Spot the Phish
Compare believable messages and learn the warning signs attackers rely on.
Interactive lessonCybersecurity without complicated terminology. Try a few everyday situations and see how easily a normal decision can become a security problem.
Choose the answer you would genuinely pick. There is no login and these exercises do not ask for or store real passwords.
Never give a real password to an unexpected page. Check the exact domain and why the password is being requested.
Urgency is a classic social-engineering technique. OTP and MFA codes are credentials too.
Attackers often use look-alike names. Read the real domain from right to left before the first slash.
A backup attackers can encrypt with the computer is not enough. Keep independent copies and test restoration.
HTTPS encrypts the connection. A fraudulent site can also have a valid HTTPS certificate.
Training rule #1: never type a genuine password, OTP, bank detail or confidential information into a demonstration.
Compare believable messages and learn the warning signs attackers rely on.
Interactive lessonLearn domains, misleading subdomains, redirects and look-alike spelling without networking jargon.
Beginner friendlyLose a laptop, NAS or cloud account and discover which copies of your data actually survive.
Business continuity