Phishing tools change every year, but the advice to users barely does. Most scams work by getting someone to act before they think. A short, plain email from IT, sent a few times a year, will do more good than a policy nobody reads. This post covers what makes a warning email work and gives you and example one to copy.
What a good warning does
A financial services company I belong to once sent its members a notice about scams. It was longer than it needed to be, but it got the important things right. These are the habits worth borrowing:
- It explains how the scam works. Phone numbers can be faked, and messages can use details about you that make them feel real. Once people understand that, they stop blaming themselves for almost being fooled.
- It says exactly what the sender will never ask for. A password, a one-time code, remote access to your device, or a request to move your money for safekeeping. A clear list gives people something concrete to check a message against.
- It gives one safe way to verify. End the conversation, then contact the organization yourself through the official app or a number you already trust. Caller ID and the sender’s name prove nothing.
- It keeps the actions few. Three or four things a person can remember are better than a page of rules.
- It reminds people they have help. A warning that only scares people teaches them to hide mistakes. One that says “come to us” teaches them to speak up.
A sample email you can send
Replace the items in brackets and send it from a real person, not a no-reply address. It is written to stay true as scam tactics change.
Subject: Spotting scam messages, and what to do if you get one
Hello everyone,
Scam messages reach every organization, ours included. Some are easy to spot. Others look very real: they can use your name, copy a logo, or seem to come from someone you know. This short note explains what to watch for and what to do.
What we will never do
- Ask for your password, a sign-in code, or an approval you didn't start.
- Ask you to give anyone remote access to your computer or phone.
- Ask you to buy gift cards, send money, or change payment details by email or text.
Warning signs
- Pressure to act right now, or a threat if you don't.
- A request that is unusual for the person or company sending it.
- A sender address that is slightly off, or a link or attachment you weren't expecting.
- A request to keep it secret or skip the normal process.
What you should do
1. Slow down. Scammers rely on urgency.
2. Don't reply, click, or call the number in the message.
3. Check it a second way. Contact the person or company using an address or phone number you already know.
4. Report it: [use the Report button in your email / forward it to phishing@yourcompany.com / call the help desk at 000-000-0000].
If you already clicked, replied, or shared a password, tell us right away at [contact]. Nobody will be in trouble. The sooner we know, the easier it is to fix.
Thank you for helping protect [Company].
[Name]
[Title]
Customize it before you send
- Only say “we will never” if it is true. If your help desk really does sometimes ask for a code or start a remote session, change the list to match what you do. People trust a rule only until the first time you break it.
- Match the reporting step to your setup. Name the one button, mailbox or phone number you actually want people to use.
- Put a human behind it. A name and a title make people more likely to reply, and more likely to speak up when they’ve made a mistake.
- Make a short version. The same message works as a few lines in a chat channel, on the intranet, or on a poster near the printer.
Make reporting easy
A warning is only half the job. People need a one-step way to report something suspicious, or they will delete it and move on. If you use Microsoft 365, the built-in Report button in Outlook can send reported messages to a mailbox you choose. Without a button, a single dedicated address works. When someone reports a message, tell them what you found, even if it was harmless. That is what makes them report the next one.
When to send it
- When someone new joins, as part of their first week.
- A few times a year, in the same words each time. Repetition is the point.
- Whenever you notice a new kind of scam reaching your users. Add one line about it rather than rewriting the whole message.
The details of phishing will keep changing. The signals, which are urgency, secrecy and unusual requests for money or credentials, change very slowly. Teach people to notice those, and give them an easy way to ask for help.