Phishing Awareness Training for a Small Team: 6 Tells, 15 Minutes
Phishing awareness training for a small team: the six tells that give a phishing email away, what to do when you spot one, and a 15-minute session outline.
Most attacks on a small business start with one email that one person trusted for one second too long. You do not need a security department to defend against that. You need every person on the team to recognise the same six tells, to know exactly what to do next, and to practise it once a quarter. This guide gives you all three.
Quick answer
Phishing is an email that pretends to be from someone you trust in order to make you click a link, open an attachment, or hand over a password or payment. The defence is not software alone. It is a team that pauses on the six tells below, reports instead of guessing, and never enters a password on a page reached from an email link.
The six tells of a phishing email
- Urgency plus consequence. "Your account will be suspended in 24 hours", "final notice", "the CEO needs this before the board call". Real organisations rarely combine a deadline with a threat in a single message.
- The From address does not match the display name. The name says "Microsoft Support" but the address is billing-alerts@some-random-domain.net. On a phone, tap the sender name to reveal the actual address before doing anything.
- The link goes somewhere else. Hover on desktop, or long-press on mobile, and read the domain immediately before the first single slash. paypal.com.secure-login.example is not PayPal; it is a subdomain of example.
- A request that bypasses your normal process. New bank details, a gift-card purchase, a password "to fix a sync issue", or an invoice from a supplier who has never emailed that address before.
- Generic greeting with specific pressure. "Dear customer" or "Hi," followed by a very specific ask. Your bank knows your name. Your supplier knows your name.
- An attachment you were not expecting, especially .html, .zip, .iso, or a document that says "enable content" or "enable macros" when opened.
What to do when you spot one
- Do not click, reply, or forward it to colleagues "as a warning". Forwarding spreads the live link.
- Report it to whoever owns email in your business. In a five-person company that may be the founder. Agree on one address, such as security@yourdomain.com, and put it in everyone's contacts.
- If it claims to be from a supplier or teammate, verify through a channel the email did not give you: phone the number you already have, or message them in your team chat.
- If you already clicked and entered a password, change that password now, from a device you trust, and turn on two-factor authentication. Then tell the person who owns email so they can check the mailbox for rules and forwards the attacker may have added.
- If you opened an attachment, disconnect the device from Wi-Fi and get it checked before using it again.
A 15-minute training session you can run yourself
You do not need slides. Book fifteen minutes at the start of a regular meeting and run this once a quarter. Rotate who leads it so the material stays fresh.
Minutes 0 to 5: show three real examples
Pull three phishing emails your team has actually received (your spam folder will have plenty). Put each on screen and ask "what gives it away?". Let people find the tells themselves; it sticks far better than a lecture.
Minutes 5 to 10: agree the one rule and the one address
The one rule: never enter a password on a page you reached from an email link. Go to the site directly instead. The one address: where suspicious mail gets reported. Write both on the shared whiteboard or pin them in chat.
Minutes 10 to 15: walk through "I clicked it"
Talk through the recovery steps above so nobody hides a mistake out of embarrassment. The single most valuable sentence in the session is "if you click something, telling us within ten minutes is a good outcome, not a failure".
Make the email itself harder to fake
Training reduces the chance a person falls for a message. Domain authentication reduces the chance the message arrives looking legitimate in the first place. Publish SPF, DKIM, and DMARC for your own domain so attackers cannot send mail that appears to come from you@yourdomain.com to your own staff. OquMail walks you through those three records with live DNS verification during setup, and its free plan covers up to 15 mailboxes on 3 domains, so a role address like security@ costs nothing to add.
Mistakes small teams make
- Running one big training on day one and never again. Phishing changes; the quarterly fifteen minutes matters more than the length of the first session.
- Punishing people who clicked. It guarantees the next click goes unreported.
- Assuming the founder is immune. Executives receive the most targeted messages.
- Testing the team with fake phishing before they have been taught the tells. Teach first, test later, and keep tests low-stakes.
Common questions
Should we buy a phishing simulation tool?
Not until the basics above are habit. A simulation tool is useful for teams of twenty or more who want to measure improvement, but a five-person business gets most of the value from three real examples and a clear reporting address.
What if the phishing email came from a real customer or supplier address?
That usually means their mailbox was compromised. Verify by phone, warn them, and treat any links or attachments from that address as unsafe until they confirm they have recovered the account.
Does a spam filter make training unnecessary?
No. Filters catch bulk phishing well and targeted phishing poorly. The message that names your CEO, your supplier, and your invoice number is precisely the one that gets through.
Free business email on your own domain
OquMail gives you up to 15 mailboxes on your domain — free — with guided SPF/DKIM/DMARC, webmail, IMAP/SMTP for any mail app, and a send API. Most teams are live in under fifteen minutes. Start at oqumail.com.
Get started free