is.
A new starter has none of the context that protects everyone else
Your existing staff carry a quiet defense they never think about. They know your CEO does not send requests at 9pm. They know finance never changes bank details over email. They know which supplier invoices look normal. None of that is written down anywhere, and a person who started on Monday has none of it.
They also want to be helpful. A new employee who receives an urgent request from someone senior is in the worst possible position: unable to judge whether it is normal, and reluctant to be the person who slowed things down by asking.
Attackers know exactly when this window is open, because your business tells them. New-hire announcements on LinkedIn are a scheduling tool for social engineering.
What the attack usually looks like
It is rarely sophisticated. The common patterns are:
- A message from the owner or a director, sent from a free email account, explaining they are in meetings and need a quick favor
- A request to move a payment or change payroll details, framed as urgent and confidential
- A fake IT setup email asking the new starter to confirm their credentials to activate an account
- A supplier introduction that arrives just as the new person takes over an account, with new bank details attached
Each of these works better on someone in their first month than it ever will again.
Closing the window
The fix is mostly process, not technology, though technology helps.
Tell them the rules on day one. Not a policy document — two or three specific sentences. Nobody at this company will ever ask you to buy gift cards. Bank details never change over email. If a request feels urgent and unusual, ringing the person to check is always the right call, and you will never be criticized for it.
Give them the least access they need to start. Most breaches get worse than they need to because the compromised account could reach everything. A new starter rarely needs the whole file server in week one.
Make external mail obvious. A banner marking messages from outside the business removes the guesswork about whether the sender is really a colleague.
Put them into training immediately, not at the annual refresh. If your security awareness program runs once a year, someone hired in month two waits ten months for the training that would have protected them in month one.
Test rather than assume. A simulated phishing message in the first few weeks tells you something real, and a click on a simulation is a teaching moment rather than an incident.
This is an onboarding problem
Every business has an onboarding checklist. Security usually appears on it as “set up accounts” and nothing else. Adding four lines — the rules conversation, minimum access, external mail marking, and enrollment in training — costs nothing and closes the gap that attackers rely on.
If you would like help building that into your process, or you want to see how your team performs against a realistic simulation before you decide, talk to us.