Skip to content
Follow Us:
Call or Text 239-513-1960
▣ JOIN REMOTE SESSION →

Phishing Awareness Training for Employees (Free Training Kit)

This ten-minute phishing awareness training for employees of small businesses is provided by Naples Computers for our clients. It covers what phishing is and why businesses are targeted, the 7 warning signs, the attacks we see most at businesses in Southwest Florida, the Stop-Look-Report rule, how to report phishing in Outlook, what to do if you clicked, and five Phish-or-Legit practice examples. All examples are fictional. A printable quiz, answer key, certificate of completion and desk poster are included.

What is phishing?

A message that pretends to be someone you trust, to get you to click, pay, or share.

Email — Fake invoices, password alerts, shared files, messages from “the boss”.
Text messages — Called “smishing”: urgent texts with links or requests.
Phone calls — Called “vishing”: callers posing as I.T., the bank, or a vendor.

Why your business is a target

  • Phishing is the #1 reported cybercrime — FBI Internet Crime Report, 2025
  • Business email scams cost about $3 billion — Reported losses in 2025 alone
  • Attackers target people, not just computers — One convincing message can get past the best filters
  • You are the last line of defense — Pausing for five seconds stops most attacks

The 7 warning signs

  • Look-alike sender — yourcornpany.com is not yourcompany.com
  • Urgency or threats — “Within 24 hours or else”
  • Generic greeting — “Hello Customer”, “Dear user”
  • Links that don’t match — Hover first: where does it really go?
  • Unexpected attachments — Especially .html, .zip, or “enable content”
  • Requests for logins or money — Passwords, codes, gift cards, wires
  • Mistakes & odd details — Typos, strange formatting, wrong logos

Phishing awareness training for employees: business attacks and practice examples

1The “boss” or a vendor asks for money

A message that looks like your CEO, owner or a regular vendor asks for a wire transfer, gift cards or a quick payment, often saying they can’t talk right now.

WHAT TO DOVerify every payment request by phone, using a number you already know. Never the number in the message.

Phishing awareness training for employees: The “boss” or a vendor asks for money

2Fake invoices and “new bank details”

A real-looking invoice, sometimes from a vendor’s hacked email, says their bank account has changed.

WHAT TO DOAny change to payment details gets a phone call to the vendor, and a second person’s approval.

Fake invoices and “new bank details”

3Fake Microsoft 365 and email sign-in pages

A link opens a page that looks exactly like your email sign-in page. Anything you type goes to the attacker.

WHAT TO DOCheck the web address before you sign in. When in doubt, close it and go to the site yourself.

Fake Microsoft 365 and email sign-in pages

4“Someone shared a document with you”

Tempting file names like bonuses, payroll or a voicemail, with a link that asks you to sign in.

WHAT TO DONot expecting it? Ask the sender, by phone or chat, before you open it.

“Someone shared a document with you”

5QR codes that hide the link

A QR code in an email or on a sticker sends you to a fake page on your phone, where it’s harder to check the address.

WHAT TO DODon’t scan QR codes in emails you weren’t expecting. Check the address before entering anything.

QR codes that hide the link

6Texts and calls from “I.T.” or “the bank”

Caller ID and text names can be faked. Real I.T. and banks won’t ask for your password or a sign-in code.

WHAT TO DOHang up and call back on a number you know. Never read a code to anyone.

Texts and calls from “I.T.” or “the bank”

Outlook

!In Outlook: Report → Report phishing

Select the message, then on the Home tab click Report and choose Report phishing.

WHAT TO DOConfirm with Report. The message is sent to your security team and moved to Deleted Items.

In Outlook: Report → Report phishing

7A fake password warning

The sender is yourcompany-mailbox.com, not yourcompany.com. It’s urgent, and the button leads to a look-alike sign-in page.

WHAT TO DOReport it. Your real I.T. team won’t ask you to “keep your password” through a link.

A fake password warning

8The “boss” texting from an unknown number

Unknown number, can’t talk, urgent and secret, and it’s about money. That’s a classic business email compromise, by text.

WHAT TO DODon’t reply. Contact the owner using the number you already have, and tell I.T.

The “boss” texting from an unknown number

9An expected email from a coworker

It’s from your company’s real domain, it mentions a meeting you know about, and it doesn’t ask for money, passwords or urgency.

WHAT TO DOLegit. Still, if an attachment ever asks you to “enable content” or sign in, stop and check.

An expected email from a coworker

10A tempting shared file

A juicy file name, an outside “document share” address, a link to an unfamiliar site that wants your work sign-in, and a deadline.

WHAT TO DOCheck with the person who supposedly shared it, by phone or chat. Then report it.

A tempting shared file

11A code you just asked for

You just signed in, the code arrived right away, and it tells you not to share it. That’s how real sign-in codes work.

WHAT TO DODidn’t just sign in? Someone may have your password. Don’t share the code, change your password, and tell I.T.

A code you just asked for

The rule: Stop. Look. Report.

  • STOP — Feeling rushed, scared or curious? That’s the trap. Pause.
  • LOOK — Sender, links, attachments, the request itself.
  • REPORT — Use the Report button, or tell I.T. Don’t just delete it.

No Report button? Tell I.T.

  • Tell your I.T. contact or manager right away — A quick call or chat message is perfect
  • Don’t forward it around the office — Asking coworkers “is this real?” spreads the bad link
  • Don’t reply, click, or call numbers in it — Even to say “stop”
  • Delete it once it’s been reported — Your I.T. team may ask for it first

Clicked? Speak up, fast.

  • Tell I.T. immediately — Minutes matter. Nobody is in trouble for reporting.
  • Something downloaded or opened? — Disconnect from the network: unplug the cable or turn off Wi-Fi
  • Typed your password? — Change it right away, from a different device if you can
  • Unexpected sign-in prompts or codes? — Deny them, and never share a code

Recap: how to phishing awareness training for employees

  • Check the real sender address
  • Urgency and secrecy are red flags
  • Hover before you click; check the address
  • Verify money requests by phone
  • Never share passwords or codes
  • Report it; clicked? Tell I.T. fast

Free employee training kit

Use the video in a staff meeting, then hand out the quiz. Employees who score 8 out of 10 or better get a certificate of completion. Print the poster for break rooms and desks.

Printable quick guide

Frequently asked questions

How often should you run phishing awareness training for employees?

A common approach is to train every new hire when they start, run a full refresher for everyone at least once a year, and share short reminders when a new scam starts going around. The printable quiz and certificate make it easy to track who has completed it.

What should an employee do after clicking a phishing link?

Tell I.T. immediately: minutes matter, and nobody is in trouble for reporting. If something downloaded, disconnect from the network. If they typed a password, change it right away, from a different device if possible, and deny any unexpected sign-in prompts.

How do you report phishing in Outlook?

Select the message, then on the Home tab click Report and choose Report phishing. The Report button is in new Outlook, Outlook on the web and the mobile app; classic Outlook uses an add-in. No Report button? Tell your I.T. contact or manager right away.

Why are small businesses targeted by phishing?

Attackers target people, not just computers, and one convincing message can get past the best filters. Phishing was the most-reported cybercrime in the FBI’s 2025 Internet Crime Report, and reported business email compromise losses were about $3 billion.

Related guides

Source: How do I report phishing or junk email? (Microsoft Support)

Stop. Look. Report. When a message makes you feel rushed, scared or curious, pause, check the sender and links, and report it. Clicked something? Tell I.T. right away: reporting fast is never a mistake.

Still need help?

Our technicians are right here in Naples — give us a call and we’ll walk you through it or fix it for you.

Call (239) 513-1960
🔧

Need On-Site Help?

We come to you anywhere in Naples, Bonita Springs, Estero & Marco Island.

Schedule a Visit