Phishing Defense — Internal Knowledge Base

Phishing remains the most common initial access vector. Employees should treat
any unexpected email that creates urgency, requests credentials, or carries an
unusual attachment as suspect. Common indicators include: sender display names
that do not match the underlying address, look-alike domains (rn instead of m,
extra hyphens), generic greetings, and links whose visible text differs from
the actual destination shown on hover.

Reporting procedure: use the "Report Phishing" button in the mail client, which
forwards the message with full headers to the security team's triage queue. Do
not forward the message manually and do not click links "to check." If you
already clicked a link or entered credentials, report it immediately and change
the affected password from a known-good device — early reporting dramatically
reduces impact and is never punished.

The security team runs quarterly phishing simulations. Simulation results are
used for targeted training only, never for discipline. Repeat-click training
focuses on hover-checking links, verifying senders out-of-band, and slowing
down on urgent requests.

Spear phishing targets specific individuals using researched personal detail,
and business email compromise (BEC) impersonates executives or vendors to
redirect payments. Any request to change banking details must be verified by
phone using a number from the vendor master file, not from the email.
