5. Putting it into practice
Workplace scenarios
Scenario 1: The urgent payment change
A finance assistant receives an email that appears to come from the managing director, who is travelling. It says a key supplier has changed banks and asks for the account details on a pending payment to be updated today, before the payment run. The tone is polite but insistent, and it ends with "I'm in meetings all day, so just get it done."
What good looks like: the assistant treats urgency plus a payment change as a classic business email compromise pattern, however plausible the message looks. They verify through a second channel they already trust: phoning the supplier on the number held on file, or speaking to the MD directly. No payment details change on the strength of an email alone, and the message is reported so colleagues can be warned.
Scenario 2: The attachment that wants macros
An office administrator receives an invoice attachment from an unfamiliar company. When opened, the document displays a banner saying the content is protected and asks them to click "Enable content" to view it.
What good looks like: the administrator recognises the request to enable macros as a strong warning sign that the document is trying to run code, closes the file without clicking anything further, and reports it through the normal channel. They don't forward the attachment to colleagues to ask "is this safe?", which would only spread the risk.
Scenario 3: The password that turned up in a breach
A team leader gets a notification that a shopping website they use has been breached, and their email address and password were among the leaked data. They realise the same password also protects their work email account.
What good looks like: they change the work password immediately to something long, unique, and generated by a password manager, and they change it anywhere else the old one was reused. They switch on multi-factor authentication for the work account if it isn't already enabled, and tell IT what happened, since credential stuffing attacks against the account may follow.
Scenario 4: The Friday afternoon click
Late on a Friday, a busy employee clicks a link in an email that looked like a parcel delivery notification and types in their work username and password before realising the page looked wrong. They feel embarrassed and consider saying nothing until Monday.
What good looks like: they report it immediately, before leaving for the weekend. Within minutes, IT can reset the password and check for suspicious sign-ins; by Monday, an attacker could have had the whole weekend inside the account. A good employer treats the fast report as exactly the right behaviour, because speed matters far more than certainty or saving face.
› Course contents
Foundations of cyber security
Common threats
Passwords and authentication
Staying safe day to day
Putting it into practice