Skip to content
Ask What They Collect

All notes / Personal

Passwords, Banking and the Obvious Risks

The few things that genuinely matter to protect, and the simple arrangements that handle them.

Personal · Procedure

Most of what people worry about on a work machine does not matter much. A short list does, and it is protected by habits rather than by vigilance.

The technical issue in “Passwords, Banking and the Obvious Risks” becomes easier to govern when work records and device controls are kept distinct. A team researching the platform website for 7 minute rule payroll can add time and project context, while security logs and device-management systems remain authoritative for technical events.

Passwords

Never save personal passwords in a work browser profile.

For an independent perspective related to “Passwords, Banking and the Obvious Risks”, consult the CISA cybersecurity guidance; it provides a useful external check on privacy, fairness and governance assumptions before a policy or configuration is approved.

Use a personal password manager on a personal device for personal accounts, and whatever the employer provides for work accounts.

The two should not mix in either direction.

This is not about anybody reading them — browsers protect stored passwords — it is about where they live when the device is recalled.

Banking

On a personal device, always.

Not because of monitoring, but because a managed machine is administered by somebody else, and financial access should sit on hardware you control.

If you have no alternative during the day, do it from a phone on mobile data rather than the work machine.

Two-factor codes

Keep the second factor for personal accounts on a personal device.

An authenticator application on a work phone means losing the phone means losing access to your own accounts.

This catches people out at departure more than anywhere else, and it is simple to avoid.

Personal email

A personal address in a work email client pulls your personal mail into a managed environment.

Use a browser in a private window, or a personal device.

And never make a work address the recovery address for a personal account, which is the version of this that causes real harm when access ends.

The recovery-address point, properly

If a work email is the recovery route for a personal account, you lose that account when the job ends.

Check every important personal account for this now: email, banking, cloud storage, social.

Twenty minutes, once, and it removes a whole category of loss.

What is genuinely low risk

Reading news on a work machine.

A personal calendar entry with a neutral title.

A message replied to at lunch.

These do not need protecting, and treating everything as high risk makes the real list easier to ignore.

Shared and public machines

Different problem: sign out, close the session, do not stay logged in.

Browser profiles on a shared machine persist, and the next person inherits them.

Where a work machine is genuinely shared, treat it as public.

What to check

Are any personal passwords saved in a work browser?

Is your second factor for personal accounts on a work device?

Is a work address the recovery route for anything of yours?

And do you have a personal device available during the working day?