No software alone can fully protect a network. Cybercriminals know this, so they target the one thing technology cannot patch: people. Phishing emails, fake links, and social engineering tricks are designed to get you to act before you think. The good news is that a few simple habits make you one of the strongest defenses your organization has.
4 Rules Every Employee Should Follow
Hover over any link before clicking it. Does the URL match where it claims to go? Be especially suspicious of shortened URLs, unexpected attachments, and emails asking you to log in to a familiar service. When in doubt, go directly to the website by typing the address yourself instead of clicking the link.
No legitimate company, bank, or IT department will ever ask for your password or your multi-factor authentication code. If someone calls, texts, or emails asking for a code "to verify your account," that is a scam. Hang up or delete the message immediately.
Urgency is the oldest trick in the book. Phrases like "Act now or your account will be closed," "Wire this payment today," or "Your boss needs this immediately" are designed to make you skip your normal judgment. Slow down. Verify through a separate channel before taking any action.
If something looks off, say something. Report suspicious emails to your IT department or internet service provider right away. Do not forward the suspicious email to coworkers to ask their opinion, as that can spread the threat. Simply report it and delete it.
Common Warning Signs of a Phishing Email
Even well-crafted phishing emails usually have at least one giveaway. Watch for these red flags:
Mismatched sender address. The display name may say "PayPal Support" but the actual email address is something like noreply@paypal-secure-update.net. Always check the full sender address, not just the name.
Generic greetings. Legitimate companies you have an account with will use your name. "Dear Customer" or "Dear User" is a sign the message was sent in bulk to thousands of people.
Spelling and grammar errors. Many phishing emails originate overseas and contain awkward phrasing or obvious spelling mistakes.
Unexpected attachments. An invoice, shipping notice, or document you were not expecting is a common delivery method for malware. Call the sender directly to confirm before opening.
Requests to bypass normal procedures. If an email asks you to skip the usual approval process or keep something confidential from your manager, that is a major warning sign.
What to Do If You Think You Clicked Something
Do not panic, but do act quickly. Disconnect your computer from the internet immediately. Call your IT support right away and let them know what happened. The faster a potential infection is reported, the better the chances of containing it before real damage is done.
If you are a small business without in-house IT, Comp-u-Doc can help. We provide cybersecurity support and network security services for businesses throughout Rhode Island. Call us at (401) 884-4432 and we will assess the situation and get you protected.
Concerned about your business security?
We offer on-site cybersecurity support for Rhode Island small businesses.
Learn About Cybersecurity Call (401) 884-4432Related: Why You Need Unique Passwords and a Password Manager | How to Set Up MFA on Gmail Using Authy
