The 10-second phishing filter: Train your brain before the boss fight
Most advice on phishing tells you what to watch out for in theory. This is not that. This is a repeatable mental process you can run in ten seconds flat, before you click, reply to emails, or pick up the phone. The goal is to make the check automatic, the way checking your mirrors before changing lanes becomes automatic. You do not think about it. You just do it.
Here is the filter. And it takes only ten seconds.
The filter: Run this before you act on anything
Work through these in order. One “yes” is enough to stop and verify. You do not need to score the whole thing before you pump the brakes.
1. Did this arrive out of nowhere? Legitimate requests usually have context. A payment request you were not expecting, a login alert you did not trigger, a delivery notification for something you did not order. Surprise is the first tell. If it arrived without context, treat it as unverified until proven otherwise.
2. Is it pushing you to act right now? A message that creates a deadline, threatens a consequence, or tells you there is no time to check may be engineered to prevent you from checking. Legitimate banks, IT teams, and executives can send urgent requests too, which is why urgency should trigger verification rather than replace it. “Act in the next fifteen minutes or your account is closed” is pressure designed to short-circuit your judgment.
3. Does the sender address actually match who they claim to be? Check the actual email address, not just the display name. Display names are cosmetic and easily faked. Look at the raw domain. “support@paypa1.com” is not a PayPal domain. “it-helpdesk@company-support-desk.net” is not your IT department. If the domain has extra words, hyphens, numbers, or anything that makes you tilt your head, there's your answer.
4. Are you being asked to go somewhere or do something you would not normally do? Click a link to a login page you were not expecting? Download an attachment from an address you do not recognize? Approve a wire transfer through a chat message instead of your normal finance system? Any request to step outside your normal process is worth pausing on, regardless of how convincing the reason sounds.
5. Does the requester ask you to keep this quiet? “Do not mention this to anyone until the deal is done.” “This is confidential, do not loop in IT.” “My assistant does not know about this yet.” Secrecy requests in a professional context are a red flag, not a feature. Legitimate internal communications do not ask you to hide anything from colleagues. If the request requires your silence to succeed, ask yourself who that silence is actually protecting.
The One Rule That Overrides Everything Else
If something in the filter fires, do not reply to the message. Do not call the number in the message. Do not click the link to check if it is real.
Go sideways. Find the contact through a route that does not touch the suspicious communication. The phone number in the company directory. The person’s direct Slack. Walking to their desk. Any channel that was established before this message arrived.
If it was real, you have lost thirty seconds. If it was not real, you have just protected yourself, or your organization, from something that could cost considerably more than thirty seconds to fix.
Applying the filter by message type
The same logic holds across every channel, with a few specifics worth knowing.
Check the sender domain before you read the content. The content is designed to be persuasive. The domain is just data. If the domain looks wrong, nothing in the body changes that.
Hover over links before clicking. The URL that appears in the tooltip is where you will actually go. Look for lookalike domains: googIe.com (capital i, not L), rn instead of m, extra subdomains that push the real domain to the right.
Attachments from unexpected senders should not be opened, even if the file type looks harmless. Office documents can contain macros, while PDFs can contain malicious links or scripts and may be used to exploit software vulnerabilities. When in doubt, ask the sender through a separate channel before opening anything.
Phone calls and voicemails
Anyone who calls you cold and asks for credentials, payment authorisation, or account access should be told you will call them back. No exceptions. Not even for urgency. Especially not for urgency.
Call back on the official number you already have, not one they give you. If they object to this, that objection is the most useful piece of information they have given you.
Voices can now be cloned convincingly from a very short audio sample. If someone calls who sounds like a colleague or executive but the request is unusual, the voice being familiar is not verification. The request itself still needs to check out through your normal channels.
Texts and messaging apps
Fraudulent SMS messages typically impersonate delivery services, banks, or government agencies. The link in the message will look close to the real one. The safest approach: do not click the link. Go directly to the organisation’s official app or website and check there.
Messaging apps used for work (Teams, Slack, WhatsApp) are increasingly used in social engineering because they feel more casual and less scrutinised than email. Apply the same filter. Unusual requests, urgency, requests for credentials or payment, and requests to keep things quiet are red flags regardless of the platform they arrive on.
What to do when something gets through
Like everything in life, the filter is not perfect. If you click something suspicious, or provide information for a request you later suspect was fraudulent, the instinct to stay quiet to avoid embarrassment is exactly what attackers count on. Report it immediately.
Tell your IT or security team what happened, what you clicked, what you entered, and when. The faster that information reaches the people who can act on it, the smaller the window for damage. Every hour matters. Every hour you wait, that window stays open.
A competent security team should treat a report of a phishing click as intelligence, not make employees afraid to disclose it. The employee who reports promptly is not the problem. The culture that makes reporting feel risky is.
The checklist, printed
Cut this out. Pin it up. Share it.
Before you act on any unexpected message:
• Did this arrive out of nowhere with no prior context?
• Is it creating pressure to act before I can think?
• Does the sender address actually match who they claim to be?
• Am I being asked to do something outside my normal processes?
• Is there a request to keep this confidential from colleagues?
If any answer is yes:
• Do not reply, click, or call any number in the message.
• Contact the sender through a separate, already-established channel.
• When in doubt, report it to IT before acting.