Cybersecurity Reach Foundation
All partner resources

Draft — pending CSRF review. This is source copy. It has not been through editorial, safety, and link review, so do not print or distribute it to a community yet.

Staff guide

Safe Sharing and Privacy

How to handle suspicious messages and screenshots without exposing private information.

For
All partners
Status
Draft, pending review
Version
Set at review

Before sending a suspicious message or screenshot to anyone

  • Remove names, email addresses, phone numbers, home addresses, account numbers, order numbers, and identity details.
  • Remove passwords, one-time codes, payment details, QR codes, and login links.
  • Defang suspicious web addresses in any public material.
  • Do not forward a private conversation to a group without permission.
  • Use the partner's approved reporting route for private material.
  • Do not ask children, clients, patrons, or victims to investigate a suspicious website.
  • Do not publicly accuse a person or organization based on one message or screenshot.

WatchOut and CSRF use reviewed public material for alerts. A report or a feed match is a lead, not automatically proof.

Partner privacy contact

Who to ask inside your organization
[PARTNER NAME / CONTACT]

Before you distribute this

  • Use it: Staff and volunteer training.
  • Replace every bracketed placeholder with your organization's own details.
  • Open every web address yourself before printing it.
  • Current warnings live at watchout.report. Check the date on anything time-sensitive.
Use your browser's print dialog to save this as a PDF.

Cybersecurity Reach Foundation · cybersecurityreach.org · Current warnings: watchout.report

General safety information. CSRF is not a crisis, legal, banking, safeguarding, or law-enforcement service.