1
Security Basics for New Hires
On screen
Security Basics for New Hires. By the end, you'll know how to build a strong password, spot a phishing email, and lock down your workspace.
Visual
map
a simple opening graphic of a laptop and an ID badge, representing day one
Narration
“Welcome to Meridian Works. In the next few minutes, you'll learn the handful of habits that keep your new account and laptop safe. No tech background needed.”
none
Notes
Title screen. Audience inferred as mixed-role, day-one new hires (warehouse, office, sales); keeping language non-technical throughout.
2
Why This Matters
On screen
You have a laptop and a login today, most of them brand new. A few small habits protect your account and Meridian's information. None of it requires technical skill.
Visual
shield
a laptop and ID badge under a simple shield, representing protection from day one
Narration
“You just got a laptop and a work login, maybe your first one ever. That account can reach company systems and information. A few simple habits keep it safe, and none of them require technical skill.”
none
Notes
Source: notes line 3. Sets the stakes plainly, without alarming new hires.
3
Passwords: Length Over Complexity
On screen
Skip the ! and the number. A long password beats a complex one. Use 3 or 4 unrelated words, like copper-lantern-drift-pony.
Visual
lock
a password field showing four random words strung together instead of symbols
Narration
“Forget adding a symbol and a number, length is what actually protects a password. Pick 3 or 4 words that don't relate to each other, something like copper-lantern-drift-pony. Longer and random beats short and complex.”
click-reveal
Notes
Source: notes line 4. Example phrase quoted directly from source notes.
4
Never Reuse Your Work Password
On screen
Never reuse your work password anywhere else. When another site gets breached, attackers try that same email and password everywhere, including here.
Visual
alert
a single password reused across several login screens, flagged with a warning mark
Narration
“Don't use your work password on any other site. When a shopping site or app gets breached, attackers try that same email and password against every account they can find, including yours here.”
click-reveal
Notes
Source: notes line 5, which references an account Meridian actually lost this way last spring. Confirm with SME whether to name that incident on screen.
5
Your Password Manager Is Already Installed
On screen
Your password manager (1Password) is already installed on your laptop. Look for its icon and use it to generate and store strong passwords.
Visual
computer
a browser toolbar with the 1Password icon highlighted
Narration
“IT already installed a password manager called 1Password on your laptop. Most people don't notice it's there. Look for its icon in your browser bar. It can generate and remember strong passwords for you.”
click-reveal
Notes
Source: notes line 6.
6
Phishing Tell #1: Urgency, Not Spelling
On screen
Phishing emails don't always have typos. The real tell is urgency: "account closes in 1 hour," "invoice overdue," "I'm boarding, sort this now."
Visual
envelope
an email with an urgent subject line highlighted
Narration
“Don't rely on spelling mistakes to spot a phishing email, plenty of them read cleanly. Watch for urgency instead: a message pushing you to act right now, before you have time to think it through.”
click-reveal
Notes
Source: notes line 7, examples quoted directly.
7
Hover Before You Click
On screen
Before you click any link, hover over it. Read the real address at the bottom of the screen. This is the single best habit you can build.
Visual
computer
a cursor hovering over a link, revealing the true address below it
Narration
“Before you click a link in an email, hover over it first. The real address shows at the bottom of your screen, and it's often different from the text you see. This one habit catches most fakes.”
click-reveal
Notes
Source: notes line 8, called out there as "the single best habit."
8
Go to the Site Yourself
On screen
Lookalike web addresses are hard to catch by eye (meridian-works vs meridianworks vs meridianw0rks). When in doubt, type the address yourself instead of clicking.
Visual
map
two near-identical web addresses side by side, next to a hand typing a fresh one into a browser bar
Narration
“Some fake addresses look almost identical to ours, just one letter or hyphen off. Nobody can be expected to catch every one. So instead of trusting a link, go to the site yourself by typing the address in.”
click-reveal
Notes
Source: notes line 9, lookalike domain examples quoted directly.
9
Never Open an .html Attachment
On screen
An .html or .htm file attached to an email is a fake login page. Meridian Works never sends those. Don't open one, don't enter your password.
Visual
folder
an email attachment icon marked with a warning cross
Narration
“If an email attachment ends in dot h t m l or dot h t m, treat it as a fake login page. We never send attachments like that. Don't open it, and never type your password into it.”
click-reveal
Notes
Source: notes line 10.
10
Lock Your Screen Every Time
On screen
Lock your screen every time you step away. Windows: Win+L. Mac: Ctrl+Cmd+Q. Anything done on an unlocked machine is logged as you.
Visual
lock
a laptop screen locking itself as someone walks away from a desk
Narration
“Lock your screen any time you leave your desk, even for a minute. On Windows, press Win and L. On a Mac, press Control, Command, and Q. Whatever happens on an unlocked machine is recorded as your action.”
click-reveal
Notes
Source: notes lines 12-13. Two real incidents from unlocked laptops in the shared kitchen (both pranks) prompted this rule. Confirm with SME whether to reference those incidents on screen.
11
Clean Desk, Too
On screen
Clear your desk too. Put away visitor passes, printouts, and anything on a whiteboard once a meeting ends.
Visual
folder
a desk with a visitor pass and printouts being tidied into a drawer
Narration
“Screen locks aren't the only habit. Clear your desk before you leave it: visitor passes, printouts, and anything left on a whiteboard after a meeting.”
click-reveal
Notes
Source: notes line 14.
12
Don't Approve a Prompt You Didn't Trigger
On screen
Multi-factor authentication is already on for your email. If you get a login prompt on your phone you didn't trigger, deny it. Someone else has your password.
Visual
phone
a phone showing an MFA approval prompt with a deny option highlighted
Narration
“You'll get a prompt on your phone whenever you sign in to email. Only approve it if you just tried to log in yourself. If a prompt shows up out of nowhere, someone else is trying to use your password. Deny it.”
click-reveal
Notes
Source: notes line 15.
13
Scenario: Would This Pass?
On screen
An email says "Your account closes in 1 hour, click here to verify." Hovering over the link shows meridianw0rks.com, not our real address. Would you click it?
Visual
alert
the email scenario shown with the hovered link address revealed underneath
Narration
“Here's a message combining two of today's warning signs: urgency, and a link address that doesn't match ours. What would you do?”
1-question check
Notes
Scenario built from the urgency example (line 7) and the lookalike-domain example (line 9). Correct answer: don't click it, report it.
14
If You Click, Report It Fast
On screen
If you ever click a bad link, tell the service desk right away. Call ext 2200 or use the Report Phish button in Outlook. Reporting fast is never a problem.
Visual
phone
a hand pressing the Report Phish button next to a phone showing ext 2200
Narration
“If you click a link you shouldn't have, don't hide it, tell the service desk immediately. Call extension 2200 or use the Report Phish button in Outlook. Nobody has ever been disciplined for reporting fast, only for staying quiet.”
none
Notes
Source: notes line 11. States the real consequence of a slip and the safe path out of it.
15
Check Your Understanding (Q1)
On screen
Which password is strongest? A) Sunshine1! B) copper-lantern-drift-pony C) Password123
Visual
check
the question framed as a quick check, not a test
Narration
“Let's check what you remember.”
1-question check
Notes
First of three knowledge-check screens. Correct answer: B, per notes line 4.
16
Check Your Understanding (Q2)
On screen
What's the biggest red flag in a phishing email? A) Spelling mistakes B) A sense of urgency C) A long subject line
Visual
check
the question framed as a quick check, not a test
1-question check
Notes
Second knowledge-check question. Correct answer: B, per notes line 7.
17
Check Your Understanding (Q3)
On screen
You clicked a suspicious link by mistake. What should you do? A) Say nothing and hope for the best B) Call ext 2200 or use Report Phish right away C) Wait to see if anything happens
Visual
trophy
the closing win state
Narration
“Nice work, you've completed this module.”
1-question check
Notes
Third question and closing. Always the last screen. Correct answer: B, per notes line 11.