Training

🎣 Phishing & Social Engineering

What to teach staff about recognizing and reporting phishing attempts.

Talking points
  • Slow down before clicking. Urgency ("act now or your account will be locked") is the #1 phishing tactic — legitimate organizations rarely demand instant action.
  • Check the sender's actual email address, not just the display name — attackers spoof names like "IT Support" from addresses that don't match your organization's domain.
  • Hover over links before clicking to see where they actually go. If the link text says one thing but the URL underneath is different, that's a red flag.
  • Be extra suspicious of requests to change payment details, wire money, or buy gift cards — verify these by phone, using a number you already have, not one in the email.
  • It's okay — expected, even — to verify a request is real by contacting the sender through a separate channel, even if it feels awkward.
  • Report suspicious emails immediately rather than just deleting them, so others can be warned if it's a targeted campaign.
Developed and supported by iConsulting — a working vCISO practice.Contact us for vCISO services →