Signs to watch for
- Urgency or threats — “your account will be closed in 24 hours”
- A sender address that doesn’t match the real company
- Links that don’t go where they claim (hover to check first)
- Unexpected attachments, especially .zip or .html files
- Requests to “verify” passwords, payments or bank details
The golden rule
If a message pressures you to act fast, slow down. Real organisations don’t rush you into handing over credentials or moving money.
What to do instead
- Don’t click — open the company’s site yourself in a new tab
- Confirm unusual payment requests by phone using a known number
- Report suspicious email to your IT provider and delete it
We run simple phishing-awareness sessions and set up email filtering and MFA so a single wrong click doesn’t become a breach.