Email copy
A note to staff about email at work
Makes early reporting welcome. That tone is the actual protection.
- For
- Nonprofits, Universities, Schools and youth, Libraries
- Status
- Reviewed
- Version
- 2026-09-01
Subject line
If you click something you should not have, just tell us
Work email is a target, and the messages are better than they used to be. They copy real branding, reference real projects, and arrive when you are busy.
Worth pausing on: a login page that appears after a link, a request to change bank details, an urgent message from someone senior who is hard to reach, an attachment you did not expect.
The part that matters most: if you click something and think better of it, tell [NAME OR TEAM] straight away. Nobody is in trouble. Almost all the harm comes from the hours between the click and someone finding out.
If you entered a password, change it from another device and say which account. That usually closes the whole thing down.
Still to fill in: [NAME OR TEAM]. Replace it before you send this.
Before you send it: Fill in a real name or team. If reporting has no obvious address, people quietly hope it was nothing.
Before you distribute this
- Use it: All-staff email, volunteer onboarding, and induction packs.
- Replace every bracketed placeholder with your organization's own details.
- Open every web address yourself before printing it.
- Current warnings live at watchout.report. Check the date on anything time-sensitive.
Cybersecurity Reach Foundation · cybersecurityreach.org · Current warnings: watchout.report
General safety information. CSRF is not a crisis, legal, banking, safeguarding, or law-enforcement service.