Full Report
Teach employees not to leave computers unlocked with this tool by Huntress, the fun cyber security awareness training provider.
Analysis Summary
# Best Practices: Securing Unattended Workstations
## Overview
These practices address the physical security risk of "unlocked computers." When a workstation is left unattended and authenticated, it bypasses all perimeter and login-based security controls, allowing unauthorized individuals to access sensitive data, send fraudulent emails, or install malicious software.
## Key Recommendations
### Immediate Actions
1. **Adopt "Hot Corners":** Configure operating system shortcuts (like Mac/Windows "Hot Corners") to allow employees to lock screens instantly with a single mouse movement.
2. **Promote the "Win + L" (Windows) or "Control + Command + Q" (Mac) Habit:** Encourage employees to use keyboard shortcuts as a muscle-memory reflex whenever they stand up.
3. **Use UnlockedComputer.com:** Utilize the Huntress free tool to provide a humorous, non-punitive "gotcha" moment that redirects employees to a quick educational landing page rather than shaming them.
### Short-term Improvements (1-3 months)
1. **Deploy Technical Guardrails:** Implement automated screen lock timeouts via Group Policy (GPO) or Mobile Device Management (MDM).
2. **Shift Awareness Culture:** Move away from "Death by PowerPoint" and annual training sessions. Implement short, story-based, or gamified training modules that occur more frequently.
3. **Establish a Positive Reinforcement Loop:** Instead of "slamming policies" in faces, reward departments that maintain a 100% locked-desk record during random walkthroughs.
### Long-term Strategy (3+ months)
1. **Build a Security-First Culture:** Integrate security awareness into the daily workflow so that locking a computer becomes as instinctual as locking a front door.
2. **Continuous Simulation:** Beyond phishing, simulate physical security lapses and provide immediate, just-in-time training to those who fail.
3. **Physical-Digital Integration:** Ensure clean-desk policies are enforceable and supported by the physical office layout (e.g., privacy screens, secure docking stations).
## Implementation Guidance
### For Small Organizations
- Focus on peer-to-peer accountability and cultural habits.
- Manually configure screen timeout settings (recommended: 2-5 minutes of inactivity).
### For Medium Organizations
- Centralize management using MDM or Active Directory to enforce lock screen policies across all remote and on-premise devices.
- Use the "UnlockedComputer.com" tool as a lighthearted way to reinforce policy without HR friction.
### For Large Enterprises
- Automate compliance reporting to see which departments frequently leave devices unlocked.
- Integrate workstation locking into a comprehensive Security Awareness Training (SAT) platform (e.g., Huntress/Curricula).
## Configuration Examples
* **Windows (via GPO):** `Computer Configuration` > `Windows Settings` > `Security Settings` > `Local Policies` > `Security Options` > `Interactive logon: Machine inactivity limit` (Set to 300 seconds or less).
* **macOS (via MDM):** Set `MaxInactivityTimeoutInMinutes` to `5` and ensure "Require password immediately after sleep or screen saver begins" is enabled.
## Compliance Alignment
- **NIST SP 800-53:** AC-11 (Device Lock)
- **ISO/IEC 27001:** Control A.7.7 (Clear desk and clear screen policy)
- **CIS Controls:** Control 4 (Secure Configuration of Enterprise Assets and Software)
## Common Pitfalls to Avoid
- **Hostile Training:** Sending "fake" emails from an employee's account or public shaming creates resentment and lowers morale.
- **Over-Reliance on Tech:** Automated timers are a backup; if a timer is set to 10 minutes, an attacker has a 10-minute window. Behavioral change is the primary defense.
- **Inconsistent Policies:** Allowing executives or certain departments to bypass auto-lock settings creates security gaps and cultural double standards.
## Resources
- **Unlocked Computer Training Tool:** hxxps[://]www[.]unlockedcomputer[.]com/
- **Huntress Security Awareness Training:** hxxps[://]www[.]huntress[.]com/platform/security-awareness-training
- **NIST Physical Security Guidelines:** hxxps[://]csrc[.]nist[.]gov/