Security — How to train your team to spot phishing in 30 minutes
Photo: Shixart1985, CC BY 2.0
Security

How to train your team to spot phishing in 30 minutes

Phishing is a fake email or text designed to trick someone into handing over information or installing malware. One successful attempt can lead to a compromised account, financial loss, or a data breach. Training for it doesn't need to take hours.

A 30-minute session, in five parts

  1. Why it matters (5 min): how one click can affect the whole company.
  2. Real examples (5 min): show a handful of realistic phishing emails, fake invoices, missed-delivery notices, fake HR updates.
  3. How to check a link and a sender (10 min): the practical part below.
  4. What to do if you click (5 min): the exact steps.
  5. Quick quiz (5 min): to check it landed.

What to teach people to notice

  • Urgency: "act now or your account will be suspended."
  • Unexpected attachments from an unfamiliar sender or out of context.
  • Any request for a password, an MFA code, or a payment.
  • A sender address that's slightly off, like support@micros0ft.com instead of the real domain.

How to check a link and a sender

Hover over a link without clicking it. The real destination shows up, and if it doesn't match what the message says, don't click.

If a message asks for a payment or a change to banking details, verify it a different way: call the sender on a number you already have on file, not one from the message itself.

Make reporting easy, and blame-free

One email address or one button for reporting suspicious messages. Make clear the goal is stopping the threat, not punishing whoever clicked.

If someone does click a bad link or open a bad attachment:

  • Disconnect the device from the internet if you can.
  • Tell IT or the security contact immediately.
  • Change the password on that account and any other account sharing it.

Keep it going after the session

One session rarely changes habits on its own.

  • A short monthly reminder on one phishing tactic.
  • Occasional safe, simulated phishing tests, with a friendly follow-up for anyone who clicks, not a penalty.
  • Multi-factor authentication (a second check beyond the password) on every account, so a stolen password alone isn't enough to get in.

A simple, no-blame reporting process plus MFA on every account covers most of the damage a stolen password could otherwise do.

Get started

Have a problem
nobody can solve?

Tell us what you're trying to build or automate.We'll scope it and get it shipped.