Security Awareness Training
1 / 6
Slide 1 Β· Welcome

Welcome to the Team!
Let's Catch Some Phish 🎣

Cyber Sally Your IT Guide

Hey there, and welcome aboard! I'm Sally β€” think of me as the friendly voice in your ear whenever something online feels a little "off."

Here's the thing nobody tells new hires on day one: our biggest defense against scammers isn't a fancy firewall or some piece of software humming away in a server room. It's you. Every single email you open is a decision point, and in the next few minutes I'll show you exactly what to look for.

⏱️ 5 minute read 🎯 6 short slides 🐟 Zero technical jargon
Slide 2 Β· The Basics

So, what exactly is "phishing"?

Cyber Sally

Phishing is just a fancy word for a very old trick: a scammer pretends to be someone you trust β€” your boss, HR, IT, even a delivery company β€” to convince you to hand over something valuable. Usually that's your password, or your money.

It's called "phishing" because they're dangling bait and hoping someone bites. They don't need everyone to fall for it β€” they just need one person, one time, to click.

🎣 Meet the bait

Scammers borrow a trusted name β€” a coworker, a bank, a well-known brand β€” because you're far more likely to act quickly for someone you recognize.

VS

πŸ¦Ήβ€β™‚οΈ Meet "Phishing Pete"

Say hi to Pete β€” our stand-in for every scammer out there. His one and only goal: get you to type your username and password into a fake page he controls.

Slide 3 Β· Spot the Signs

The 4 Big Red Flags 🚩

You don't need to be technical to catch a phishing attempt. You just need to recognize these four behavioral tricks β€” they show up again and again.

1

Unexpected urgency

Scammers want you moving faster than you think. Panic skips the "wait, does this seem right?" step.

"Act NOW or your account will be deleted!"
2

The "too good to be true" offer

A surprise bonus, a free gift card, an unexpected prize β€” offers designed to make you click before you think.

"You've been selected for a $500 reward!"
3

Mismatched sender

The display name says one thing, but the actual address behind it tells a different story entirely.

"HR Team" <hr-update@gmail.com>
4

Spelling & grammar slips

Real corporate emails go through review. Odd phrasing, typos, or clumsy grammar in an "official" message is a big tell.

"Kindly to confirm you're account informations"
Slide 4 Β· Scenario 1

The Fake Boss (a "Spear Phishing" Trick)

This one targets you specifically, using a name you'd never question β€” the CEO.

Cyber Sally jumps in

Freeze β€” a real CEO is never going to ask a brand-new hire to secretly buy gift cards over email. Think about it: no company reimburses employees with Target gift cards.

Notice the tricks stacked together: urgency ("20 minutes"), secrecy ("keep this between us"), and a sender name that sounds official. That combo is a classic spear-phishing setup β€” it's aimed at you personally, using a name you'd never question.

What to do: stop, and verify through a separate channel β€” call or message the person directly using a number or handle you already know. Never reply to the suspicious email itself.

Slide 5 Β· Scenario 2

The Fake IT Alert

This one plays on habit β€” nobody wants to lose access to their own account.

Phishing Pete tempts you

"Come on, just one click! It's your own password, what's the harm? You've got two hours β€” better hurry before IT locks you out..."

Cyber Sally interrupts

Not so fast, Pete. First red flag: "keep your same password" makes no real sense β€” that's not how password resets work, and that's exactly why it sounds oddly reassuring.

Here's your best trick: hover your mouse over a link without clicking and look at where it actually leads (it usually shows up in the corner of your screen, or in a tooltip like the one above). If the address looks strange, unrelated to our company, or oddly spelled β€” that's your answer. Don't click it.

Slide 6 Β· Your Move

Okay, I'm suspicious. What do I actually do?

βœ•

DON'T click links or download attachments. Even "just looking" can trigger something. If it's suspicious, leave it alone.

βœ•

DON'T reply β€” not even to say "stop emailing me" or "unsubscribe." Replying just confirms your address is active and being read.

βœ“

DO use the "Report Phishing" button in your email client. It takes two seconds, alerts our security team instantly, and helps protect everyone else on your team too.

You made it β€” nice work! πŸŽ‰

You now know more about phishing than most of the internet. Stay curious, stay a little suspicious, and remember: it's always okay to pause and ask before you click. Go get 'em! β€” Cyber Sally πŸ’›