Skip to content
Amrani Academy

4. Accounts and everyday habits

MFA everywhere, and phishing aimed at remote workers

Multi-factor authentication (MFA) is the biggest single upgrade you can make to account security, and phishing is the attack most likely to reach you as a remote worker. The two belong together, because MFA is your safety net when phishing succeeds.

Turn MFA on, everywhere it's offered

MFA means proving who you are with something extra beyond a password, usually an authenticator app prompt or code, a text message, or a physical security key. With MFA enabled, a stolen password alone is not enough to get into your account. Enable it on every work service that offers it, and on your important personal accounts too, especially personal email, which is the recovery route into everything else. An authenticator app or security key is stronger than text messages, but any MFA is far better than none.

MFA fatigue: never approve a prompt you didn't cause

Attackers who have your password may bombard you with approval prompts hoping you'll tap yes to make them stop. If you receive an MFA prompt you did not trigger, deny it and report it to IT immediately, because it means someone has your password and is actively trying to use it.

Phishing rises when workers go remote

Remote workers lean on email and chat, and can't swivel a chair to ask "did you send this?". Attackers exploit that with urgent messages that impersonate IT, your manager, or suppliers: fake password reset links, bogus voicemail or document notifications, requests to buy gift cards or change bank details. Slow down when a message is urgent, unexpected, or asks for credentials or payment. Check the sender's actual address, hover over links before clicking, and never enter your work password on a page you reached from an email link.

Verify through another channel

For any unusual request involving money, credentials, or sensitive data, verify with the supposed sender through a different channel, a phone call to a known number or a message in your normal chat tool. Never verify by replying to the suspicious message itself. If something feels off, report it. A false alarm costs minutes; a missed phish can cost far more.

Course contents