Skip to main content

5 Things You Should Never Do on a Work Computer in 2026

Media 5 Things You Should Never Do on a Work Computer

 

Your work laptop may sit on your desk all day. You might take it home, use it on the sofa, travel with it and spend more time using it than your own computer.

That familiarity can make it very easy to forget one important fact:

It isn't your personal computer.

A business device may contain customer information, Microsoft 365 credentials, company files, access to cloud applications and security tools that protect the wider organisation. Something that seems harmless on a home computer can therefore create a much bigger problem when performed on a company-managed device.

The original advice around separating work and personal activity is still valid, but workplace security has changed considerably. Businesses now commonly use endpoint management, EDR, Conditional Access, application control and cloud-based security policies to manage company devices. Microsoft Intune, for example, can control devices and applications, deploy security configuration and influence whether a device can access organisational resources.

Here are five things employees should avoid doing on a work computer in 2026.

1. Don't Store Personal Passwords and Sensitive Personal Data on It

The old advice was simply:

“Don't save passwords in your browser.”

That's too simplistic in 2026.

Modern password managers — including properly secured browser-based ones — can actually improve security by helping users create unique passwords. The NCSC itself recommends password managers as a useful security tool.

The real problem is storing personal credentials inside a company-managed environment.

For example, avoid putting your:

Personal banking credentials.

Personal email passwords.

Private cloud-storage credentials.

Personal password vault.

Copies of passports or driving licences.

Personal photographs or tax records.

onto a business device unless there is a genuine business reason and company policy permits it.

Why?

Because you do not control the lifecycle of that computer.

It might need replacing.

IT may rebuild it.

It may be remotely managed.

It could be returned when you leave.

It could be investigated following a cyber incident.

Company backups or management processes may also capture information you never intended to become part of a corporate system.

The NCSC recommends organisations securely erase devices before they are reused or leave organisational control precisely because computers can retain work, personal and financial data.

What about employer monitoring?

Don't assume every employer is secretly reading everything you do.

UK employers that monitor workers still need to comply with data-protection law. ICO guidance says monitoring should be necessary, proportionate and transparent, and employees should generally be informed about it.

But the practical point remains:

A work device should not be treated as a private personal computer.

Keep sensitive personal information on systems you control.

2. Don't Install Unapproved Software, Browser Extensions or AI Tools

This is an increasingly important problem.

A user needs to convert a PDF.

They Google:

“Free PDF converter.”

Another employee wants an AI tool to summarise a customer document.

Someone else installs a browser extension promising to organise Gmail or automate LinkedIn.

Individually, these decisions may seem harmless.

Collectively, they create shadow IT.

The NCSC defines shadow IT as technology being used outside the organisation's normal approval and risk-management processes. It specifically includes employees putting organisational information into personal cloud services or unapproved AI tools.

The problem isn't that every unapproved application is malicious.

The problem is that IT may not know:

What data it accesses.

Where that data is stored.

Who owns the service.

Whether information is used to train AI models.

Whether the application is still receiving security updates.

What permissions a browser extension has.

Whether the software contains malware.

Whether the company can remove access when an employee leaves.

Microsoft now provides App Control for Business through Intune specifically to help organisations restrict which applications are allowed to run on managed Windows devices.

And Microsoft's Enterprise App Management capabilities can provide organisations with controlled deployment and updating of approved third-party applications rather than leaving employees to download whatever they find online.

The better approach

Need a new application?

Ask IT.

Need an AI tool?

Check whether the business has approved one.

Need a browser extension?

Have it reviewed.

A five-minute question can prevent a considerably larger security problem later.

3. Never Disable Security Tools, Updates or Management Software

This one remains absolutely relevant.

You're trying to finish something.

A security application appears to be slowing the computer down.

Windows wants to restart.

Your VPN is irritating you.

EDR blocks an application you want.

A backup or synchronisation process is consuming resources.

It can be tempting to think:

“I'll just turn this off for ten minutes.”

Don't.

Company security software is usually there because it provides one part of a much larger protection strategy.

That could include:

Endpoint Detection and Response.

Microsoft Defender.

Disk encryption.

DNS or web filtering.

Device management.

Application control.

Patch management.

Backup or synchronisation.

The NCSC's July 2026 guidance for small organisations says keeping devices, applications and software up to date is one of the most important ways to protect them from malware and ransomware.

Modern endpoint management also means security configuration may be linked directly to access.

A company can use device-management and identity information to determine whether a computer is sufficiently compliant to access corporate resources. Microsoft Intune feeds device and application posture into Microsoft Entra Conditional Access for exactly this type of decision.

So if something is interfering with your work, don't bypass it.

Contact IT and explain the problem.

There may be a legitimate fault or performance issue that needs fixing.

Don't ignore updates either

Restarting your laptop at an inconvenient moment can be frustrating.

An unpatched security vulnerability can be considerably more frustrating.

Keep the device updated and allow company patch-management policies to do their job.

4. Never Let Friends or Family Use Your Work Computer

You're working from home.

Your child's laptop battery dies.

Your partner needs to print something.

A friend asks to quickly use the browser.

It's only going to take five minutes.

Still no.

A work computer may already have authenticated access to:

Email.

Microsoft Teams.

SharePoint.

OneDrive.

Customer databases.

Accounting systems.

VPNs.

Password managers.

Internal applications.

Someone else using the computer could accidentally access information they were never authorised to see.

They might also:

Open malicious links.

Install software.

Change browser settings.

Connect unknown USB devices.

Delete company information.

Expose confidential data.

The NCSC recommends organisations use device-management controls and clearly define how work information may be accessed, particularly where personal or shared devices are involved. Its BYOD guidance says organisations need explicit policies defining employee and organisational responsibilities rather than allowing unmanaged access to develop informally.

Lock the screen when you walk away

This applies in the office as well.

Leaving a logged-in workstation unattended can allow somebody else to access the same applications and information you can.

Use:

Windows + L

when stepping away from a Windows computer.

It's one of the easiest security habits you can develop.

5. Never Move Company Data Into Personal Email, Cloud Storage or Random USB Drives

This is perhaps the most important addition to the old article.

Suppose you're working from home and need a document later.

You email it to your personal Gmail account.

Or upload it to your personal Dropbox.

Or copy it onto a USB stick.

Problem solved?

You've actually created another problem.

The organisation may no longer know:

Where that data exists.

Who has access.

Whether it is encrypted.

How long it will remain there.

Whether it is backed up.

Whether it can be deleted.

Whether it has been shared onwards.

This is exactly the type of behaviour the NCSC identifies as shadow IT. Personal cloud storage containing company information may sit completely outside the organisation's security and risk-management controls.

USB devices create similar issues.

The NCSC warns that removable media can introduce malware and create data-loss risks, particularly because portable storage may not be encrypted or protected by device authentication.

Instead, use the company's approved systems.

That might mean:

SharePoint.

OneDrive.

Teams.

A managed file server.

Approved cloud storage.

A company VPN.

Secure document-sharing systems.

If those systems aren't giving you what you need, speak to IT rather than inventing your own workaround.

What About Personal Email, Shopping or Online Banking?

This is where the old article was a little too black and white.

Checking the news on your work computer isn't automatically a cyber incident.

Neither is ordering something online during your lunch break.

Whether limited personal use is allowed depends on your employer's acceptable-use policy.

The safer principle is:

Don't use a work computer for personal activity that creates unnecessary security, privacy or compliance risk.

That means being particularly cautious about:

Personal banking.

Downloading personal software.

Pirated media.

Unknown streaming sites.

Cryptocurrency tools.

Unapproved browser extensions.

Personal cloud services.

Sensitive personal documents.

Anything you would be uncomfortable explaining to IT during a security investigation probably belongs on your own device.

Work Computers Are Increasingly Managed Devices

The biggest difference in 2026 is that a company laptop may be much more tightly integrated into the organisation's security architecture than older PCs were.

A properly managed device can potentially have:

Security baselines.

EDR.

Disk encryption.

Application controls.

Patch policies.

Device compliance.

Conditional Access.

Remote management.

Remote wipe.

Cloud application policies.

Microsoft Intune is specifically designed to enrol, configure, secure and update organisational devices while controlling access to corporate resources.

That isn't about making employees' lives difficult.

It is about protecting the company information the device can reach.

Personal Devices Need Rules Too

The reverse situation also matters.

If employees use their personal computers for work, the business still needs a strategy.

The NCSC's BYOD guidance recommends organisations understand the risks first, define policies and determine what technical controls are required.

In some environments that might involve:

Device enrolment.

Mobile Device Management.

Mobile Application Management.

Conditional Access.

Restricting what data BYOD users can access.

Keeping organisational data within managed applications.

Microsoft Intune's application-protection policies, for example, can apply rules controlling how corporate information is accessed and moved within managed applications.

BYOD can work.

Unmanaged BYOD without a policy is the problem.

What Employees Should Do Instead

The safest approach is surprisingly simple.

Treat the work computer as a business asset.

Use approved applications.

Store company information in approved locations.

Keep personal information elsewhere.

Allow security updates to install.

Do not disable protection.

Do not share the device.

And if something strange happens, tell IT.

Especially if you've:

Clicked a phishing link.

Entered credentials somewhere suspicious.

Approved an unexpected MFA request.

Installed something you now regret.

Copied confidential data somewhere unintended.

The NCSC recommends organisations make phishing reporting easy and have a process for dealing with reported incidents.

Hiding a mistake generally gives an attacker more time.

Reporting it gives IT a chance to contain it.

Secure Business Devices With Hamilton Group

Hamilton Group can help businesses properly manage and secure the computers employees rely on every day.

That includes managed IT support, endpoint management, Microsoft Intune, Microsoft 365, Microsoft Entra ID, Conditional Access, EDR, patch management, DNS and web filtering, device security, vulnerability management and cyber-security awareness training.

We can also help organisations establish sensible BYOD and acceptable-use policies, control applications and keep business information inside approved systems rather than allowing shadow IT to develop.

And when an employee does have a problem — or thinks they may have clicked or installed something they shouldn't — our aim is to make first contact on IT support requests within 15 minutes.

Call Hamilton Group on 0330 043 0069 or visit hgmssp.com to speak with one of our IT and cyber-security experts.