I Know Victoria’s Secret: It’s An Acceptable Use Policy (Business Only Surfing)


When it comes to cybersecurity in the workplace, implementing an Acceptable Use Policy (AUP) that limits internet access to business-related sites is often seen as a somewhat unimportant step. And while a policy isn’t a technical control nor will it stop everyone, it serves as a deterrent. A frequent question we hear from new clients highlights this: “Why can’t we access certain sites whether those are sports websites, news sites, or even shopping sites like Victoria's Secret?” Although these requests can be amusing, they arise often during the onboarding of new businesses—especially if no clear policy has been communicated to employees.

One memorable interaction that always brings a chuckle happened years ago, before ransomware became prevalent. Back then, clients who were lax about cybersecurity usually dealt with minor threats like quasi-spyware or non-destructive malware, often resulting in extra browser toolbars. One client wanted to implement a strict “allow-only” domain list, but management was unsure which sites to permit for "business use." So, they asked employees for suggestions. The responses were priceless: suggestions included sites like Babies R Us, internet radio stations, their children's school websites, and, of course, Victoria's Secret. 

Originally, content filtering on business networks was designed to keep employees focused and reduce distractions. However, this reasoning always seemed a bit shallow—just because someone spends a few minutes on a shopping site doesn’t mean they aren’t productive. Over time, though, the reasoning behind this policy evolved as malicious website activity became more common.

That same client above was a little ahead of the curve. They wanted domain restrictions simply because we recommended it as a solution to prevent them from paying for numerous spyware cleanups every month. Thus, not to micromanage or increase productivity, but to help the bottom line. 

The Real Risk: Hacked and Malicious Websites

The internet is filled with seemingly innocent websites that can harbor malicious code, leaving a business vulnerable. Employees might think visiting a harmless site like an online store or a news page has no downside, but even trusted websites can (and have) become compromised leading to malware, phishing attacks, or even ransomware. In nearly all cases, employees don't even realize they've exposed the company to a threat.

A Business-Only Internet Policy for Security

Implementing an AUP focused on business-only browsing can significantly reduce the risk of cyberattacks. By restricting internet access to approved, business-related websites, you lower the likelihood of an employee unintentionally introducing malware, spyware, or ransomware into the network.

In today's world of advanced threats like ransomware and phishing, it's no longer just about keeping employees "on-task." It's about protecting the organization's overall security, and integrity, and keeping their name out of the headlines. When faced with the consequences of compromised data, suddenly that request for access to Victoria’s Secret doesn’t seem as funny anymore.

Ultimately, fostering a workplace culture that understands and adheres to an Acceptable Use Policy not only protects the business but also encourages employees to be part of the solution rather than contributing to potential vulnerabilities. Clear policies and strong communication are essential to keeping everyone aligned with the ultimate goal—maintaining a safe and secure work environment.