A USB drive found in a car park, meeting room or reception desk is not a harmless lost-and-found item. This 2026 guide explains how to train staff to handle suspicious USB devices without plugging them in, spreading malware or exposing business data.
TL;DR
- A suspicious USB device is a report-and-isolate event, never a plug-in-and-check task.
- In 2026, staff should not connect an unknown USB device to a work, personal or shared computer.
- A clear chain of custody and a two-minute report protect people and evidence.
- Cyber Aware awareness training lets teams practise removable-media decisions without real malware.
Why this matters
Unknown USB devices are designed to exploit curiosity, helpfulness and urgency. A label such as “Payroll,” “Photos” or “Confidential” can be enough to persuade someone to connect it to a computer. That one action can introduce malicious code or create an unauthorised path to data.
Training staff to handle suspicious USB devices needs a simple rule: do not plug it in. Instead, isolate it safely, record where it was found and report it. Begin with awareness training so employees understand that the risk comes from connection, not from touching the item.
In 2026, Cyber Aware security awareness training should also cover personal USB devices. A drive from home, a supplier or a conference still needs to follow the organisation’s approved removable-media process.
What you'll need
- 20 minutes for the lesson and 10 minutes for a physical response drill.
- A written removable-media policy.
- A secure collection point or named team responsible for unknown devices.
- A two-minute report template.
- Disposable training props that cannot store data.
- A clear escalation route for devices found in restricted areas.
Use empty training props only. Do not connect unknown or simulated devices to any system during a lesson.
Step 1: Set the non-connection rule
State the rule plainly: an unknown USB device must never be connected to a work computer, personal computer, kiosk or charging port. The location and label do not make it safe.
Explain that a USB drive can act as more than storage. It can carry malicious files or behave like another kind of device when connected. The safest response is to leave the content unread.
Expected outcome: Every staff member can state “do not plug it in” without hesitation.
Common mistake: Allowing a staff member to check a device on an old or offline laptop. That still creates risk and can destroy evidence.
Step 2: Identify the immediate scene risk
Teach staff to notice where the device was found. A USB drive in a public reception area differs from one found beside a restricted workstation or a finance printer. The location affects who needs to be told and whether the area needs further review.
Staff should not search for an owner by inserting the device, browsing its label online or asking colleagues to test it. They should record the location, time and visible description.
Expected outcome: The first report includes enough location detail to support a response.
Common mistake: Passing the device around so several people can inspect it.
Step 3: Isolate without improvising
If the local policy allows safe handling, place the device in a labelled envelope or designated secure container without connecting it to anything. If a device is in a restricted area, leave it where it is if moving it could affect evidence and contact the responsible team.
The policy must name who collects devices and where they go. A vague instruction to “give it to IT” fails when the device is found outside business hours.
Expected outcome: Staff know the collection point and responsible contact.
Common mistake: Keeping the device in a desk drawer until someone remembers to mention it.
Step 4: Use the two-minute report
The report needs four fields: what was found, exact location, time discovered and whether anyone connected it. Add a photo only if policy allows and it does not require moving the device.
Make the report route visible in reception, meeting rooms and shared spaces. Cyber Aware security awareness training should teach that an early report is useful even when the device turns out to be a colleague’s harmless drive.
Expected outcome: A report reaches security or IT within 2 minutes.
Common mistake: Waiting to report until an owner is identified.
Step 5: Cover personal and supplier devices
Staff often assume that a USB drive from a trusted supplier, home office or event is safe. It still requires the approved process, especially if it will connect to a business system.
Set a practical alternative: use approved file-sharing services or arrange for IT to scan and transfer necessary content through a controlled process. In 2026, convenience is not a reason to bypass removable-media controls.
Expected outcome: Staff know there is a secure route for legitimate file transfer.
Common mistake: Using a personal USB drive to move a file because the network is slow.
Step 6: Rehearse a realistic scenario
Place a labelled training prop near a printer or meeting room. Ask staff to choose between plugging it in, moving it without reporting, or using the approved report-and-isolate process. Debrief the choice in 5 minutes.
Use phishing simulations to connect the physical scenario to digital social engineering. A suspicious email attachment and a found USB drive use the same pressure point: curiosity before verification.
Expected outcome: Staff choose the correct action under ordinary workplace conditions.
Common mistake: Making the prop obviously fake, which removes the judgement call.
Step 7: Follow up on patterns, not blame
Review whether devices are found repeatedly in the same site, area or supplier process. A cluster may indicate a physical-security gap or a need for clearer disposal procedures.
Use human risk reporting to identify training follow-up based on observed behaviour and report completion. Cyber Aware security awareness training should treat staff reports as a positive outcome.
Expected outcome: The organisation learns from reports and improves the physical environment.
Common mistake: Naming or shaming people who report a device late.
Troubleshooting
Someone already connected the USB device
Disconnect it only if instructed by the incident process, stop using the computer and report immediately. Include the device, time and actions taken.
The device has a company logo
Treat it as untrusted until the approved owner or IT process confirms it. A logo does not establish safety.
The device is found in a restricted area
Follow site security instructions and report the exact location. Do not move it if the local process requires evidence preservation.
A supplier needs to transfer files by USB
Use the approved controlled process or a secure file-sharing method. Do not make an exception at the desk.
Tools and resources
- A visible “do not plug it in” removable-media rule.
- A secure collection point and after-hours contact.
- A two-minute report template with location, time and connection status.
- Cyber security gap assessment to check whether removable-media controls, staff training and response evidence are covered together.
What to do next
Run a 10-minute found-USB drill at one office or client site this quarter, then test whether staff can name the report route without looking it up. Use the result to improve signage and the next Cyber Aware refresher.
FAQ
What should staff do when they find an unknown USB device?
Staff should not plug it in. They should follow the approved isolate-and-report process, recording the exact location and time it was found.
Can staff check a USB device on an old computer?
No. An old or offline computer still creates malware and evidence-handling risk. Only an approved controlled process should examine the device.
Is a USB drive with a company logo safe?
No. A company logo does not prove ownership or safety. Handle it through the same report-and-isolate process as any unknown device.
What if someone already plugged in the USB device?
They should stop using the computer and report immediately through the incident process. Include the device, time and actions taken so the team can respond quickly.
How should suppliers transfer files safely?
Use an approved secure file-sharing service or IT-controlled transfer process. Do not bypass removable-media controls for convenience.
How often should USB-device training run?
Run a short physical scenario at least annually and include the rule in induction training. Repeat it after a found-device event or policy change in 2026.
One last thing
The best response to a found USB device is deliberately uneventful: do not connect it, document it and pass it to the right team. That restraint prevents the incident from becoming a technical crisis.