Train Staff to Handle Suspicious USB Devices 2026

Train staff to handle suspicious USB devices in 2026: do not plug in, isolate safely, report within two minutes and protect evidence.

A USB drive found in a car park, meeting room or reception desk is not a harmless lost-and-found item. This 2026 guide explains how to train staff to handle suspicious USB devices without plugging them in, spreading malware or exposing business data.

TL;DR

Why this matters

Unknown USB devices are designed to exploit curiosity, helpfulness and urgency. A label such as “Payroll,” “Photos” or “Confidential” can be enough to persuade someone to connect it to a computer. That one action can introduce malicious code or create an unauthorised path to data.

Training staff to handle suspicious USB devices needs a simple rule: do not plug it in. Instead, isolate it safely, record where it was found and report it. Begin with awareness training so employees understand that the risk comes from connection, not from touching the item.

In 2026, Cyber Aware security awareness training should also cover personal USB devices. A drive from home, a supplier or a conference still needs to follow the organisation’s approved removable-media process.

What you'll need

Use empty training props only. Do not connect unknown or simulated devices to any system during a lesson.

Step 1: Set the non-connection rule

State the rule plainly: an unknown USB device must never be connected to a work computer, personal computer, kiosk or charging port. The location and label do not make it safe.

Explain that a USB drive can act as more than storage. It can carry malicious files or behave like another kind of device when connected. The safest response is to leave the content unread.

Expected outcome: Every staff member can state “do not plug it in” without hesitation.

Common mistake: Allowing a staff member to check a device on an old or offline laptop. That still creates risk and can destroy evidence.

Step 2: Identify the immediate scene risk

Teach staff to notice where the device was found. A USB drive in a public reception area differs from one found beside a restricted workstation or a finance printer. The location affects who needs to be told and whether the area needs further review.

Staff should not search for an owner by inserting the device, browsing its label online or asking colleagues to test it. They should record the location, time and visible description.

Expected outcome: The first report includes enough location detail to support a response.

Common mistake: Passing the device around so several people can inspect it.

Step 3: Isolate without improvising

If the local policy allows safe handling, place the device in a labelled envelope or designated secure container without connecting it to anything. If a device is in a restricted area, leave it where it is if moving it could affect evidence and contact the responsible team.

The policy must name who collects devices and where they go. A vague instruction to “give it to IT” fails when the device is found outside business hours.

Expected outcome: Staff know the collection point and responsible contact.

Common mistake: Keeping the device in a desk drawer until someone remembers to mention it.

Step 4: Use the two-minute report

The report needs four fields: what was found, exact location, time discovered and whether anyone connected it. Add a photo only if policy allows and it does not require moving the device.

Make the report route visible in reception, meeting rooms and shared spaces. Cyber Aware security awareness training should teach that an early report is useful even when the device turns out to be a colleague’s harmless drive.

Expected outcome: A report reaches security or IT within 2 minutes.

Common mistake: Waiting to report until an owner is identified.

Step 5: Cover personal and supplier devices

Staff often assume that a USB drive from a trusted supplier, home office or event is safe. It still requires the approved process, especially if it will connect to a business system.

Set a practical alternative: use approved file-sharing services or arrange for IT to scan and transfer necessary content through a controlled process. In 2026, convenience is not a reason to bypass removable-media controls.

Expected outcome: Staff know there is a secure route for legitimate file transfer.

Common mistake: Using a personal USB drive to move a file because the network is slow.

Step 6: Rehearse a realistic scenario

Place a labelled training prop near a printer or meeting room. Ask staff to choose between plugging it in, moving it without reporting, or using the approved report-and-isolate process. Debrief the choice in 5 minutes.

Use phishing simulations to connect the physical scenario to digital social engineering. A suspicious email attachment and a found USB drive use the same pressure point: curiosity before verification.

Expected outcome: Staff choose the correct action under ordinary workplace conditions.

Common mistake: Making the prop obviously fake, which removes the judgement call.

Step 7: Follow up on patterns, not blame

Review whether devices are found repeatedly in the same site, area or supplier process. A cluster may indicate a physical-security gap or a need for clearer disposal procedures.

Use human risk reporting to identify training follow-up based on observed behaviour and report completion. Cyber Aware security awareness training should treat staff reports as a positive outcome.

Expected outcome: The organisation learns from reports and improves the physical environment.

Common mistake: Naming or shaming people who report a device late.

Troubleshooting

Someone already connected the USB device

Disconnect it only if instructed by the incident process, stop using the computer and report immediately. Include the device, time and actions taken.

The device has a company logo

Treat it as untrusted until the approved owner or IT process confirms it. A logo does not establish safety.

The device is found in a restricted area

Follow site security instructions and report the exact location. Do not move it if the local process requires evidence preservation.

A supplier needs to transfer files by USB

Use the approved controlled process or a secure file-sharing method. Do not make an exception at the desk.

Tools and resources

What to do next

Run a 10-minute found-USB drill at one office or client site this quarter, then test whether staff can name the report route without looking it up. Use the result to improve signage and the next Cyber Aware refresher.

FAQ

What should staff do when they find an unknown USB device?

Staff should not plug it in. They should follow the approved isolate-and-report process, recording the exact location and time it was found.

Can staff check a USB device on an old computer?

No. An old or offline computer still creates malware and evidence-handling risk. Only an approved controlled process should examine the device.

Is a USB drive with a company logo safe?

No. A company logo does not prove ownership or safety. Handle it through the same report-and-isolate process as any unknown device.

What if someone already plugged in the USB device?

They should stop using the computer and report immediately through the incident process. Include the device, time and actions taken so the team can respond quickly.

How should suppliers transfer files safely?

Use an approved secure file-sharing service or IT-controlled transfer process. Do not bypass removable-media controls for convenience.

How often should USB-device training run?

Run a short physical scenario at least annually and include the rule in induction training. Repeat it after a found-device event or policy change in 2026.

One last thing

The best response to a found USB device is deliberately uneventful: do not connect it, document it and pass it to the right team. That restraint prevents the incident from becoming a technical crisis.

Related guides

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.