Case File · Phishing Awareness Security Awareness Training
Module 01 — Briefing

Spotting a phishing email before it spots you.

This short module covers the red flags used in real phishing attempts, what to do when you see one, and a walkthrough drawn from our own recent simulation. It ends with a short quiz.

30.4%
of employees clicked the link in our last Group‑wide phishing simulation
15.4%
went on to enter credentials on the fake page
2,217
employees across the Group were tested

Your name, email, business unit, and quiz score will be recorded to a shared training completion log visible to your organization's training administrator.

Module 01 · Part 1

Three signals that give phishing away.

Most phishing emails share the same three tells. Learn these and you'll catch the majority of attempts at a glance.

RED FLAG 01

Sender spoofing

The name in your inbox looks right. The address behind it often isn't.

  • Domain is misspelled or unfamiliar (vatit‑secure.net vs vatit.com)
  • Display name says "IT Support" but the address doesn't match
  • Reply‑to address differs from the sender address
RED FLAG 02

Urgency tactics

Pressure is the payload. It's designed to make you act before you think.

  • Countdown deadlines ("within 30 minutes")
  • Threats of suspension, fines, or lost access
  • Requests that bypass normal process "just this once"
RED FLAG 03

Suspicious links & attachments

What you see and where it actually leads are often two different things.

  • Hover before you click — check the real destination
  • Unexpected .zip, .exe, or macro‑enabled files
  • Generic greetings and inconsistent formatting
Module 01 · Part 2

If you suspect an email is malicious.

Four steps, in order. The most common mistake isn't clicking — it's deleting the evidence before it's reported.

1

Don't click, don't reply, don't forward

Any interaction can confirm to the sender that your address is active and being read.

2

Report it to IT Security

Use your organization's official reporting process (report button or forwarding to your security team) so it can be traced and blocked for everyone.

3

Leave it in your inbox until confirmed

Don't delete it — IT Security may need the original headers and content to investigate.

!

Already clicked or entered a password?

Change that password immediately and report it — speed matters far more than embarrassment here.

Module 01 · Part 3

Annotated: the actual email from our simulation.

This is the real email sent in our Group‑wide simulation — a spoofed HR "compensation review" request sent from a lookalike Docusign domain. Tap each numbered marker to see why it's a red flag.

Exhibit A — Actual Simulation Email
HR compensation review phishing simulation email screenshot, full Outlook view
Select markers 1–7 on the email — each explanation appears in the panel on the right.
Module 01 · Assessment

Quick check.

8 questions. Pick an answer for each — you'll see which ones were correct, with explanations, at the end. Once you move to the next question you can't go back.

Question 1 of 8
Module 01 · Complete

Training complete.

Here's how you did.

Your result is being recorded to the training completion log for .