Performance Leader's top tips to support digital security
Security is an ongoing process that requires constant vigilance. To help our clients ensure their performance management system stays safe – and to engage their staff as a front line of defence – we’ve identified nine crucial security measures they can implement immediately.
Our top nine security tips are to:
- use single sign-on (SSO) – this measure is more secure than passwords and ensures people who leave the firm have their access removed immediately
- enable multi-factor authentication (MFA) – Performance Leader MFA on all admin accounts provides added security on top of SSO
- sync with HRIS – this measure keeps user lists updated daily or weekly, and revokes access for departed users (note: it’s important to only use work emails, even for test accounts)
- apply least privilege access – this involves granting users the minimum access required for their job functions (e.g. use Restricted Admin instead of Super Admin access where appropriate)
- conduct regular access reviews – these periodic checks look at user permissions (e.g. Super Admin, Restricted Admin and Leadership Views) to reflect current roles and responsibilities
- monitor admin activities – reviews of admin user activity make it easier to spot unusual behaviour, such as an admin trying to log in without SSO (you can also sign up for weekly admin email reports)
- Use secure file transfer – no admin task requires sending us personally identifiable employee data (e.g. user uploads), so if a secure file transfer is required for a custom workflow, use a secure file sharing tool like Egnyte, Sharepoint or Dropbox
- know your CSM – Performance Leader staff will never email you from personal addresses, so if you are unsure about any correspondence, schedule a video conference with us or email support@performanceleader.com, and
- when in doubt, reach out – we prefer receiving false alarms over missing a real incident so if you are concerned about anything, email security@performanceleader.com
If you’d like any more information about implementing these measures, contact your CSM or email support@performanceleader.com.