How to train staff on a clean desk policy

How to train staff on a clean desk policy: what it covers, a training sequence that changes habits, and how to measure compliance without policing desks.

A clean desk policy is a workplace rule requiring staff to clear confidential papers from their desks, lock their screens and put away removable media whenever they leave the desk — during the day and at close of business. It is usually paired with a clear screen rule (lock your computer every time you step away), which is why standards like ISO 27001 treat them as one control: clear desk and clear screen. The point is not tidiness. It is that confidential information — client lists, payslips, contracts, unlocked systems — must never be exposed to someone who should not see it.

TL;DR

Why a clean desk policy matters

A policy on paper documents and locked screens is the physical sibling of phishing training. Both address the same truth: controls fail at the point of human contact. The Office of the Australian Information Commissioner reported that human error caused 37% of all data breaches in the first half of 2025, up from 29% in the previous period — before counting the criminal attacks that started with someone being careless. An unlocked screen in a shared office, a payslip left in the printer tray or a client contact list visible from reception is a breach waiting for a visitor, a cleaner or a contractor with a phone.

Some industries do not get a choice. ISO 27001 includes clear desk and clear screen as an explicit control, so any organisation certified against it — or answering its questionnaires — needs a written policy and evidence that staff follow it.

What a clean desk policy should cover

ItemRuleNotes
Papers and printoutsFiled or shredded at end of day; nothing sensitive left outCollect printouts from the printer tray immediately
Screens and devicesLocked every time you step away; auto-lock after 5 minutesWin+L on Windows, Ctrl+Cmd+Q on Mac
Removable mediaUSBs and external drives stored in a locked drawerNo unknown USBs plugged in — ever
Whiteboards and notesClient names, credentials and contact details wiped or removedPhotos of whiteboards are a common leak
Visitor areasNothing visible from reception, meeting rooms or windowsWalk the route a visitor takes

Keep the policy to one page. A twelve-page policy is a document nobody reads and nobody can be trained on.

How to train staff on it

1. Explain the why, with a real consequence

Staff follow rules they understand. Open with the failure mode: a competitor or scammer photographs a screen, or a payslip left on a desk becomes a privacy complaint to the OAIC. Human error drove 37% of Australian breaches in the first half of 2025 — a reminder that the small, everyday slip is where breaches actually start.

2. Rehearse the leaving-the-desk moment

The habit lives or dies in the two seconds when someone stands up. Run it as a drill: the phone rings, you stand — what do you do? Lock the screen, papers away, drawer closed. Repeat it until the sequence is automatic, the same way you rehearse verifying a payment request. A memo describing the moment does not train the moment.

3. Run the visitor test

Have a colleague walk the office as a visitor would — reception, corridors, meeting rooms — and photograph what is visible (with your approval and only internally). Count what a stranger could learn in ten seconds: client names on a whiteboard, an invoice on a desk, an unlocked laptop facing the door. Share the results with the team, without naming individuals. This makes the risk concrete in a way no policy statement does.

4. Fold it into recurring training

Clean desk is one behaviour among many. It works best as part of a monthly cadence rather than a once-a-year policy launch. Cyber Aware's training ships short modules you can assign on a schedule — pair a clean-desk module with phishing and password modules so the behaviours reinforce each other. An unlocked screen and a forwarded phishing attachment are the same failure type: information handed to someone who should not have it.

5. Spot-check and measure

Pick a simple measure — the percentage of desks passing a weekly five-minute walk — and track the trend, not the individuals. Coach failures privately. Publish the trend openly. What gets a number gets attention, and what gets a public shaming gets resentment instead of compliance.

6. Keep the evidence

Auditors, certifiers and insurers ask two things: is there a written policy, and can you show staff were trained on it. Keep the policy, the training completion records and the spot-check trend together. Cyber Aware's gap assessment shows where the human-risk gaps sit before an auditor finds them, and completion records per person can be exported as evidence.

Common mistakes

FAQ

Does a clean desk policy apply to remote workers? Yes. Sensitive papers and unlocked screens at home are exposed to household members, visitors and delivery people. Adapt the rules — lockable storage, automatic screen locks, shredding or secure return of papers — rather than exempting home workers.

How often should we train the clean desk policy? At onboarding for new starters, then as a short reinforcement module on a monthly cadence. A single annual briefing does not produce a daily habit.

Is locking the screen enough on its own? No. An unlocked policy also covers papers, printouts, USBs and what is visible from visitor areas. Screen locking is one control inside a wider policy.

How do we get senior staff to comply? Hold everyone to the same rule and start with the leadership team's own desks. Nothing kills a policy faster than staff seeing managers exempt from it.

Related guides

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.