Advo’s Operations Manager, Nic Draycott, outlines the importance of employees in any cyber security within an organisation. Their understanding and implementation of protocols is essential.
When companies think about cyber security, they’ll often think of firewalls, antivirus software and IT infrastructure. Whilst these technical measures are essential, one of the biggest cyber security risks remains the people within an organisation. According to the UK Government’s Cyber Security Breaches Survey 2025/26, phishing remains the most common type of cyber-attack experienced by UK businesses, with 38% of businesses identifying phishing attacks in the previous 12 months. The survey also found that 93% of businesses experiencing cybercrime reported phishing as part of the incident.
As many of these attacks rely on employees unknowingly responding to fraudulent emails or requests, for us, it’s not just our IT team, but importantly our HR and Payroll teams that play a crucial role in protecting sensitive business and employee data through effective policies, training and secure processes. Your whole company needs to be aware of the dangers.
Our HR and Payroll teams are responsible for handling some of an organisation’s most valuable information, including employee records, bank account details, salaries and home addresses. This makes them an attractive target for cyber criminals, who are increasingly using phishing emails, fraudulent payment requests and social engineering techniques to gain access to confidential information.
Creating a strong cyber security culture starts with clear policies and well informed employees. Regular training helps staff recognise suspicious emails, understand the importance of strong passwords and know how to report potential security threats. Embedding good cyber security practices into the employee lifecycle from onboarding through to leaving the business, can significantly reduce the risk of data breaches.
Effective joiner, mover and leaver processes also play an important role. Ensuring new employees understand their responsibilities for handling sensitive information, reviewing system access when employees change roles and promptly removing access when someone leaves the business are all simple, but effective measures that help protect organisational data.
Payroll processes should also be regularly reviewed to minimise risk. Introducing approval workflows and maintaining clear audit trails can help prevent fraudulent activity and provide greater confidence in payroll accuracy.
Cyber security compliance extends beyond technology, frameworks such as Cyber Essentials and data protection legislation place increasing emphasis on governance, documented processes and employee awareness. Companies that regularly review their HR policies, employee records and payroll procedures are often better placed to demonstrate compliance while reducing operational risk.
As Cyber threats continue to evolve, organisations should view cyber security as a shared responsibility rather than solely an IT function. At Advo we are proud to be certified in both Cyber Essentials and Cyber Essentials Plus, demonstrating our commitment to protecting the sensitive employee and payroll data entrusted to us. These independent certifications provide our clients with confidence that robust cyber security controls underpin our outsourced HR and Payroll services, helping them meet their own compliance obligations while benefiting from secure, reliable and trusted support.
Need support reviewing your HR processes or payroll controls? Our experienced HR and Payroll professionals can help you strengthen your people processes, improve compliance and ensure your organisation is well prepared for today’s evolving cyber security challenges. Contact us to find out how we can support your business.



Article written by Nic Draycott, Advo’s Operations Manager