Welcome to [Company Name]'s Security Training
Hello Team! Technology helps us do our jobs, but it also comes with risks. Criminals on the internet want to steal our company's data and money. They don't usually try to "hack" our computers directly—instead, they try to trick you into letting them in.
You are our strongest defense. Please read this short guide to learn the three main ways you can help keep [Company Name] safe.
1. How to Spot a Fake Email (Phishing)
"Phishing" is when a hacker sends you an email pretending to be someone you trust, like your boss, your bank, or IT support. They want you to click a bad link or open a virus.
Look for these warning signs:
- It is urgent or scary: Hackers use fear to make you hurry. If an email says "Your account will be deleted in 24 hours!" or "Immediate payment required," stop and take a breath.
- Check the sender's address carefully: The name might say "Microsoft Support", but the actual email address might be "support@micro-soft-help-123.com". Always look at the real address.
- Hover before you click: If there is a link, use your mouse to hover over it without clicking. A small box will pop up showing the real website destination. If it looks strange, do not click it.
- Unexpected attachments: Never open an attachment you weren't expecting, especially if it ends in ".exe", ".zip", or even a strange Microsoft Word file.
2. Keep Your Passwords Safe
Your password is the key to our company's front door. If a hacker gets your password, they can read your emails and steal our files.
- Make it long: A long password is much harder for a computer to guess. Use at least 12 characters. A "passphrase" made of multiple words (like "BlueHorseRunsFast!") is very strong.
- Never share it: Do not tell anyone your password. [Company Name]'s IT team will never ask you for your password. If someone asks for it, it is a trick.
- Don't reuse passwords: Do not use the same password for your work email that you use for your personal Netflix or Facebook account. If one gets hacked, they all get hacked.
- Use Multi-Factor Authentication (MFA): When you log in, you will be asked to approve it on your phone. This is annoying, but it is extremely important! It means even if a hacker guesses your password, they still cannot get in without your physical phone.
3. Be Careful with Physical Security
Not all hackers use the internet. Some use the real world.
- Lock your screen: Whenever you walk away from your desk, even just to get coffee, lock your computer screen (Press Windows Key + L, or Command + Control + Q on a Mac).
- Don't plug in random USB drives: If you find a USB thumb drive in the parking lot or the lobby, do not plug it into your computer. It might be a trap loaded with a virus. Give it to the IT team.
- Beware of tailgating: If someone you don't know tries to follow you through a locked door into the office, politely ask them to use the front desk. Do not hold the door for strangers.
What to do if you make a mistake
We are all human. If you click a bad link, or type your password into a fake website, do not hide it.
Tell the IT team immediately by [calling this phone number / emailing this address / clicking the Report button]. You will not get in trouble for making a mistake and reporting it quickly. You will save the company from a lot of damage!
Thank you for doing your part to keep [Company Name] safe.