Mandatory — All Employees
Security Awareness Training
This training covers the essentials of staying safe online and protecting Entravel's systems, customers, and data. Read through every section below, then complete the short test at the end. You need 80% or higher to pass, and you have 3 attempts.
1. Why This Matters
Most security incidents don't start with a hacker breaking through a firewall — they start with an email, a phone call, or an unlocked laptop. Attackers target people because people are usually the easiest way in. This training exists to make sure every one of us — regardless of role — can recognize an attack attempt and knows exactly what to do about it.
Reporting is never a mistake. If you report something suspicious and it turns out to be harmless, nothing bad happens to you. The only thing that goes wrong is staying silent about something that looked wrong.
2. Email & Phishing
Phishing is a fraudulent message designed to trick you into clicking a link, opening an attachment, entering credentials, or making a payment. Below is what a real, legitimate message looks like next to a phishing attempt using the same scenario.
Example: An "overdue invoice"
PHISHING
From: Alan Morgado <billing@entravel-support-team.com>
Subject: Invoice #I40404 — Due Upon Receipt
"Please see the enclosed overdue invoice for $19,906.47. Regards, Alan Morgado." — attached: BILL-I40404.pdf
LEGITIMATE
From: accounts@knownvendor.com (matches prior correspondence)
Subject: Invoice #4021 for August services
References a real PO number you recognize, matches a vendor you already work with, and payment terms match your existing agreement — no urgency language, no unusual account changes.
Notice: the phishing example uses a lookalike domain ("entravel-support-team.com"), urgency wording ("Due Upon Receipt," "overdue"), and an unfamiliar sender name — three classic red flags stacked together.
Red flags checklist
- Sender domain: Does the actual address match the real company domain exactly? Watch for extra words, hyphens, or swapped letters ("rn" instead of "m").
- Urgency: "Act now," "due immediately," "your account will be suspended" — pressure is a tactic, not a coincidence.
- Unexpected attachments: Invoices, "remittance advice," shipping notices from senders you weren't expecting.
- Login prompts: Any link that asks you to "verify your account" or re-enter your password.
- Unusual requests: Bank detail changes, gift cards, wire transfers — especially from someone claiming to be a manager or executive.
If you see any of these signs: don't click, don't reply, don't forward it to coworkers to ask "is this real?" Report it to entravel.security@entravel.com or log it on the IT Service Desk portal. Verify unusual requests by calling the person directly — never by replying to the email itself.
If you already clicked, opened an attachment, or entered your password: this is not the time to stay quiet. Report it immediately and contact the System Administrator right away — every minute matters when credentials may be compromised.
3. Passwords & Two-Factor Authentication (2FA)
- Use a unique password for every work account — never reuse a personal password for anything work-related.
- Longer passphrases beat complex-but-short passwords. "correct-horse-battery-staple42" is stronger and easier to remember than "P@ssw0rd!".
- Store passwords in the company-approved password manager — not in browsers, spreadsheets, or sticky notes.
- Never disable 2FA/MFA where it's offered, and never read an MFA code out to anyone — including someone claiming to be IT. IT will never ask for your code.
- If you get an MFA push notification you didn't request, deny it and report it — someone else may have your password.
4. Devices & Screen Security
- Lock your screen every time you step away from your desk — in the office, at home, or in a co-working space. Windows: Win + L. Mac: Ctrl + Cmd + Q.
- Install operating system and application updates promptly when prompted — most malware exploits known, unpatched vulnerabilities.
- Keep endpoint protection / antivirus active and never disable it, even temporarily.
- Don't install unapproved software or browser extensions on a company device.
- Report a lost or stolen device immediately so IT can revoke access before it's misused.
5. Public Wi-Fi & Remote Work
- Avoid accessing company systems over open/public Wi-Fi (airports, cafés, hotels) without the company VPN active.
- Treat any Wi-Fi network you don't control as untrusted — someone else on that network can potentially see unencrypted traffic.
- Working from home is fine, but keep your home router's firmware updated and its admin password changed from the default.
- Never leave a company laptop unattended in a public space, even for "just a minute."
6. Data Confidentiality & Storage
- Store work files in approved company systems (shared drives, approved cloud storage) — not on personal drives, personal email, or personal USB sticks.
- Think before forwarding: customer data, contracts, and internal financials should only go to people who need them for their job.
- Before sending sensitive information externally, double check the recipient address — autocomplete has sent confidential files to the wrong person more than once at every company.
- Encrypt or password-protect files containing sensitive data when sharing them outside approved internal systems.
- When a device is retired or reassigned, IT must wipe it first — never hand off a device "as is."
7. Physical Security
- Don't leave printed documents with customer or financial data visible on your desk — clear your desk before leaving.
- Be mindful of screens visible to visitors or in public spaces, particularly on video calls in shared spaces.
- Challenge or report anyone in the office you don't recognize and who isn't wearing/showing appropriate access credentials.