Record Identify Notify the details the source affected parties Notify Prevent Recover your IT Team the spread the files Staff Training and Awareness NHRIs should provide step-by-step guides to their staff who handle personal information. Use a riskbased approach to deciding who should get the awareness materials and activities. There are some essential topic areas that can be covered in a take-home guide for staff or can be the focus of activities that can include formal training sessions or reminders and simulation games and exercises. Password Protection: Emphasise the importance of using strong, unique passwords for all devices, including computers, tablets, and mobile phones. Passwords should be a mix of letters, numbers, and symbols, and avoid easily guessable information. Password managers should be used as an easy option to achieve more secure practices without staff having to remember or write down multiple complex passwords. NHRIs can recommend one or more of the specific password managers in the market to their staff. Two-Factor Authentication (2FA): Encourage staff to enable two-factor authentication wherever possible. Automatic Screen Lock: Encourage staff to set devices to automatically lock after a short period of inactivity to prevent unauthorised access if the device is left unattended. Secure Home Wi-Fi: Staff working from home should secure their Wi-Fi networks with strong, unique passwords and ensure that encryption (WPA2 or WPA3) is enabled on the router (modem). NHRIs can provide tips on how to implement a strong password on home routers. Use of Public Wi-Fi: Public Wi-Fi networks are insecure, making devices vulnerable to interception. Staff should avoid accessing sensitive information when connected to public Wi-Fi unless they use a Virtual Private Network (VPN). Secure Mobile Communication: Staff using mobile phones should use encrypted messaging apps (e.g., Signal or WhatsApp) for sensitive communications. Regular SMS texts and unencrypted emails should be avoided for sharing confidential information. Run the latest updates: Advise staff to keep their operating systems, software, and apps updated to the latest versions to protect against vulnerabilities and security threats. Remote Wipe: Enable remote wipe functionality on mobile devices, so if a device is lost or stolen, all data can be securely erased. Data Protection Guidelines for NHRIs Toolkit 21

Select target paragraph3