Cybersecurity Reach Foundation
All partner resources

Draft — pending CSRF review. This is source copy. It has not been through editorial, safety, and link review, so do not print or distribute it to a community yet.

Email copy

A note to staff about email at work

Sets the tone that reporting a mistake early is welcome. That tone is the actual protection.

For
Nonprofits, Universities, Schools and youth, Libraries
Status
Draft, pending review
Version
Set at review

Subject line

If you click something you should not have, tell us — that is all we ask

Work email is a target, and the messages are much better than they used to be. They copy real branding, they reference real projects, and they arrive when you are busy.

The things worth pausing on: a login page that appears after you click a link, a request to change bank details, an urgent message from someone senior who is unusually hard to reach, and any attachment you were not expecting.

Here is the part that matters most. If you click something and then think better of it, tell [NAME OR TEAM] straight away. Nobody is in trouble. Almost all the harm from these comes from the hours between the click and someone finding out — not from the click.

If you entered a password, change it from a different device and let us know which account it was. That is usually enough to close the whole thing down.

Paste it into your newsletter or email and edit it freely.

Still to fill in: [NAME OR TEAM]. Replace it before you send this.

Before you send it: Fill in a real name or team. If reporting has no obvious address, people quietly hope it was nothing.

Before you distribute this

  • Use it: All-staff email, volunteer onboarding, and induction packs.
  • Replace every bracketed placeholder with your organization's own details.
  • Open every web address yourself before printing it.
  • Current warnings live at watchout.report. Check the date on anything time-sensitive.
Use your browser's print dialog to save this as a PDF.

Cybersecurity Reach Foundation · cybersecurityreach.org · Current warnings: watchout.report

General safety information. CSRF is not a crisis, legal, banking, safeguarding, or law-enforcement service.