Document Summary:

This document is intended for Falcon IT Services clients and serves as a baseline Acceptable Use and Employee Cybersecurity Policy that organizations can incorporate into their HR or employee on-boarding documentation.

The policies contained in this document represent a baseline of cybersecurity best practices for end users. Organizations may copy and incorporate this content into their own policies and may add, remove, modify, or further customize the requirements to align with their specific business operations, risk profile, regulatory obligations, and internal policy needs.

This document can be requested by contacting security [@] falconitservices [dot] com.

Employee Cybersecurity Policies and Acceptable Use Requirements

  1. Purpose

The purpose of these policies is to protect the company, its employees, customers, business partners, information, systems, and technology resources from cybersecurity threats, unauthorized access, data loss, fraud, and misuse.

Every employee who uses company technology, accesses company information, or conducts company business is responsible for following these requirements.

These requirements apply to company-owned and company-managed computers, mobile devices, accounts, applications, networks, cloud services, email, messaging systems, file storage, and other technology used for company business.

Employees are expected to use good judgment and to contact the Falcon IT Services Help Desk or designated IT/security contact whenever they are unsure whether an action is permitted.

These employee requirements do not replace the company’s Written Information Security Program (WISP), incident-response procedures, disaster-recovery procedures, business-continuity plans, or other administrative policies.


2. General Employee Responsibilities

Employees must:

  • Protect company information and technology from unauthorized access, disclosure, alteration, loss, or destruction.
  • Use company technology primarily for legitimate business purposes and in accordance with company policy.
  • Protect their usernames, passwords, authentication devices, and other credentials.
  • Follow instructions provided by the company’s IT and security personnel.
  • Use only approved devices, applications, services, and methods for conducting company business.
  • Access only the systems, files, applications, and information they are authorized to access.
  • Protect company equipment from theft, loss, damage, and unauthorized use.
  • Complete required cybersecurity awareness training. See https://falconitservices.com/cybersecurity-training-awareness-services/
  • Report suspected phishing, malware, compromised credentials, lost devices, suspicious activity, or accidental disclosure of sensitive information promptly to the Falcon IT Services Help Desk or designated security contact.
  • Ask for assistance before taking an action that could create a security or privacy risk.

Employees must not attempt to bypass security controls for convenience or to accomplish a business task more quickly.


3. Account and Credential Security

Each employee must use their own individual account and credentials.

Employees must:

  • Keep usernames, passwords, PINs, authentication codes, recovery codes, and security tokens confidential.
  • Use passwords that meet the company’s password requirements of 14 characters (minimum) that does not contain discoverable personal details.
  • Use passwords that are difficult for others to guess.
  • Use a unique password for each company account when separate passwords are required.
  • Not store password in electronic text, spreadsheets or in the cloud. Use an approved password manager when one is provided or keep passwords in a book that is kept in a safe or under lock and key until they are memorized.
  • Change a temporary password immediately when instructed to do so.
  • Lock their computer or device when leaving it unattended.
  • If you are given a static password that does not need to be changed, report it to security@falconitservices.com.

Employees must never:

  • Share their password with another employee, coworker, manager, contractor, or IT technician.
  • Allow another person to use their account.
  • Write passwords on sticky notes or leave them where unauthorized people can see them.
  • Store company passwords in personal notes applications, unapproved browsers, personal cloud storage, or other unauthorized locations.
  • Send passwords through email, text message, chat, or other unapproved communication methods.
  • Reuse company passwords for personal email, banking, social media, shopping, or other personal accounts.
  • Use another person’s credentials unless specifically authorized through an approved technical process.

IT personnel will not normally need an employee’s password. If someone claiming to be from IT asks for a password, the employee should verify the request through an established channel before providing any information.


4. Multifactor Authentication (MFA)

Employees must use multifactor authentication whenever it is required or enabled for a company account or system.

Employees must:

  • Protect their MFA device and authentication applications.
  • Keep MFA codes and recovery codes confidential.
  • Approve MFA requests only when they personally initiated the associated login or action.
  • Contact the Falcon IT Services Help Desk or security@falconitservices.com if unexpected MFA requests are received.

Employees must never approve an unexpected MFA prompt simply to make the notification stop.

Repeated unexpected MFA prompts may indicate that someone is attempting to access the employee’s account.

MFA codes must never be provided to another person unless an approved company procedure specifically requires it.


5. Phishing, Social Engineering, and Suspicious Communications

Employees must remain alert for phishing, impersonation, social engineering, fraud, and other attempts to trick them into revealing information or performing unauthorized actions.

Suspicious messages may arrive through:

  • Email
  • Text messages
  • Telephone calls
  • Voicemail
  • Microsoft Teams or other messaging platforms
  • Social media
  • Video conferencing
  • QR codes
  • Websites
  • In-person requests

Employees should be particularly cautious when a message:

  • Creates a sense of urgency or panic.
  • Requests a password or MFA code.
  • Requests confidential or sensitive information.
  • Requests a payment or financial transaction.
  • Requests a change to banking or payment information.
  • Claims to be from an executive, manager, customer, vendor, IT technician, or other trusted person.
  • Contains unexpected links or attachments.
  • Requests that normal procedures be bypassed.
  • Asks the employee to install software or allow remote access.
  • Uses unusual wording, addresses, telephone numbers, or communication methods.
  • Requests secrecy or instructs the employee not to verify the request.

Employees must independently verify unusual or sensitive requests before acting on them.

Do not rely solely on the email address, telephone number, caller ID, display name, or messaging account through which the request was received.

When in doubt, contact the Falcon IT Services Help Desk or the appropriate person using a known and trusted contact method.


6. Email and Messaging

Company email and messaging systems are provided for legitimate business purposes.

Employees must:

  • Use company-approved email and messaging systems for company business.
  • Exercise caution when opening attachments or clicking links.
  • Verify unexpected requests before taking action.
  • Confirm recipients before sending sensitive information.
  • Use approved secure methods when transmitting sensitive information.
  • Report suspicious messages according to company procedures.

Employees must not:

  • Use personal email to conduct company business.
  • Forward company information to personal email accounts for convenience.
  • Use personal messaging applications to conduct company business when an approved company communication method is available.
  • Send confidential or sensitive information through unauthorized communication channels.
  • Open suspicious attachments or links when there is reason to believe they may be malicious.
  • Forward phishing messages or suspicious attachments to other employees except through an approved reporting process.

Employees should exercise particular caution with messages involving payments, invoices, passwords, account changes, sensitive information, or requests for urgent action.


7. Personal Email and Personal Accounts

Personal email accounts and personal online accounts must not be used to bypass company security controls.

Employees must not:

  • Send company documents to personal email accounts.
  • Store company information in personal cloud-storage accounts.
  • Use personal accounts to conduct company business without authorization.
  • Use personal accounts as an alternative when a company system is inconvenient or temporarily unavailable.
  • Forward company email to personal email accounts without authorization.

If an employee needs access to a business application or storage service that is not currently available, the employee should contact the Falcon IT Services Help Desk for assistance.


8. Data Protection and Confidential Information

Employees are responsible for protecting information according to its sensitivity.

Company information may include:

  • Customer information
  • Employee information
  • Personally identifiable information (PII)
  • Protected health information (PHI), where applicable
  • Financial information
  • Payment information
  • Passwords and credentials
  • Confidential business information
  • Trade secrets
  • Intellectual property
  • Contracts
  • Business plans
  • Internal communications
  • Proprietary documents
  • Information received from customers, vendors, or business partners

Employees must:

  • Access sensitive information only when authorized and required for their job duties.
  • Share sensitive information only with authorized recipients.
  • Use approved storage locations.
  • Use approved methods for transferring sensitive information.
  • Verify recipients before sending sensitive information.
  • Protect sensitive information from unauthorized viewing.
  • Follow company data-classification requirements when provided.
  • Never transmit sensitive information using Scan-to-mail functions found in MFCs.

Employees must not copy, download, transfer, disclose, or store sensitive information merely for convenience.

The fact that an employee can technically access information does not necessarily mean that the employee is authorized to use or disclose it.

If the employee is unsure about what systems or processes are authorized to store and transmit sensitive data, they must contact the Falcon IT Services Help Desk for assistance.

Employees must report data privacy violations from vendors, co-workers or other entities to security@falconitservices.com.


9. File Storage and Sharing

Company files must be stored in company-approved locations.

Employees must not:

  • Store company files in personal cloud-storage accounts.
  • Use unauthorized file-sharing services for company information.
  • Upload company information to unauthorized websites or applications.
  • Transfer sensitive information using unapproved methods.
  • Create unauthorized shared repositories for company information.

Employees should contact the Falcon IT Services Help Desk when they need a new secure shared folder, file repository, collaboration space, or other storage location.

Sensitive information should be shared only with people who have a legitimate business need to receive it.

Employees must report data privacy violations from vendors, co-workers or other entities to security@falconitservices.com


10. Secure Communications

Sensitive information must be transmitted only through company-approved and appropriately secured communication methods.

Employees must not send sensitive information through:

  • Personal email
  • Unapproved messaging applications
  • Unapproved file-transfer services
  • Personal cloud-storage accounts
  • Public file-sharing services
  • Other unauthorized channels

Sensitive information includes, but is not limited to:

  • Passwords
  • MFA codes
  • PII
  • PHI
  • Payment-card information
  • Financial information
  • Confidential business information
  • Trade secrets
  • Intellectual property

When an employee is unsure whether a communication method is appropriate, the employee must contact the Falcon IT Services Help Desk before transmitting the information.

Employees must report data privacy violations from vendors, co-workers or other entities to security@falconitservices.com


11. Software and Applications

Employees may use only software and applications approved by the company.

Employees must not independently install:

  • Unauthorized software
  • Pirated or cracked software
  • Software obtained from untrusted sources
  • Key generators or software cracks
  • Unauthorized patches
  • Unapproved remote-access applications
  • Unauthorized utilities or security tools
  • Applications that have not been approved for company use

If an employee needs an application that is not currently installed or approved, the employee must submit a request by e-mailing helpdesk@falconitservices.com.

Employees must not virtualize their OS environment, boot from USB sticks, uninstall, disable, modify, or interfere with security software, endpoint protection, monitoring tools, or other security controls installed on company-managed devices.


12. Browser Extensions and Add-ons

Browser extensions, plug-ins, add-ons, and similar browser-based applications can access websites, files, browsing activity, credentials, and other information. Browser extensions are an increasingly important source of data-loss risk for organizations. Because extensions can be granted broad access to websites and browser activity, a malicious or compromised extension can potentially collect and exfiltrate sensitive company information without the employee realizing it.

Employees must not install browser extensions or add-ons on company-managed devices unless they are approved by the company.

Employees should contact the Falcon IT Services Help Desk if a browser extension or plug-in is needed for legitimate business purposes.


13. Shadow IT and Unauthorized Services

Employees must not independently acquire or use technology services for company business without authorization.

This includes:

  • Cloud-storage services
  • File-sharing services
  • Project-management applications
  • CRM systems
  • AI services
  • Accounting applications
  • Communication platforms
  • Remote-access services
  • Online databases
  • Browser-based applications
  • Personal cloud accounts
  • Other SaaS services

Employees must not create accounts with third-party services using company information or company credentials unless the service has been approved.

If an employee needs a new technology service, application, or online tool for business purposes, the employee must request approval by emailing security@falconitservices.com.

All requests will be evaluated for security, potential risks, financial viability, and business necessity. Approval will be determined through a quorum meeting between the organization’s designated stakeholders and the Falcon IT Services security team.

Employees must not use an unapproved service while an approval request is pending.


14. Connecting Third-Party Applications to Company Accounts

Employees must be careful when applications or websites ask for access to company accounts.

Employees must not connect a company email account, cloud account, files, contacts, calendar, or other organizational resources to an application unless the application has been approved.

This includes requests to:

  • “Sign in with” a company account.
  • Grant an application access to email.
  • Grant access to company files.
  • Grant access to contacts or calendars.
  • Authorize an application through OAuth.
  • Provide an API key.
  • Connect a third-party service to a company account.

Employees should contact the Falcon IT Services Help Desk when unsure whether an application may be connected to a company account.


15. Artificial Intelligence (AI) Tools

Employees may use artificial intelligence tools only in accordance with company policy and using company-approved services.

Employees must not enter confidential, proprietary, sensitive, personal, protected health, financial, payment-card, credential, or other restricted information into an AI service unless the company has specifically approved that use.

Employees must not upload company documents to an AI service simply because the service can analyze them.

Employees must not connect an AI service to company email, files, cloud services, applications, or other organizational resources without authorization.

AI-generated content must be reviewed by an appropriate employee before it is:

  • Sent to a customer or business partner.
  • Published externally.
  • Used in an important business decision.
  • Used in a legal, financial, technical, or other high-impact context.
  • Represented as factual or authoritative information.

Employees should remember that AI-generated information may be inaccurate, incomplete, misleading, or inappropriate.


16. Remote Access

Employees must use only company-approved methods to remotely access company systems.

Employees must not install or use unauthorized remote-access software.

Employees must not allow another person to remotely control a company computer unless the activity is authorized.

Employees should use company-approved remote-access solutions and authentication methods when working outside the office.

Employees should contact the Falcon IT Services Help Desk if they need assistance establishing or maintaining authorized remote access.


17. Wi-Fi and Internet Connections

Employees should use trusted networks when accessing company resources.

When working remotely:

  • Use a trusted home network when available.
  • Keep home Wi-Fi protected with a strong password.
  • Avoid public Wi-Fi networks such as hotels and coffee shops, especially abroad.
  • Use the company’s approved secure remote-access method when required.
  • Use ONLY your personal home WiFi or a company-approved cellular hotspot when connecting to company resources remotely.

Employees should not connect company-managed devices to unknown or suspicious networks when a safer connection is available.


18. Mobile Devices

Employees who use smartphones, tablets, or other mobile devices for company business must protect those devices appropriately.

Mobile devices used to access company resources must:

  • Use a screen lock.
  • Use supported operating-system versions.
  • Receive security updates.
  • Use encryption where supported and required.
  • Be protected against unauthorized access.

Employees must not jailbreak or root devices used to conduct company business or access company systems.

Employees should not allow family members, friends, or other unauthorized people to use a device that provides access to company information.


19. Lost or Stolen Devices

Employees must immediately notify the Falcon IT Services Help Desk and the designated company contact if a company device or a device used to access company information is:

  • Lost
  • Stolen
  • Missing
  • Left in an unauthorized location
  • Suspected of being accessed by an unauthorized person

This includes laptops, smartphones, tablets, USB drives, authentication devices, and other equipment that may contain or provide access to company information.

Employees should not delay reporting a lost device because they believe they may recover it later.


20. Portable and Removable Media

USB drives, external hard drives, memory cards, and other removable media can introduce malware and create a risk of data loss.

Employees may use removable media only for legitimate business purposes, when approved by an organization manager, and temporarily unlocked by the Falcon IT Services Help Desk.

Employees must not:

  • Use unknown USB drives.
  • Connect found USB devices to company computers.
  • Copy sensitive information to unauthorized removable media.
  • Use personal removable media to transfer company information unless specifically authorized.
  • Use removable media to bypass company file-sharing or security controls.

Employees should contact the Falcon IT Services Help Desk when they need to transfer files using removable media.


21. Physical Security

Employees are responsible for protecting company equipment and information from unauthorized physical access.

Employees must:

  • Lock computers when leaving them unattended.
  • Keep company laptops and mobile devices under their control.
  • Protect sensitive documents from unauthorized viewing.
  • Keep confidential documents off desks and other exposed areas when not in use.
  • Prevent unauthorized people from using company equipment.
  • Challenge or report suspicious activity when appropriate and safe to do so.
  • Keep access cards, keys, and other physical credentials secure.

Employees must not allow unauthorized individuals to access restricted areas, company equipment, or sensitive information.


22. Clean Desk and Clear Screen Practices

Employees should minimize the exposure of sensitive information when working in offices, shared spaces, conference rooms, public locations, or remote environments.

Employees should:

  • Lock their screen whenever leaving their computer.
  • Secure sensitive paper documents when not in use.
  • Avoid leaving confidential information visible to visitors or unauthorized employees.
  • Remove sensitive documents from printers and scanners promptly.
  • Dispose of sensitive paper documents using approved disposal methods.

Employees should be aware of people who may be able to see their screen when working in public areas.


23. Printers, Scanners, and Physical Documents

Employees must use company-approved printers, scanners, and document-storage locations when handling sensitive information.

Employees must:

  • Retrieve sensitive documents from printers promptly.
  • Verify the destination before scanning or printing.
  • Store scanned documents in approved locations.
  • Protect paper copies containing sensitive information.
  • Dispose of sensitive documents through approved methods.
  • Never use scan-to-email to transmit private or protected information.

Employees must not scan sensitive documents directly to personal email accounts or unauthorized external destinations.


24. Company Equipment

Company equipment is provided for business purposes and must be treated as company property.

Employees must:

  • Protect equipment from theft and damage.
  • Use equipment only as authorized.
  • Follow IT instructions concerning maintenance, updates, and security.
  • Return equipment when requested.
  • Notify the appropriate company contact if equipment is damaged, lost, or stolen.

Employees must not make unauthorized hardware or configuration changes to company-managed devices.


25. Security Updates and Patches

Employees must allow company-managed devices to receive required security updates.

Employees must not:

  • Disable automatic updates.
  • Delay required updates without authorization.
  • Circumvent device-management controls.
  • Disable security software to make an application work.
  • Prevent Falcon IT Services tools from operating.
  • Prevent Falcon IT Services staff from updating or servicing devices when requested.

If an update causes a problem with a business application, employees should contact the Falcon IT Services Help Desk rather than attempting to disable the security control themselves.


26. Use of Company Technology

Company technology must be used responsibly and primarily for legitimate business purposes.

Employees must not deliberately waste or excessively consume company resources.

Examples include:

  • Excessive personal Internet use.
  • Unauthorized streaming or downloading.
  • Unauthorized games.
  • Excessive printing.
  • Mass mailings unrelated to legitimate business.
  • Chain letters.
  • Unauthorized file sharing.
  • Activities that unnecessarily consume network, storage, computing, or printing resources.
  • Contact the Falcon IT Services Help Desk for non-productivity related requests.

Limited personal use may be permitted if consistent with company policy, does not interfere with work, does not create a security risk, and does not violate applicable law or company policy.


27. Prohibited Use

Employees must not use company systems or resources to:

  • Commit fraud or other unlawful activity.
  • Attempt to gain unauthorized access to systems or accounts.
  • Access another person’s account without authorization.
  • Steal, obtain, or disclose another person’s credentials.
  • Introduce malware or other malicious software.
  • Circumvent security controls.
  • Harass, threaten, or abuse others.
  • Send discriminatory or unlawful material.
  • Distribute unauthorized copyrighted material.
  • Install pirated or cracked software.
  • Conduct unauthorized commercial activity.
  • Disclose confidential company information without authorization.
  • Misrepresent personal opinions as official company statements.
  • Conduct activities that violate company policy or applicable law.

28. Financial and Payment Requests

Employees involved in financial transactions, invoices, purchasing, payments, or vendor communications must be especially cautious about requests involving money or changes to payment information.

Employees must independently verify requests involving:

  • Wire transfers
  • Bank-account changes
  • Vendor payment changes
  • Payment instructions
  • Invoice changes
  • Refunds
  • Gift cards
  • Unusual purchases
  • Urgent financial requests

An email, text message, voicemail, chat, or video call is not sufficient by itself to establish that a financial request is legitimate.

Employees must use a known and trusted contact method to independently verify unusual financial requests before acting.

Employees must follow all additional company approval requirements for financial transactions.


29. Voice Mail and Telephone Security

Employees must protect voicemail accounts and telephone systems used for company business.

Employees must:

  • Use a voicemail PIN that is not easily guessed.
  • Keep voicemail credentials confidential.
  • Avoid leaving sensitive information in voicemail messages.
  • Verify unusual requests received by telephone before acting on them.

Employees should not leave passwords, payment information, sensitive personal information, or confidential business information in voicemail messages.

Caller ID or voice recognition alone should not be considered proof of a caller’s identity.


30. Working in Public Locations

Employees working outside company facilities must take reasonable steps to prevent unauthorized access to company information.

Employees should:

  • Position screens so they cannot easily be viewed by others.
  • Use privacy screens where appropriate.
  • Avoid discussing confidential information where unauthorized people may overhear.
  • Keep laptops and mobile devices under their control.
  • Avoid using unknown or unsecured networks when handling sensitive information.
  • Lock devices whenever they are unattended.

Employees should take particular care in airports, hotels, coffee shops, restaurants, conference centers, public transportation, and other shared environments.


31. Visitors and Other Individuals

Employees must not provide unauthorized individuals with access to company systems, devices, accounts, files, or confidential information.

Employees must not:

  • Allow visitors to use their company computer.
  • Give another person their password.
  • Allow unauthorized people to enter restricted areas.
  • Leave sensitive documents where visitors can see them.
  • Allow unauthorized individuals to connect devices to company equipment or networks.

Employees should contact the appropriate company personnel if a visitor requires access to company technology or information.


32. Use of Personal Devices

If the company approves an employee to use a personally owned device for business purposes, the device must meet the company’s applicable security requirements.

Employees must not use personal devices to access company systems unless such use is explicitly authorized.

Employees using an authorized personal device for company business must follow applicable requirements for:

  • Screen locking
  • Operating-system updates
  • Malware protection
  • Encryption
  • Approved applications
  • Data storage
  • Authentication
  • Loss or theft reporting

Employees must not use personal devices as a way to bypass company security requirements.


33. AI-Enabled Devices and Wearables

Employees must follow company rules concerning smart watches, smart glasses, AI-enabled devices, voice assistants, cameras, recording devices, and other technology capable of recording or transmitting information.

Employees must not use such devices to record, photograph, transmit, or disclose confidential company information without authorization.

Employees must respect company rules concerning workplace privacy, recording, and confidential conversations.


34. Company Information on Personal or External Services

Company information must remain within approved company systems and services unless an authorized business process specifically permits otherwise.

Employees must not:

  • Upload company files to personal cloud storage.
  • Store company documents in personal note-taking applications.
  • Copy company information to personal USB drives.
  • Send company information to personal email.
  • Upload company information to unauthorized AI services.
  • Enter company credentials into unauthorized applications.
  • Use unauthorized online services to process company information.

When an employee needs a service that is not currently approved, the employee should request it through the company’s IT process.


35. Need-to-Know and Least-Privilege Access

Employees must use company information only when it is necessary for their assigned job responsibilities.

Employees must not:

  • Browse files merely because they are accessible.
  • Access customer or employee information without a legitimate business purpose.
  • Search for information about coworkers, customers, or other individuals out of curiosity.
  • Attempt to obtain access to systems or information beyond their authorized responsibilities.
  • Use another employee’s account to obtain information.

Access to information is based on job responsibilities and business need.


36. Monitoring and Company Systems

Employees should understand that company-owned systems and resources may be monitored, logged, audited, retained, or reviewed as permitted by applicable law and company policy.

This may include activity involving:

  • Company computers
  • Company accounts
  • Email
  • Internet access
  • File access
  • Cloud applications
  • Security systems
  • Company networks
  • Company-owned mobile devices

Employees must not attempt to disable or circumvent authorized monitoring or security controls.

Any employee privacy rights protected by applicable law remain unaffected by these requirements.


37. Security Awareness Training

All employees must complete required cybersecurity awareness training as directed by the company.

Training may cover:

  • Phishing
  • Social engineering
  • Malware
  • Password security
  • MFA
  • Data protection
  • Safe Internet use
  • Acceptable use
  • Secure remote work
  • AI security
  • Physical security
  • Financial fraud
  • Reporting suspicious activity

Employees are expected to apply the practices taught in security awareness training to their day-to-day work.


38. Reporting Security Concerns

Employees are not expected to investigate or resolve suspected cybersecurity problems themselves.

Employees should promptly contact the Falcon IT Services Help Desk or designated company security contact if they believe:

  • Their password may have been disclosed.
  • Their account may have been compromised.
  • They approved an unexpected MFA request.
  • They clicked a suspicious link.
  • They opened a suspicious attachment.
  • A device may contain malware.
  • A company device has been lost or stolen.
  • Sensitive information was sent to the wrong person.
  • Confidential information may have been disclosed.
  • Someone may have gained unauthorized access to company systems.
  • They received a suspicious request for credentials, payment, or sensitive information.
  • They observe other unusual or suspicious technology activity.

Employees should provide the relevant information they have and follow instructions from the Falcon IT Services Help Desk or designated security contact.

Employees must not attempt to conceal a mistake or suspected security problem.

The purpose of reporting is to allow the appropriate personnel to evaluate the situation and take whatever action is appropriate. Employees are not responsible for independently determining whether an event constitutes a security incident.


39. When in Doubt, Stop and Verify

Employees should not feel pressured to act immediately when a request involves security, money, credentials, sensitive information, or unusual access.

When in doubt:

  1. Stop before taking the requested action.
  2. Do not click additional links or open unexpected attachments.
  3. Do not provide passwords, MFA codes, or other credentials.
  4. Do not transfer sensitive information.
  5. Independently verify the request using a trusted contact method.
  6. Contact the Falcon IT Services Help Desk if the request remains uncertain.

Security is more important than speed when a request appears unusual.


40. Employee Acknowledgment

By using company systems and technology, employees acknowledge that they are expected to:

  • Protect company information and technology.
  • Keep credentials confidential.
  • Use MFA appropriately.
  • Follow company-approved software and technology requirements.
  • Protect company devices.
  • Use approved methods to store and transmit company information.
  • Follow acceptable-use requirements.
  • Complete required cybersecurity training.
  • Verify unusual requests.
  • Promptly report suspected security concerns.
  • Ask for assistance when they are uncertain about a cybersecurity requirement and subsequently follow instructions from Falcon IT Services.

Failure to follow these requirements may result in corrective or disciplinary action consistent with company policy and applicable law.

These requirements may be updated as technology, threats, business operations, or applicable legal and regulatory requirements change.

error: Sorry, copy/paste is disabled