Security awareness
What phishing is — and why awareness matters
What is phishing?
Phishing is a social-engineering technique where someone pretends to be a trusted person, brand, or system to trick you into clicking a link, opening a file, or sharing credentials and other sensitive information.
Messages often look urgent (“your password expires today”), familiar (IT, payroll, delivery), or official (logos and wording similar to Microsoft 365 or internal tools). Attackers rely on speed and pressure more than technical sophistication.
Common signs
- Unexpected requests for passwords, MFA codes, or payment details
- Links that don’t match the real organisation (look carefully at the domain)
- Odd sender display names, reply-to addresses, or slight spelling changes
- Urgent threats: lockouts, missed payroll, legal action, “final notice”
- Attachments or shared files you were not expecting
What is security awareness?
Security awareness is practical training that helps people recognise risky situations and respond safely. It is not about blaming individuals — modern attacks are designed to fool careful, busy people.
Good awareness programmes combine clear guidance, realistic practice, and an easy way to report suspicious messages without fear of punishment for “having clicked.”
Why organisations run phishing simulations
Authorized phishing simulations send carefully controlled messages that look like real threats, so teams can measure risk, spot process gaps (such as reporting paths), and improve training. They are approved by the organisation, scoped in advance, and used for learning — not to trick staff for entertainment.
Domains operated by securitytools.co.za may support that authorized infrastructure. They are not public login services and should never be used to enter corporate passwords.
What you should do
- Pause before clicking when something feels off
- Verify unusual requests through a known channel (not the email’s reply button)
- Report suspicious messages to IT / security using your organisation’s process
- Never enter credentials unless you typed the official site address yourself