5. Putting it into practice
Workplace scenarios
Scenario 1: The supplier's new bank details
Priya works in accounts at a Manchester engineering firm. An email arrives from a long-standing supplier, sitting inside an existing thread about an invoice that genuinely is due this week. It says the supplier has switched banks, gives new account details, and asks for payment by Friday to avoid a late fee.
**What good looks like:** Priya treats any change of bank details as high risk, however genuine the thread looks. She calls the supplier on the number held in the firm's own records, not one from the email, and asks them to confirm the change. When they say they know nothing about it, she reports the email to IT, and the payment is stopped before it leaves. The thirty-second phone call is the whole defence.
Scenario 2: The chief executive's urgent favour
Late on a Friday afternoon, Dan receives an email that appears to come from his chief executive: "Are you at your desk? I need gift cards for a client thank-you and I'm stuck in meetings. Keep this between us and send me the codes." The display name is right and the tone sounds plausible.
**What good looks like:** Dan recognises the pattern of authority, urgency, secrecy, and gift cards, a request with no legitimate business equivalent. He does not reply. He expands the sender and sees a lookalike domain, reports the message using the phishing button, and mentions it to the chief executive on Teams so IT can warn the wider team. He is not embarrassed to check, because a real executive would thank him for it.
Scenario 3: The midnight MFA prompts
Aisha wakes to find several MFA approval prompts on her phone from overnight. The next morning she gets a call from "IT support" asking her to approve the next prompt "so we can close the ticket and fix the issue".
**What good looks like:** Aisha knows an unexpected prompt means someone already has her password. She denies every prompt, hangs up on the caller, and contacts the real service desk through the normal channel to report what happened. Her password is reset and the sign-in attempts are blocked. She never approves a prompt for a login she did not just attempt herself, no matter who asks.
Scenario 4: I already clicked
Tom opens what looks like a OneDrive sharing notification, clicks through, and types his work password before the page shows an error. Only then does he notice the odd address in the browser bar.
**What good looks like:** Tom reports it to IT immediately and says exactly what happened, including that he entered his password. He changes that password from a device he trusts, and everywhere else it was reused. He does not forward the email to warn colleagues, and he does not delete it. Because he reported within minutes, IT revokes his sessions and pulls the same email from other inboxes before anyone else clicks.
› Course contents
How social engineering works
Spotting phishing emails
Beyond email
Responding and reporting
Putting it into practice