Cybersecurity Reach Foundation
All partner resources

Email copy

A note to staff about email at work

Makes early reporting welcome. That tone is the actual protection.

For
Nonprofits, Universities, Schools and youth, Libraries
Status
Reviewed
Version
2026-09-01

Subject line

If you click something you should not have, just tell us

Work email is a target, and the messages are better than they used to be. They copy real branding, reference real projects, and arrive when you are busy.

Worth pausing on: a login page that appears after a link, a request to change bank details, an urgent message from someone senior who is hard to reach, an attachment you did not expect.

The part that matters most: if you click something and think better of it, tell [NAME OR TEAM] straight away. Nobody is in trouble. Almost all the harm comes from the hours between the click and someone finding out.

If you entered a password, change it from another device and say which account. That usually closes the whole thing down.

Paste it into your newsletter or email and edit it freely.

Still to fill in: [NAME OR TEAM]. Replace it before you send this.

Before you send it: Fill in a real name or team. If reporting has no obvious address, people quietly hope it was nothing.

Before you distribute this

  • Use it: All-staff email, volunteer onboarding, and induction packs.
  • Replace every bracketed placeholder with your organization's own details.
  • Open every web address yourself before printing it.
  • Current warnings live at watchout.report. Check the date on anything time-sensitive.
Use your browser's print dialog to save this as a PDF.

Cybersecurity Reach Foundation · cybersecurityreach.org · Current warnings: watchout.report

General safety information. CSRF is not a crisis, legal, banking, safeguarding, or law-enforcement service.