Shared document outside an active project
Use a fictional document invitation that asks for an unexpected sign-in. The employee practices opening the known collaboration service and verifying the sender through the usual project channel.
Remote employees make security decisions in email, shared documents, chat, and calls, often without a nearby colleague to ask. Training should make the next safe action easy to find.
Build a program around the tools people actually use, a reporting route that works from home, and reinforcement that fits different working hours.
Cloud-workflow scenarios • Accessible reporting • Asynchronous learning
NIST advises verifying urgent messages using contact information obtained independently of the message. For a distributed team, translate that advice into a concrete habit: open the known application, consult the internal directory, or contact the named service desk through a saved route.
Document what an employee should do if they already clicked or approved a request. They should be able to find the response contact without searching an unfamiliar message. Ask managers to reinforce early reporting and explain what information the response team needs, including when the interaction happened.
Source: NIST: Recognizing, verifying, and reporting phishing
Use a fictional document invitation that asks for an unexpected sign-in. The employee practices opening the known collaboration service and verifying the sender through the usual project channel.
A mock message asks a new starter to confirm delivery details or pay a small equipment charge. Practice contacting the established onboarding coordinator instead of using the message's reply address.
Use a lesson or tabletop discussion to rehearse rejecting an unsolicited prompt and contacting support. Do not generate live authentication requests or collect real credentials for an awareness exercise.
A discussion scenario presents a supposed colleague asking for sensitive information. Teach verification through the company directory and an approved channel; email simulation support does not imply chat simulation support.
Run these checks with employees from more than one location. A workflow that works on an administrator's laptop may fail on a mobile mail client.
| Working condition | What to test | Decision before launch |
|---|---|---|
| Different time zones | Delivery, reminders, and reporting timestamps. | Choose local working windows and explain the reporting time zone. |
| Mobile email | Readability, link visibility, and the actual reporting route. | Provide a tested alternative if a reporting button is unavailable. |
| Limited bandwidth | Lesson load time, captions, and text alternatives. | Offer a practical way to complete learning without a live session. |
| After-hours reports | Acknowledgment and the documented escalation route. | Name the responsible team and communicate coverage honestly. |
| New or contract staff | Access to guidance and the internal support directory. | Resolve missing access before treating nonparticipation as a result. |
NIST's learning-program guidance emphasizes evaluation and adjustment. Use the pilot findings to revise instructions before expanding; the proposed rollout here is an operational example, not a prescribed NIST schedule.
List email clients, collaboration tools, device types, languages, and support hours. Choose one behavior to practice, such as verifying an unexpected file invitation.
Place concise instructions in onboarding materials and a familiar internal location. Test them from an employee account, including the fallback when the normal application is unavailable.
Use a small cohort across locations and normal working windows. Coordinate with the response team so employee reports receive useful handling and genuine incidents retain priority.
Share a short explanation of the decision and the verification route. Give people a reasonable completion window, then review unanswered reports, access problems, and lesson feedback.
Source: NIST SP 800-50 Rev. 1: Building a Cybersecurity and Privacy Learning Program
Before launch, verify that a remote employee can find the support contact, report a suspicious message, receive acknowledgment, access the explanation, and complete follow-up from their normal device. Record one successful walkthrough and each unresolved limitation.
In reporting, distinguish delivery from opportunity to participate. A message received during leave or outside local hours needs context. Compare equivalent scenarios and review how quickly reports reach the responsible team, where those timestamps are available. Do not interpret a missing event as proof that someone ignored the exercise.
No. Short lessons, recorded explanations, and asynchronous exercises can support employees across time zones. A live discussion can help with complex workflows, but provide an accessible alternative and a way to ask questions later.
Use approved workplace channels within the agreed exercise scope. If a relevant channel cannot be simulated appropriately, use a fictional example in a lesson or tabletop discussion. Do not assume access to employees' personal accounts.
Test the lesson and reporting instructions on the mail clients employees use. Include a usable fallback for clients without the expected reporting control, and explain how to reach support after an interaction.
Ask to see scheduling behavior, mobile lesson access, language options, reporting instructions, reminder controls, and completion exports. Verify current capabilities and distinguish platform features from steps your team must operate manually.
Bring your device, scheduling, and reporting requirements to a Phishmake demo and walk through the experience your employees would use.