Skip to main content

Should You Track Your Employees’ Internet Usage?

Media IT strategy meeting

The internet is essential to the way most businesses operate.

Employees use it to communicate with customers, access cloud applications, research information, share documents and complete everyday tasks. However, unrestricted internet access can also introduce cybersecurity, productivity and compliance risks.

This may leave business owners wondering whether they should monitor what employees do online.

Tracking internet usage can help protect your organisation, but it must be approached carefully. Excessive monitoring may damage trust, invade employees’ privacy and potentially breach data protection or employment laws.

For most businesses, the objective should not be to watch every click an employee makes. It should be to protect company systems, identify genuine risks and make sure business technology is being used appropriately.

What Does Employee Internet Monitoring Mean?

Employee internet monitoring can take several different forms.

A business may record or review:

* Websites visited on company devices
* Attempts to access blocked websites
* Internet bandwidth usage
* Downloads and uploaded files
* Use of cloud storage services
* Access to social media
* Email activity
* Security warnings
* Attempts to visit malicious websites
* Connections made from company devices
* Internet activity outside normal working hours

The level of detail available will depend on the systems being used.

Firewalls, web-filtering platforms, endpoint security tools and Microsoft 365 services may all collect information about how business systems are accessed.

Some monitoring is primarily designed to protect the organisation from cyber threats. Other tools are intended to assess employee productivity or investigate potential misconduct.

It is important to understand the difference.

Is It Legal to Monitor Employees’ Internet Usage?

UK employers can monitor employees’ internet usage, but they must be able to justify the monitoring and carry it out fairly.

The monitoring of email or internet use may involve processing employees’ personal data. This means employers must consider their obligations under UK data protection law.

Government guidance states that employers must make staff aware that they are being monitored and explain why. The Information Commissioner’s Office also advises that monitoring must have a lawful basis and should be necessary and proportionate.

Employers should normally tell employees:

* What information is being collected
* Why monitoring is taking place
* How the information will be used
* Who can access the records
* How long the information will be retained
* What behaviour is permitted
* What may happen if policies are breached

This information can be included within an acceptable-use policy, staff handbook and employee privacy notice.

Covert monitoring should only be considered in very limited circumstances, such as a specific investigation into suspected criminal activity where informing the individual would make detection difficult. It should not be used as a routine management tool.

Because employment and data protection requirements can change, businesses should obtain appropriate legal or HR advice before introducing extensive monitoring.

Why Might a Business Track Internet Usage?

There are several legitimate reasons why a business may monitor internet activity.

Protecting the Business From Cyberattacks

One of the strongest reasons to monitor internet usage is cybersecurity.

Employees may accidentally visit a malicious website, click a phishing link or download an infected file.

Security monitoring can help identify:

* Malware downloads
* Phishing websites
* Suspicious browser activity
* Connections to known malicious services
* Unauthorised applications
* Attempts to bypass security controls
* Large or unusual data transfers

Modern security systems can often block these threats automatically before they cause damage.

This type of monitoring is usually focused on identifying dangerous activity rather than evaluating how hard an individual employee is working.

Preventing Data Loss

Employees regularly handle confidential business and customer information.

Internet monitoring may help detect when sensitive information is being uploaded to personal email accounts, unapproved cloud storage platforms or file-sharing websites.

This can help protect against both accidental and deliberate data loss.

For example, an employee may upload a confidential spreadsheet to a personal file-sharing service because it appears convenient. They may not intend to cause harm, but the business could lose control over where that information is stored and who can access it.

Monitoring can alert the business to this activity and allow suitable action to be taken.

Reducing Access to Inappropriate Content

Businesses may choose to block websites containing illegal, harmful or inappropriate material.

This can help protect employees and reduce the risk of company systems being used in ways that could damage the organisation’s reputation.

Web filtering may also be used to restrict categories such as:

* Gambling websites
* Adult content
* Illegal downloads
* Known malicious websites
* Cryptocurrency mining websites
* Anonymous proxy services
* Unapproved file-sharing platforms

Blocking unsuitable website categories can often be more appropriate than allowing unrestricted access and reviewing individual browsing histories afterwards.

Managing Network Performance

Some websites and applications can consume large amounts of internet bandwidth.

Video streaming, large downloads, online gaming and personal cloud backups may affect internet performance for other employees.

Monitoring overall network usage can help identify whether particular applications or services are affecting business systems.

The business may then decide to block, restrict or prioritise certain types of traffic.

This does not always require identifying individual employees. In many cases, reviewing overall application or website-category usage may provide enough information.

Investigating a Specific Concern

There may be occasions when a business has a genuine reason to investigate an employee’s internet activity.

This could include suspected:

* Data theft
* Fraud
* Harassment
* Serious misuse of company systems
* Disclosure of confidential information
* Access to illegal content
* Breach of company policy

Any investigation should be proportionate, properly authorised and handled confidentially.

The business should also follow its disciplinary procedures and obtain HR or legal guidance where appropriate.

Can Internet Monitoring Improve Productivity?

Some employers introduce internet monitoring because they are concerned that employees are spending too much time on social media, shopping websites or other non-work activities.

Monitoring may help identify serious or repeated misuse, but it should not be treated as the only way to manage performance.

An employee visiting a non-work website does not automatically mean they are unproductive. They may be taking an agreed break, dealing with an urgent personal matter or using a website for a legitimate business reason.

Similarly, an employee who appears active online all day is not necessarily producing good work.

Performance should normally be managed through:

* Clear objectives
* Agreed responsibilities
* Regular meetings
* Measurable outcomes
* Appropriate supervision
* Support and training
* Fair performance procedures

Acas advises employers to trust employees to do their jobs and warns that excessive monitoring can damage trust, cause stress and reduce productivity. It recommends consulting employees and creating a clear monitoring policy.

Internet monitoring may provide useful supporting information, but it should not replace effective management.

What Are the Risks of Excessive Monitoring?

Monitoring every website visit, mouse movement or period of inactivity may appear to give managers greater control.

However, excessive monitoring can create new problems.

Damaging Employee Trust

Employees may feel that the business does not trust them.

This can affect morale, engagement and the relationship between managers and their teams.

Monitoring is more likely to be accepted when employees understand that it is being used to protect business systems rather than secretly evaluate every minute of their working day.

Collecting Personal Information

Internet records may reveal sensitive information about an employee.

For example, browsing activity could potentially indicate information about someone’s health, finances, beliefs or personal circumstances.

Even when an employee is using a company device, the business should avoid collecting more information than it genuinely needs.

The ICO recommends considering whether monitoring is necessary and proportionate, whether it could intrude into personal lives and whether a less intrusive alternative could achieve the same purpose.

Creating Additional Security Risks

Monitoring systems can collect large volumes of sensitive information.

If browsing histories, screenshots or detailed activity reports are not properly secured, they could become valuable targets for attackers.

Access should be restricted to authorised individuals, and information should be deleted when it is no longer required. The ICO advises that monitoring data should only be available to those who need it and must be protected against loss, damage or theft.

Misinterpreting the Information

Internet activity does not always provide the full context.

A website may have been opened automatically by an application. An employee may be researching a customer, investigating a phishing email or accessing social media as part of their role.

Businesses should avoid making important decisions based only on automated reports.

Any concern should be reviewed fairly, with the employee given an opportunity to explain the activity.

Should You Block Websites Instead of Monitoring Them?

In many cases, blocking known risks is more effective than constantly monitoring employees.

A secure web-filtering platform can prevent access to:

* Known malware websites
* Phishing pages
* Dangerous downloads
* Newly created suspicious domains
* Illegal content
* Unapproved file-sharing services
* Websites that breach company policy

Blocking reduces the opportunity for misuse and may collect less personal information than detailed surveillance.

Businesses can also apply different policies to different groups.

For example, the marketing team may need access to social media websites that are not required by other departments. The IT team may need access to software download pages that would normally be restricted.

Policies should support the way employees genuinely work rather than applying unnecessary restrictions to everyone.

Create an Acceptable-Use Policy

Before monitoring or restricting internet access, your business should have a clear acceptable-use policy.

The policy should explain:

* Whether reasonable personal internet use is permitted
* Which websites or services are restricted
* Whether company devices may be used outside work
* Whether internet activity is recorded
* Why monitoring takes place
* Who may review the records
* How long information may be retained
* How suspected misuse will be investigated
* What disciplinary action may follow serious misuse
* How employees can raise questions or concerns

Employees should be given access to the policy and made aware of any important changes.

The policy should be written clearly. Employees should not need technical or legal knowledge to understand what is expected of them.

Carry Out an Impact Assessment

Before introducing extensive monitoring, businesses should assess its likely impact.

Acas recommends considering the reason for the monitoring, its expected benefits, any negative effects, possible alternatives and whether there is a valid justification.

The assessment should consider:

* What problem the business is trying to solve
* Whether monitoring will genuinely address that problem
* What information will be collected
* Whether less intrusive options are available
* Which employees will be affected
* How the information will be protected
* How long it will be retained
* Who will be allowed to access it
* Whether monitoring remains proportionate

More intrusive or high-risk monitoring may require a formal data protection impact assessment.

The business should also review monitoring regularly rather than leaving it in place indefinitely without checking whether it is still required.

Use the Least Intrusive Method

Monitoring should be limited to what the business genuinely needs.

For example, if the objective is to prevent malware, the business may only need security alerts and blocked-site reports. It may not need to record every legitimate website each employee visits.

If the concern is excessive video streaming, the business may be able to review total bandwidth use rather than an individual’s complete browsing history.

If the objective is to prevent data loss, the business may focus on unusual file transfers and unapproved cloud services rather than recording all online activity.

A targeted approach is normally easier to justify and less likely to undermine trust.

Keep Monitoring Information Secure

Internet usage records should be treated as confidential business information.

Access should be restricted to people with a genuine need to see it, such as authorised managers, HR representatives or the IT security team.

Businesses should also decide:

* Where monitoring records are stored
* How the information is encrypted
* How access is logged
* How long records are retained
* How old information is securely deleted
* How data requests will be handled
* What happens if the monitoring platform is compromised

Collecting information without protecting it properly can create more risk than it solves.

Focus on Security Rather Than Surveillance

For most small and medium-sized businesses, monitoring should primarily focus on security and compliance.

Useful controls may include:

* Secure web filtering
* Malware and phishing protection
* Endpoint detection and response
* Microsoft 365 security monitoring
* Data-loss prevention
* Application control
* Firewall reporting
* Blocking unapproved cloud storage
* Alerts for unusual downloads
* Device and account monitoring

These controls can help identify dangerous behaviour without requiring managers to watch every employee’s activity.

The aim should be to reduce risk, not to create a workplace where employees feel constantly observed.

So, Should You Track Employees’ Internet Usage?

There is no single answer that is suitable for every business.

Some level of internet security monitoring is sensible for most organisations. Businesses need to identify malicious websites, dangerous downloads, unusual data transfers and attempts to access restricted services.

However, detailed monitoring of every employee’s browsing history should only be used where there is a clear, lawful and proportionate reason.

Before introducing monitoring, ask:

* What problem are we trying to solve?
* Is monitoring necessary?
* Could web filtering solve the problem instead?
* Are we collecting more information than we need?
* Have employees been told what we are doing?
* Is the information being stored securely?
* Could the monitoring damage trust?
* Do we have a clear policy?
* Have we obtained suitable HR or legal advice?

The right approach should protect the business while respecting employees’ privacy.

How Hamilton Group Can Help

Hamilton Group helps businesses protect their networks, devices and data through managed IT support and cybersecurity services.

We can help with:

* Secure web filtering
* Firewall management
* Internet usage reporting
* Malware and phishing protection
* Microsoft 365 security
* Managed endpoint protection
* Data-loss prevention
* Application control
* Network monitoring
* Acceptable-use policy support
* Cybersecurity awareness training
* Cyber Essentials support

We can review your current internet security, identify unnecessary risks and recommend controls that protect your business without introducing excessive employee surveillance.

Call Hamilton Group today on 0330 043 0069 to discuss secure internet access, web filtering and the right monitoring approach for your business.