Phishing is a fake email or text designed to trick someone into handing over information or installing malware. One successful attempt can lead to a compromised account, financial loss, or a data breach. Training for it doesn't need to take hours.
A 30-minute session, in five parts
- Why it matters (5 min): how one click can affect the whole company.
- Real examples (5 min): show a handful of realistic phishing emails, fake invoices, missed-delivery notices, fake HR updates.
- How to check a link and a sender (10 min): the practical part below.
- What to do if you click (5 min): the exact steps.
- Quick quiz (5 min): to check it landed.
What to teach people to notice
- Urgency: "act now or your account will be suspended."
- Unexpected attachments from an unfamiliar sender or out of context.
- Any request for a password, an MFA code, or a payment.
- A sender address that's slightly off, like
support@micros0ft.cominstead of the real domain.
How to check a link and a sender
Hover over a link without clicking it. The real destination shows up, and if it doesn't match what the message says, don't click.
If a message asks for a payment or a change to banking details, verify it a different way: call the sender on a number you already have on file, not one from the message itself.
Make reporting easy, and blame-free
One email address or one button for reporting suspicious messages. Make clear the goal is stopping the threat, not punishing whoever clicked.
If someone does click a bad link or open a bad attachment:
- Disconnect the device from the internet if you can.
- Tell IT or the security contact immediately.
- Change the password on that account and any other account sharing it.
Keep it going after the session
One session rarely changes habits on its own.
- A short monthly reminder on one phishing tactic.
- Occasional safe, simulated phishing tests, with a friendly follow-up for anyone who clicks, not a penalty.
- Multi-factor authentication (a second check beyond the password) on every account, so a stolen password alone isn't enough to get in.
A simple, no-blame reporting process plus MFA on every account covers most of the damage a stolen password could otherwise do.


