Skip to main content
All resources
Framework
5 min readUpdated 18 April 2026

Security Onboarding Checklist for New Staff

Everything to provision, restrict and teach in a new starter's first week — plus the offboarding mirror that stops orphaned access.

Access debt compounds

Most organisations we assess have more active accounts than employees. Every unclosed account is a credential waiting to be phished or brute-forced, and it will not show up in a payroll reconciliation.

The fix is procedural: onboarding and offboarding are mirror images, and both are checklists with named owners and evidence.

Teach three things well

Skip the annual hour-long module. New starters need to reliably do three things: verify payment and banking changes by phone, report a suspicious message in one click, and never reuse a work password.

The checklist

Day 1 provisioning

  • Account created from a role template, not by copying an existing user
  • MFA registered in person or via verified enrolment
  • Device enrolled in management with disk encryption confirmed
  • Password manager provisioned and demonstrated

Week 1 education

  • Payment and banking change verification procedure walked through
  • One-click phishing report button demonstrated
  • Acceptable use and data handling policy acknowledged
  • Incident reporting contact saved to phone

Ongoing

  • Access reviewed at 90 days and on every role change
  • Simulated phishing included from month 2
  • Privileged access requested separately and time-bound

Offboarding mirror

  • All sessions and tokens revoked, not just password reset
  • MFA methods removed and device wiped or returned
  • Mailbox delegated or converted to shared per retention policy
  • SaaS applications outside SSO manually deprovisioned

Need this done, not just documented?

Fast Emu delivers the controls in this checklist as a managed service, monitored 24/7 from Australia.