Securing the Modern Workplace

Cybersecurity is evolving just as quickly as the technology we use every day. From passwordless authentication and AI-powered meeting assistants to QR code payments, modern tools are helping organisations work smarter, but they also introduce new security considerations.

Understanding how these technologies can be exploited, and how to use them safely, is becoming just as important as adopting them in the first place.

Securing the Modern Workplace

QR Code Scams: How to Spot and Avoid "Quishing"

QR codes are now part of everyday business, whether you're accessing restaurant menus, making payments, connecting to Wi-Fi, or opening shared documents. Unfortunately, cybercriminals are increasingly using QR codes to hide malicious links and bypass traditional email security.

Known as "quishing", these attacks replace a visible hyperlink with a QR code that directs users to fake login pages or payment portals designed to steal credentials and financial information.

Microsoft recently reported a significant increase in QR code phishing campaigns, making it an attack method organisations should be aware of.

Why It’s a Risk:

QR codes hide malicious links from traditional email scanning.

Users are often redirected to personal mobile devices with fewer security controls.

Fake Microsoft, supplier, and payment requests increasingly use QR codes instead of links.

What You Can Do:

Treat QR codes with the same caution as suspicious links.

Check the web address your phone displays before opening it.

If you're unsure, navigate directly to the website rather than scanning the code.

Enable phishing-resistant MFA wherever possible.

Report suspicious QR codes to your IT team.

Common QR Code Scams

Fake QR codes placed over genuine parking meter or payment terminal stickers.

QR codes embedded within PDF invoices.

Emails asking you to "Scan to keep your account active" or verify your Microsoft account.

The Beginning of the End for Passwords: Enter Passkeys

Passwords remain one of the weakest points in cybersecurity. Weak passwords, password reuse, and phishing continue to be responsible for many successful cyberattacks.

Passkeys provide a more secure alternative by replacing reusable passwords with phishing-resistant cryptographic credentials, allowing users to authenticate using biometrics or the PIN already used to unlock their device.

Major platforms including Microsoft, Google, and Apple now support passkeys, and Microsoft Entra will make passkeys the default authentication experience from September 2026.

Why It’s a Risk: 

Passwords can be guessed, reused, stolen, or exposed in data breaches.

Traditional MFA can still be targeted through phishing or MFA fatigue attacks.

Managing multiple passwords creates unnecessary risk for users.

What You Can Do:

Introduce passkeys for administrators, finance teams, and privileged users first.

Allow users to register a passkey alongside their password during the transition.

Configure a backup authentication method such as a second device or security key.

Retain passwords only for applications that do not yet support passkeys.

Benefits of Passkeys

Resistant to phishing attacks.

Eliminates password reuse.

Faster and simpler sign-in experience.

Reduces the risk of MFA fatigue attacks.

AI Note-Takers and Information Security: Understanding the Exposure

AI-powered meeting assistants are becoming increasingly common, automatically recording meetings, generating transcripts, summarising discussions, and identifying actions. While these tools can improve productivity, they can also introduce security, privacy, and compliance risks if not managed appropriately.

Unlike traditional meeting notes, AI note-takers often capture conversations word for word, increasing the amount of sensitive information being stored and shared.

Why It’s a Risk: 

Sensitive business discussions may be recorded unnecessarily.

Meeting transcripts could be stored outside organisational control.

AI platforms may retain or process meeting data differently depending on the vendor.

Users may not realise an AI assistant has joined or is recording a meeting.

What You Can Do:

Approve a single AI note-taking platform for business use.

Confirm whether meeting data is used to train AI models.

Disable automatic meeting joining unless explicitly required.

Obtain consent before recording meetings.

Restrict AI note-takers from highly confidential discussions.

Apply access controls and appropriate retention policies to recordings and transcripts.

Train employees on when AI note-takers should and should not be used.


Visibility, Awareness and Control

29 May 2026

Cybersecurity risks are not always caused by sophisticated attacks or major system failures. In many cases, risk builds quietly through everyday habits, overlooked processes, and limited visibility into where data is stored or how users interact with systems.

Reducing Risk Through Strong Foundations

29 May 2026

Learn how to reduce cyber risk through stronger security foundations. This month's bulletin covers home office security, legacy technology risks, vulnerability management, MFA, and cybersecurity best practices.