This Was a Phishing Simulation
This exercise was conducted by the Ignyte Security & Compliance team.
The survey you just completed was not a legitimate request. It was designed to look routine so we could measure how our team responds to unexpected messages asking for information. No harm was done, and this is exactly the kind of scenario these exercises are meant to teach.
Phishing Awareness Training
Phishing remains one of the most common ways attackers gain a foothold inside an organization. The good news: a well-informed team is the single most effective defense against it. This short guide explains what just happened, why these exercises matter, and how to recognize and respond to real threats.
Why We Run These Exercises
Simulated phishing campaigns give our security team practical, real-world insight that policies alone cannot provide. Specifically, they help us:
- Identify where support is needed, so training can be directed to the teams that will benefit most.
- Measure progress over time by tracking how our collective awareness improves with each exercise.
- Strengthen our defenses using what we learn to refine email filtering and detection controls.
- Build a security-first culture where reporting a suspicious message is second nature for everyone.
What Is Phishing?
Phishing is a form of social engineering in which an attacker impersonates a trusted person or organization to manipulate you into taking an action that compromises security. Common goals include getting you to:
- Reveal passwords, credentials, or confidential information.
- Open an attachment that installs malware or ransomware.
- Click a link leading to a fraudulent website.
- Authorize a payment or transfer under false pretenses.
- Provide details that enable a larger attack on our systems.
Why It Matters
The large majority of security breaches begin with a phishing message. A single successful attempt can lead to significant financial loss, operational disruption, and damage to the trust our clients place in us.
Warning Signs to Watch For
Most phishing attempts share a handful of recognizable characteristics. Here are the ones that were present in this exercise:
A Sense of Urgency
Pressure to act quickly is designed to stop you from pausing to think.
An Unexpected Request
A form or survey you were not told to expect deserves a second look.
Mismatched Links
Hover over any link and confirm the destination matches the sender.
Generic Greetings
Legitimate internal messages usually address you by name.
A Sender That Doesn't Match
Check the actual email address, not just the display name shown.
Requests for Sensitive Data
Be cautious whenever a message asks for credentials or personal details.
How to Protect Yourself
Recommended Practices
- Verify the sender's identity before responding.
- Hover over links to preview the true destination.
- Inspect URLs carefully for subtle misspellings.
- Report suspicious messages to the Security team.
- Enable multi-factor authentication everywhere.
- Keep software and devices up to date.
- Use strong, unique passwords for each account.
Practices to Avoid
- Clicking links in unexpected messages.
- Opening attachments you did not anticipate.
- Sharing passwords or credentials by email.
- Replying to a message that feels suspicious.
- Dismissing security warnings from your tools.
- Reusing the same password across services.
- Trusting a display name at face value.
If You Receive a Suspicious Message
- Do not click any links or open any attachments.
- Report the message to the Security team right away.
- Forward it to security@ignyteplatform.com.
- Use your mail client's built-in report option if available.
- Delete the message from your inbox once reported.
- Do not reply to the sender under any circumstances.
A Note From the Security Team
Our goal is to support you, not to catch you out. Reporting a suspicious message, even one you interacted with, helps protect the entire organization. When in doubt, ask first. There is never a penalty for checking.
Multi-Factor Authentication
Multi-factor authentication (MFA) is one of the most effective safeguards available. Even if an attacker obtains your password, they cannot access your account without the second verification factor. If you have not yet enabled MFA on every account that supports it, please make that a priority this week.
Common Methods, From Good to Strongest
- Text-message codes. Better than nothing, but the most vulnerable option.
- Authenticator apps. Time-based codes from apps such as Microsoft or Google Authenticator.
- Hardware security keys. Physical devices that offer the strongest protection.
- Biometrics. Fingerprint or facial recognition tied to your device.
Your Ongoing Responsibilities
- Complete assigned security training when scheduled.
- Report suspicious messages and phishing attempts promptly.
- Keep your devices, software, and passwords current.
- Use strong, unique passwords for every account.
- Enable multi-factor authentication wherever it is offered.
- Approach unexpected requests with healthy skepticism.
- Share what you learn with colleagues and family.
Resources & Support
Access interactive modules covering phishing, password hygiene, and incident reporting.
Reach us anytime at security@ignyteplatform.com for questions or to report a concern.
Use the approved password manager to generate and store strong, unique credentials.
Review current security policies and incident response procedures at any time.
You've Completed This Training
Your participation has been recorded. Take a few minutes this week to enable MFA, review your passwords, and save the Security team's contact details. Small habits make a lasting difference.
Return to Ignyte Platform