Skip to content

Search ThreatNotes

Beginner~1 hour3 lessons

Intro to Phishing Defense

How phishing actually works, how to spot it under time pressure, and exactly what to do in the first ten minutes after someone clicks.

Start the course

Most phishing training teaches people to look for spelling mistakes. That advice is a decade out of date, and it fails against the campaigns that actually get through — the ones that are well-written, correctly branded, and sent from a real, compromised account at a company you genuinely work with.

This course covers what phishing actually exploits, the tells that still hold up when the email looks perfect, and the response steps that matter most in the first ten minutes after a click.

Who this is for

Anyone who reads email for a living. There is no prerequisite beyond that — no tooling to install, no command line, no lab environment.

If you’re the person others come to when something looks wrong, lesson three is the one to bookmark.

What you’ll be able to do afterwards

  • Explain why phishing works on attentive, competent people
  • Triage a suspicious message in under a minute using checks that survive good forgeries
  • Take the right first actions after a click, in the right order
  • Know which of those actions are genuinely urgent and which can wait

Lessons

  1. How phishing actually worksPhishing does not target ignorance. It targets the shortcuts every competent person uses to get through a day of email.
  2. Spotting the tellsTypos are not the signal. Here are the checks that still work against a well-made forgery, ordered by how fast they are.
  3. What to do when you click something badThe first ten minutes matter more than anything else. Here is the order of operations, and why hiding it is the only real mistake.
  • phishing
  • social-engineering
  • fundamentals