top of page

Why Locking Your Computer Is a Compliance Issue

Sep 28
3 min read
Hands typing on a laptop with a glowing digital padlock and checkmark, suggesting secure login or online protection

What do you do when you’re in the office and need another cup of coffee? Perhaps you stand up from your desk, walk to the break room, talk to a coworker for a minute, and come back.

You were gone for five minutes. What’s the big deal?

If you left your computer unlocked, you may have potentially put a lot of sensitive information at risk.

We tend to think about unauthorized access as someone stealing a password or hacking into an account from thousands of miles away. Sometimes, however, gaining access is as simple as sitting down at an unattended computer.

Your Login Gives You Access for a Reason

Your work account is probably not identical to everyone else’s. Depending on your job, you may have access to customer records, employee information, financial documents, internal communications, or other sensitive information.

Those permissions are assigned specifically to you.

This is part of an important compliance concept called the Principle of Least Privilege. You and all your coworkers should receive only the minimum access necessary to do your job.

Leaving your computer unlocked can completely undermine that protection. Someone without permission to access a particular system may suddenly be able to access it through your account.

Most people don’t intentionally leave their computers exposed. You expect to walk away for 30 seconds…but then, someone stops you in the hallway. Your phone rings. A heated conversation pulls you in.

Suddenly, your unlocked computer has been sitting unattended for ten minutes! It doesn’t necessarily take ten full minutes for someone to cause a problem, though. Someone could read an email, open a customer record, copy a file, send a message from your account, or photograph information on your screen in seconds.

It Creates an Accountability Problem, Too

Your organization may also maintain audit logs showing who accessed sensitive information and what they did with it. Those records can be extremely important during a cybersecurity investigation.

Now, let’s suppose someone uses your unlocked computer to open a confidential file. The system may record that your account accessed it. This creates an auditability problem: Was it actually you? Did someone else use your computer? What did they see? Did they copy anything?

One unlocked workstation can make a simple audit trail much more complicated to follow.

What About Working From Home?

Locking your computer matters outside the office, too. Working from home does not automatically make company information less sensitive.

Family members, roommates, visitors, maintenance workers, and other people may be nearby. Even if you completely trust them, they’re probably not authorized to access your company’s systems. You may not care, but imagine if you were a customer. Would you want your IRS caseworker’s husband to see your SSN?

The same rule applies when working from hotels, airports, coworking spaces, or other public locations. If you walk away, lock the screen.

Making Compliance a Habit

Fortunately, this is one of the easiest compliance risks to prevent.

Get into the habit of locking your computer every time you leave it, even if you expect to be gone for a mere few seconds.

On a Windows computer, press the Windows key + L to lock your screen immediately.

On a Mac, you can press Control + Command + Q.

It’s a very fast keyboard shortcut that makes a big difference to your data privacy.

You should also allow your organization’s automatic screen-lock settings to do their job. Don’t disable or extend them just because repeatedly signing in feels inconvenient. Those settings exist for a reason!

Locking the Screen Doesn’t Mean You Don’t Trust Your Coworkers

Some people feel silly locking their computers when they work in a small office where everyone knows one another. Just remember, these cyber-hygiene tips aren’t about suspicion.

Cyber-compliance requires organizations to control access to sensitive information. Your coworker may be completely trustworthy and still have no legitimate reason to access the customer records available through your account.

Good access control protects everyone by keeping clear boundaries around who can see what.

Conclusion

You can have a strong password, multi-factor authentication, and carefully controlled permissions…but none of those protections help very much if you authenticate yourself and then leave the computer open for someone else.

Locking your screen is one of the smallest cybersecurity habits you can develop, but it protects something incredibly important: Your identity and everything your account has authorization to access.

Coffee can wait one extra second. Always lock your screen before you leave.

Comments


bottom of page