🎣 Phishing & Social Engineering
What to teach staff about recognizing and reporting phishing attempts.
Talking points
- Slow down before clicking. Urgency ("act now or your account will be locked") is the #1 phishing tactic — legitimate organizations rarely demand instant action.
- Check the sender's actual email address, not just the display name — attackers spoof names like "IT Support" from addresses that don't match your organization's domain.
- Hover over links before clicking to see where they actually go. If the link text says one thing but the URL underneath is different, that's a red flag.
- Be extra suspicious of requests to change payment details, wire money, or buy gift cards — verify these by phone, using a number you already have, not one in the email.
- It's okay — expected, even — to verify a request is real by contacting the sender through a separate channel, even if it feels awkward.
- Report suspicious emails immediately rather than just deleting them, so others can be warned if it's a targeted campaign.