top of page

Phishing Prevention: Take the 10-Question Phishing IQ Test

Nav
5 hours ago
7 min read

Take the Phishing IQ Test


Ten emails and texts, sent to a fictional office manager at a fictional dental practice. Some are phishing and some are perfectly legit, so clicking Phishing ten times won't get you a perfect score. Hover over or tap the links to see where they really go, the same way you should on a real email. Every company, name and address in the test is made up. The tricks aren't. Each one is based on a pattern I see in real inboxes every month.


If you scored 8 or better, nice work. Now send it to the person in your office who clicks everything. Everyone has one. (If you can't think of who it is, I have bad news.)



Here's the short answer. Phishing prevention works in three layers: technical controls that stop most phishing before anyone sees it, people who can spot what gets through, and a process that makes one bad click survivable. Skip any layer and the other two end up doing all the work.


phishing prevention

TL;DR: Take the 10-question test below and send it to your team. Then turn on MFA, lock down your email domain with DMARC, and make a rule that any request about money or passwords gets verified by phone. That covers most of what actually happens.

I've been in IT for 20+ years, from the bench at Circuit City to running NSOCIT, and phishing is still the way in for more incidents than anything clever. So let's start with a quick test of the layer most businesses skip: the people.


Man reading email on his laptop while taking a phishing IQ test


Phishing Is Still the Most Reported Cybercrime


This isn't a vibe. It's in the numbers.


The FBI's 2025 Internet Crime Report lists phishing and spoofing as the most reported crime type of the year, with 191,561 complaints. The same report puts business email compromise losses at $3,046,598,558, which is what phishing turns into when it works on the person who pays the bills.


It's also moving off email. Verizon's 2026 Data Breach Investigations Report found "mobile social engineering (fake text messages and voice calls) with a success rate 40% higher than traditional email phishing." Your email filter can't read your staff's text messages.


And it's what insurers pay out on. Coalition's 2026 Cyber Claims Report found that business email compromise and funds transfer fraud made up 58% of all claims. If you're working on your cyber insurance application, phishing controls are most of the cyber insurance requirements you'll be asked about.


Magnifying glass over a laptop representing how to spot a phishing email

How to Spot a Phishing Email in Ten Seconds


CISA's guide to recognizing and reporting phishing lists the classic signs, including "urgent or emotionally appealing language" and "incorrect email addresses or links." Its bottom line is refreshingly short: "If a message looks suspicious, it's probably phishing."


Here's the ten-second version I teach:


  1. Read the address, not the name. Anyone can set their display name to your boss's name. The address after it is harder to fake.

  2. Hover before you click. On a computer, hold the mouse over the link and look at the bottom corner of the screen. On a phone, press and hold.

  3. Notice the deadline. "Within 2 hours" or "before Friday's payment run" is there to stop you thinking.

  4. Notice the ask. Passwords, gift cards, bank changes and "log in to view" documents are the four big ones.

  5. Check the attachment type. Voicemail doesn't arrive as an .html file. Neither do invoices, usually.


None of this needs technical skill. It needs about ten seconds and the habit of spending them.


Email inbox on a screen, where phishing prevention filters work

Phishing Prevention Starts Before the Inbox


The best phishing email is the one nobody on your team ever sees. These controls do most of the heavy lifting:


  • Email filtering with link and attachment scanning. Microsoft 365 and Google Workspace both have it, but the stricter settings aren't always on by default.

  • SPF, DKIM and DMARC. These stop strangers sending email as your domain. Check yours in ten seconds with our free email security checker.

  • Block risky attachment types. HTML, ISO and script attachments have almost no business use and a long criminal record.

  • External sender tags. A simple "EXTERNAL" banner on outside email makes the fake "Sam from the office" message stand out.

  • MFA everywhere. It's technically a clean-up control, but it's the reason a stolen password doesn't automatically become a stolen mailbox. Authenticator apps or hardware keys beat text messages.


This layer isn't glamorous, and nobody ever thanks it. It's the IT equivalent of a smoke detector.


Conference room set up for a phishing awareness training session

The People Layer: Training That Actually Works


Here's my one strong opinion on this. A training certificate is like a compliance badge. It proves someone sat through a video once. It doesn't prove they'd catch the email that lands at 4:55pm on a Friday.


What actually changes behaviour:


  • Short and often beats long and yearly. Five minutes a month sticks. Forty-five minutes every January gets watched on mute.

  • Realistic phishing simulations. Send fake phishing emails to your own team, then show people what they missed. Like the test above, but with their real inbox.

  • A report button, and praise for using it. The person who reports a phish is doing security work. Treat it that way, even when it turns out to be a real email.

  • No public shaming. People who get embarrassed stop reporting. People who stop reporting are how a click turns into an incident.


If you only change one thing, make reporting easy and reward it. Your team sees more phishing than your filter does, and the fastest phishing prevention win in most offices is simply getting people to say something.


Padlock on a laptop representing controls that make one bad click survivable

Make One Bad Click Survivable


Someone will click eventually. The goal is making sure one click doesn't become a breach.


I see the same pattern over and over (a pattern, not one client). Someone enters their password on a fake login page. IT resets that one password and closes the ticket. A few days later, the attacker is back in through webmail or the VPN, because that password was reused somewhere else. Cleaning up one account while the same password works on five others is like changing the lock and leaving the spare key under the mat.


So build the backstops:


  • MFA on email, remote access and admin accounts, so a stolen password isn't enough

  • Least privilege, so a clicked link on a receptionist's laptop can't reach the file server's admin panel

  • Endpoint detection and response (EDR), so malicious attachments get caught when they run, not after

  • A call-back rule for money, written down: any payment change or unusual request gets verified by phone, using a number you already had


That last one is free. It also stops most of the business email compromise losses in the FBI numbers above.


Man holding a smartphone with a text message, a common spear phishing channel

Spear Phishing, Texts and the Calendar Invite Problem


Generic phishing goes to thousands of people. Spear phishing goes to one, and it's usually done its homework. It knows your boss's name, your vendor's name and that you pay invoices on Fridays. That's why "Quick favor" from a Gmail address with the owner's name works better than any long-lost inheritance ever did.


Spear phishing prevention comes down to verification. When a request is unusual, check it on a second channel you trust: a phone call, a message on Teams, or walking over to someone's desk.


Two newer tricks deserve a mention:


  • Text messages. Delivery fees, bank alerts and "is this you?" texts. There's no hover on a text, so the rule is simple: don't tap links in texts you weren't expecting.

  • Calendar invites from unknown organizers. Many calendars add invites automatically, so a phishing link shows up looking like a meeting. If you don't recognize the organizer, delete the invite and report it. Don't click Join to find out what it is.


Man at a computer after clicking a phishing link

What to Do If Someone Clicks


Fast and calm beats slow and embarrassed. If someone on your team clicks or enters a password:


  1. Tell IT immediately. Minutes matter. This is exactly why a no-shame reporting culture pays off.

  2. Change the password from a different, clean device, along with any account that shares it.

  3. Sign out every session and re-check MFA. Attackers sometimes register their own MFA device.

  4. Look for new mailbox rules. A forwarding rule to an outside address, or one that hides replies, is a classic sign.

  5. Warn the people who might get the next email, especially if the account sent anything after the click.


If money moved, call your bank right away and ask about a recall. Then call your insurer's breach hotline if you have one.


Small business owner setting up phishing protection himself

When You Don't Need Us for This


If you're a five-person office on Microsoft 365 or Google Workspace, you can do most of this yourself in an afternoon. Turn on MFA for everyone, turn on the built-in phishing protection, check your DMARC record, and send the test above to your team twice a year. That's a solid setup, and you don't need to pay us for it.


Where it gets harder is 15 to 150 people, a mix of devices, a few vendors who email invoices, and nobody whose actual job is security. That's where ongoing simulations, filtering that's actually tuned, and someone watching alerts at 2am are worth a flat monthly rate. That's what our managed cybersecurity covers.


Question marks representing common phishing prevention questions

Straight Answers


What is the best way to prevent phishing?


Use layers. Email filtering and DMARC stop most of it before anyone sees it, training helps people catch what gets through, and MFA plus a call-back rule for money limit the damage when someone clicks.


How can employees recognize a phishing email?


Check the real sender address, hover over links before clicking, and be suspicious of urgent deadlines and requests for passwords, gift cards or bank changes. When in doubt, verify on a second channel.


What helps protect from spear phishing?


Verification. Spear phishing uses real names and real context, so the defence is a habit of confirming unusual requests by phone or in person. External sender tags and MFA help too.


How often should we run phishing training?


Short sessions monthly or quarterly work better than one long annual session. Pair them with realistic phishing simulations so people practise on emails that look like their real inbox.


What should I do if I clicked a phishing link?


Tell IT right away, change the password from a clean device, sign out all sessions, and check for new mailbox forwarding rules. If you entered payment details or moved money, call your bank immediately.


Does MFA stop phishing?


MFA doesn't stop the email, but it stops a stolen password from being enough on its own. Phishing-resistant MFA, like authenticator app number matching or hardware keys, holds up better than text message codes.


IT support technician on a call helping with phishing prevention

Still Stuck? Give Us a Call


If your team's scores came back lower than you'd like, that's normal. These emails are built by people who do this full time. The good news is phishing prevention is one of the fastest things to improve.


We're a flat-rate MSP in Baltimore covering Maryland, Virginia and Washington D.C., with a response time under 15 minutes on critical issues. Give us a call on 410-703-3857 or book a free review, and we'll look at your email security settings and set up phishing training that people actually finish.


And if you ever get an email from us asking for your password, that one's phishing too. We already know it's "Summer2026" anyway. (Kidding. Please change it.)


Comments


bottom of page