
Practical security awareness resources and checklists
This page collects the ready-to-use tools we reference across our guides — checklists you can run through before clicking a link, at your desk, or while setting up a new account. Everything here is written to be actionable in minutes, whether you're new to security or responsible for keeping a whole team safe. Use these alongside the full guides for context on why each step matters.
Suspicious email verification checklist
- Check the sender's full address, not just the display name — hover to reveal the real domain (e.g. paypa1-secure.com instead of paypal.com).
- Read the greeting: generic openers like 'Dear customer' from a service that normally uses your name are a warning sign.
- Look for urgency or threats — 'your account will be closed in 24 hours' is designed to make you act before thinking.
- Hover over every link (don't click) and confirm the destination URL matches the organisation's official domain.
- Never open unexpected attachments, especially .zip, .html, or files asking you to 'enable macros' in Office documents.
- Verify requests for money, gift cards, or credentials through a separate, known channel — call the person or company directly.
- When in doubt, report the message to your IT or security team and delete it rather than replying.
Account hardening checklist
- Enable two-factor authentication on email, banking, and work accounts — prioritise email since it can reset every other password.
- Use an authenticator app or a hardware key instead of SMS codes where possible, as SMS can be intercepted or SIM-swapped.
- Replace reused passwords with unique passphrases of at least 12 characters generated by a password manager.
- Review connected apps and third-party access in your Google, Microsoft, and social accounts, and revoke anything unfamiliar.
- Check for old accounts you no longer use and close them to shrink your exposure to data breaches.
- Set up recovery options (backup codes, secondary email) and store them somewhere offline and secure.
- Turn on login alerts so you're notified of sign-ins from new devices or locations.
Quick reference: key facts to remember
- A strong passphrase of 12+ characters is far harder to crack than a short complex password — length beats complexity.
- Two-factor authentication blocks the vast majority of automated account takeover attempts, even if your password leaks.
- Legitimate organisations will never ask for your password, full card details, or 2FA code by email or phone.
- Phishing links often use lookalike domains, subdomains, or URL shorteners to hide their real destination — always inspect before clicking.
- On public or home Wi-Fi, a VPN encrypts your traffic, but it does not protect you from phishing or malware you download yourself.
- In France, you can report phishing and online fraud via cybermalveillance.gouv.fr and forward scam SMS to the number 33700.
What should I do first if I think I clicked a phishing link?
Disconnect from the network to limit any download, then change the password of any account you may have entered on that page — starting with your email. Enable two-factor authentication if it isn't already on, run a malware scan, and report the incident to your IT or security team so they can watch for related activity.
Are password managers safe to trust with all my passwords?
Reputable password managers encrypt your vault so that even the provider cannot read it, and they let you generate and store unique passwords without memorising them. The main risk is a weak master password, so protect it with a long passphrase and turn on two-factor authentication for the manager itself.
Is SMS-based two-factor authentication good enough?
SMS 2FA is much better than no second factor, so keep it if that's your only option. However, codes can be intercepted or stolen through SIM-swap attacks, so where available switch to an authenticator app or a physical security key for stronger, phishing-resistant protection.
How can I tell a legitimate urgent message from a scam?
Genuine organisations rarely pressure you to act within minutes or threaten immediate account closure. Slow down, don't use the links or numbers in the message, and contact the company directly using details from their official website or the back of your card to confirm whether the request is real.
What extra precautions matter when working remotely?
Keep your devices and software updated, lock your screen when you step away, and avoid entering credentials on shared or public computers. Use your organisation's VPN for work systems, be cautious with personal devices handling company data, and follow the same email-verification habits you would use in the office.
How do I help colleagues who aren't very technical stay safe?
Focus on a few clear habits rather than overwhelming them: verify unexpected requests, use a password manager, and turn on two-factor authentication. Share these checklists, create a simple way for them to report suspicious messages without fear of blame, and lead by example so good practice becomes normal across the team. Learn more.
Guides
Phishing awareness: how to spot and stop attacks
Learn how phishing works, the warning signs to watch for, and simple steps to avoid falling for fraudulent messages at work and at home.
How to create and manage strong passwords
A plain-language guide to building strong, memorable passwords, using password managers, and avoiding the mistakes that leave accounts exposed.
Social engineering: how attackers manipulate people
Understand the tactics behind social engineering attacks and learn practical habits to protect yourself and your colleagues from manipulation.
Two-factor authentication: an essential extra layer
Learn what two-factor authentication is, why it matters, and how to set it up to add a strong extra layer of protection to your accounts.
Staying secure while working remotely
Practical security awareness tips for remote and hybrid workers, from securing your home network to protecting devices and sensitive data.
How to spot scam and fraudulent emails
A clear checklist for identifying scam emails, from suspicious links and senders to urgency tricks, so you can respond safely and avoid fraud.