Practical cybersecurity training

Small actions.
Stronger defenses.

Build the everyday habits that protect you, your colleagues, and your organization—one clear, practical lesson at a time.

15 min focused lesson5 quiz questions0 technical knowledge needed

Your learning path

Four modules. One resilient mindset.

Start with the threats most likely to reach your inbox, then build the habits that protect every part of your digital workday.

01

Phishing Attempts

Recognize, resist, and report deceptive messages.

Available now
02

Protecting Your Credentials

Create stronger access habits and keep accounts secure.

Next module
03

Digital Devices

Use laptops, phones, and shared devices safely.

Learning path
04

Information Security

Handle, share, and store sensitive information with care.

Learning path

Module 01

Phishing attempts

Blocking external threats

Phishing is a deceptive message designed to make you click, share information, or take an action that benefits an attacker.

THE CORE HABITPause. Inspect. Verify. Report.

Look past the polish.

A phishing email can look professional, use a familiar logo, and even include your name. Its real goal is to trigger a fast reaction before you notice what is wrong.

● ● ●Inbox / Message
P
Payroll Departmentpayroll@riskaxis-benefits.com

Action required: Updated benefits payment

Hello Jordan, we were unable to process your benefits enrollment. Please review the attached form and sign in with your work account before 12:00 PM.

Thank you,
Payroll Services

1Unfamiliar domainThe display name says Payroll, but the domain is not your company’s.
2Artificial deadlineA short deadline pushes you to act before checking.
3Unexpected sign-inBenefits teams should not request credentials through an email link.

One clue may be harmless.
Several clues demand a pause.

01

Urgency or fear

“Act now,” “final warning,” or threats of account closure.

02

A surprising request

Passwords, gift cards, payments, files, or confidential information.

03

Sender mismatch

A familiar name paired with a misspelled or unrelated email domain.

04

Unusual language

Generic greeting, odd phrasing, or a tone that does not fit the sender.

05

Hidden destination

Link text looks safe, but hovering reveals a different website.

06

Unexpected attachment

An invoice, QR code, shared file, or document you were not expecting.

SAFER MOVE

Open the service yourself

Use a saved bookmark, company portal, or known app instead of the message link.

VERIFY

Use a separate channel

Call a known number or start a new message. Do not use contact details provided in the suspicious email.

STOP

Never share a code

A legitimate support person should never ask for your password or multi-factor authentication code.

Reporting protects everyone

Speed matters more than certainty.

You do not need to prove that a message is malicious. Report anything suspicious so the right team can investigate and warn others.

  1. 01

    Stop interacting

    Do not click again, reply, download, forward, or delete the message.

  2. 02

    Use the approved reporting method

    Select your email client’s “Report phishing” button or contact your IT/security team through the company’s known channel.

  3. 03

    Share what happened

    If you clicked, downloaded, replied, or entered information, say so clearly. Honest details help responders act quickly.

IF YOU ALREADY CLICKED

Disconnect only if your organization instructs you to. Contact security immediately, keep the message, and follow their password or device guidance.

Module summary

Your four-step phishing defense

01

Pause

Resist urgency. Take a breath before acting.

02

Inspect

Check the sender, request, link, and context.

03

Verify

Use a separate, trusted route to confirm.

04

Report

Send it to the right team—even if unsure.

Knowledge check

Put your instincts to work.

Choose the safest response. You’ll see an explanation after every answer.

QUESTION 1 OF 5

An email says your Microsoft 365 password expires in one hour. What should you do first?