Phishing remains one of the most common ways attackers get a foothold in an organization. The good news: most phishing emails share tell-tale signs. Train your team to run this 30-second check before clicking anything.
1. Check the real sender
Look past the display name at the actual email address. Attackers use look-alike domains such as acme-secure-login.co instead of acme.com, or swap letters that look similar.
2. Notice the pressure
Urgency is a manipulation tactic. Phrases like 'your account will be locked in 2 hours' or 'the CEO needs this now' are designed to make you act before you think.
3. Hover before you click
On desktop, hover over links to see the real destination. On mobile, long-press. If the link text and destination don't match, don't click.
4. Be wary of attachments
Unexpected invoices, shipping notices or 'shared documents' are common lures, especially archives or files that ask you to enable macros or sign in to view.
5. Question the request
Requests to reset a password, change bank details, buy gift cards or share credentials should always be verified through a separate channel you trust, like a known phone number.
If you think you clicked
Don't panic, and don't hide it. Speed matters more than blame.
Report it to IT or security immediately.
Change the affected password and confirm MFA is enabled.
A security-aware culture, where people feel comfortable reporting mistakes quickly, is one of the most effective defenses an organization can build.
