This ten-minute phishing awareness training for employees of small businesses is provided by Naples Computers for our clients. It covers what phishing is and why businesses are targeted, the 7 warning signs, the attacks we see most at businesses in Southwest Florida, the Stop-Look-Report rule, how to report phishing in Outlook, what to do if you clicked, and five Phish-or-Legit practice examples. All examples are fictional. A printable quiz, answer key, certificate of completion and desk poster are included.
What is phishing?
A message that pretends to be someone you trust, to get you to click, pay, or share.
Why your business is a target
- Phishing is the #1 reported cybercrime — FBI Internet Crime Report, 2025
- Business email scams cost about $3 billion — Reported losses in 2025 alone
- Attackers target people, not just computers — One convincing message can get past the best filters
- You are the last line of defense — Pausing for five seconds stops most attacks
The 7 warning signs
- Look-alike sender — yourcornpany.com is not yourcompany.com
- Urgency or threats — “Within 24 hours or else”
- Generic greeting — “Hello Customer”, “Dear user”
- Links that don’t match — Hover first: where does it really go?
- Unexpected attachments — Especially .html, .zip, or “enable content”
- Requests for logins or money — Passwords, codes, gift cards, wires
- Mistakes & odd details — Typos, strange formatting, wrong logos
Phishing awareness training for employees: business attacks and practice examples
1The “boss” or a vendor asks for money
A message that looks like your CEO, owner or a regular vendor asks for a wire transfer, gift cards or a quick payment, often saying they can’t talk right now.

2Fake invoices and “new bank details”
A real-looking invoice, sometimes from a vendor’s hacked email, says their bank account has changed.

3Fake Microsoft 365 and email sign-in pages
A link opens a page that looks exactly like your email sign-in page. Anything you type goes to the attacker.

4“Someone shared a document with you”
Tempting file names like bonuses, payroll or a voicemail, with a link that asks you to sign in.

5QR codes that hide the link
A QR code in an email or on a sticker sends you to a fake page on your phone, where it’s harder to check the address.

6Texts and calls from “I.T.” or “the bank”
Caller ID and text names can be faked. Real I.T. and banks won’t ask for your password or a sign-in code.

!In Outlook: Report → Report phishing
Select the message, then on the Home tab click Report and choose Report phishing.

7A fake password warning
The sender is yourcompany-mailbox.com, not yourcompany.com. It’s urgent, and the button leads to a look-alike sign-in page.

8The “boss” texting from an unknown number
Unknown number, can’t talk, urgent and secret, and it’s about money. That’s a classic business email compromise, by text.

9An expected email from a coworker
It’s from your company’s real domain, it mentions a meeting you know about, and it doesn’t ask for money, passwords or urgency.

10A tempting shared file
A juicy file name, an outside “document share” address, a link to an unfamiliar site that wants your work sign-in, and a deadline.

11A code you just asked for
You just signed in, the code arrived right away, and it tells you not to share it. That’s how real sign-in codes work.

The rule: Stop. Look. Report.
- STOP — Feeling rushed, scared or curious? That’s the trap. Pause.
- LOOK — Sender, links, attachments, the request itself.
- REPORT — Use the Report button, or tell I.T. Don’t just delete it.
No Report button? Tell I.T.
- Tell your I.T. contact or manager right away — A quick call or chat message is perfect
- Don’t forward it around the office — Asking coworkers “is this real?” spreads the bad link
- Don’t reply, click, or call numbers in it — Even to say “stop”
- Delete it once it’s been reported — Your I.T. team may ask for it first
Clicked? Speak up, fast.
- Tell I.T. immediately — Minutes matter. Nobody is in trouble for reporting.
- Something downloaded or opened? — Disconnect from the network: unplug the cable or turn off Wi-Fi
- Typed your password? — Change it right away, from a different device if you can
- Unexpected sign-in prompts or codes? — Deny them, and never share a code
Recap: how to phishing awareness training for employees
- Check the real sender address
- Urgency and secrecy are red flags
- Hover before you click; check the address
- Verify money requests by phone
- Never share passwords or codes
- Report it; clicked? Tell I.T. fast
Free employee training kit
Use the video in a staff meeting, then hand out the quiz. Employees who score 8 out of 10 or better get a certificate of completion. Print the poster for break rooms and desks.
Printable quick guide
Frequently asked questions
How often should you run phishing awareness training for employees?
A common approach is to train every new hire when they start, run a full refresher for everyone at least once a year, and share short reminders when a new scam starts going around. The printable quiz and certificate make it easy to track who has completed it.
What should an employee do after clicking a phishing link?
Tell I.T. immediately: minutes matter, and nobody is in trouble for reporting. If something downloaded, disconnect from the network. If they typed a password, change it right away, from a different device if possible, and deny any unexpected sign-in prompts.
How do you report phishing in Outlook?
Select the message, then on the Home tab click Report and choose Report phishing. The Report button is in new Outlook, Outlook on the web and the mobile app; classic Outlook uses an add-in. No Report button? Tell your I.T. contact or manager right away.
Why are small businesses targeted by phishing?
Attackers target people, not just computers, and one convincing message can get past the best filters. Phishing was the most-reported cybercrime in the FBI’s 2025 Internet Crime Report, and reported business email compromise losses were about $3 billion.
Related guides
- How to spot a phishing email: 7 warning signs
- How to turn on two-factor authentication
- Managed I.T. services for businesses
Source: How do I report phishing or junk email? (Microsoft Support)
