Working in China
Work Device and Account Security in China: An Employee Checklist
A practical security checklist for foreign employees in China covering company devices, accounts, approved apps, travel, phishing, incident reporting, backups, and handover.
Rules and procedures can change. Check the linked official sources before acting on time-sensitive information.
Quick answer
What you need to know
Use employer-approved devices, apps, networks, storage, and reporting channels; separate work from personal data and report suspicious activity quickly without attempting an improvised investigation.
- Follow written employer security and data-handling rules, including approved software and services.
- Use unique credentials, multifactor authentication, updates, screen locks, and approved backups.
- Verify unusual payment, password, file-sharing, or login requests through a second channel.
- Report a lost device or suspected compromise immediately and preserve facts for the response team.
Foreign employees often combine company systems, Chinese mobile services, business travel, and personal devices. Security works best when the boring decisions—approved apps, backups, access, and reporting—are settled before an incident.
Learn the employer’s operating rules
Find the written policies for device enrollment, software installation, messaging, file sharing, removable media, printing, remote work, travel, retention, and incident reporting. Ask which IT and security contacts are genuine and how they identify themselves.
Use only employer-approved tools for work data. Availability does not equal authorization. Cross-border access, personal information, industry data, encryption, and remote connectivity can involve legal and contractual requirements; ask the employer’s IT, security, privacy, or legal team rather than configuring a workaround yourself.
Harden daily access
Use a unique password or passphrase for each work account and enable the employer’s approved multifactor method. Install managed updates, keep automatic screen locking on, and avoid sharing accounts. Never approve an unexpected login prompt.
Separate personal photos, chats, email, and cloud storage from work information. Back up work only to approved destinations. When working away from the office, control sightlines, keep devices with you, and confirm the allowed network or hotspot method. The remote and hybrid work guide covers the broader workspace checklist.
Slow down social engineering
Treat unexpected urgency, secrecy, payment changes, QR codes, attachments, password resets, and requests for employee or customer data as verification triggers. Contact the person through a separately established number or internal directory. A familiar profile photo or chat history is not sufficient proof.
For finance or reimbursement tasks, follow documented approval steps and compare requests with the work expense reimbursement guide.
Respond without erasing evidence
If a device is lost, an account behaves unexpectedly, or sensitive information may have been sent to the wrong place, report it immediately through the official channel. Note the time, device, account, network, message, and actions already taken. Follow the response team’s instructions for locking, disconnecting, password changes, or police and regulatory reporting.
Do not delete messages, factory-reset equipment, confront a suspected attacker, or run unapproved cleanup tools unless the response lead instructs you.
Security checklist
- Save official IT, security, privacy, and emergency reporting contacts.
- Use approved devices, software, networks, storage, and backups.
- Enable unique credentials, multifactor authentication, locks, and updates.
- Verify unusual requests through a second trusted channel.
- Limit work data on personal devices and personal data on work devices.
- Prepare extra controls before business travel or remote work.
- Report loss, phishing, misdelivery, or abnormal access immediately.
- During exit, return assets and complete formal account and data handover.
Official reference points
Cybersecurity, privacy, employment, and sector rules vary. Follow your employer’s current policies and consult its IT, security, legal, or privacy professionals for regulated data and incident decisions.
Frequently asked questions
Common questions
Can I use personal cloud storage for work files in China?
Only if your employer explicitly approves it for the relevant data. Use the organization's authorized storage and sharing tools and follow classification and retention rules.
What should I do if my work phone or laptop is lost?
Contact the employer's security or IT channel immediately, provide factual time and location details, and follow instructions for locking, account protection, reporting, or replacement.
How should I handle a suspicious request from a manager?
Pause and verify through a separately established channel, especially for payments, credentials, sensitive files, gift cards, QR codes, or urgent secrecy. Report the attempt under company policy.
May I install a VPN or security tool myself?
Do not improvise. Use only employer-approved and lawfully provided tools and ask IT or legal teams about current requirements and permitted configurations.