What's Changing
The security tools behind the scenes are moving from the Notes/Domino environment to Microsoft's enterprise security platform. For you, the day-to-day doesn't change much, but there are a few things you should know to keep your account (and the corporation's data) safe.
What Stays the Same
- The rules - don't click suspicious links, don't share your password, report anything weird
- Common sense applies - if an email looks off, it probably is
- IT has your back - the security team monitors for threats so you don't have to
Spotting Phishing Emails
Phishing emails are fake emails that try to trick you into giving up your password or clicking a dangerous link. They're the #1 security threat for any organization.
Red Flags to Watch For
- Urgent language: "Your account will be locked in 24 hours!"
- Unexpected attachments from people you don't know
- Slightly wrong email addresses: support@microsooft.com (notice the double 'o')
- Requests for your password - Microsoft (and the SLSMC IT Service Desk) will NEVER ask for your password via email
- Links that don't match - hover over a link before clicking. If it says "microsoft.com" but the actual URL goes somewhere else, don't click
What to Do If You Get a Suspicious Email
- Don't click any links in the email
- Don't open any attachments
- Don't reply to the email
- Click the Report button in Outlook (if available) or report it to the SLSMC IT Service Desk
- Delete the email
What to Do If You Accidentally Clicked
Don't panic. Just:
- Change your password immediately at portal.office.com
- Tell the SLSMC IT Service Desk right away
- They'll check your account and make sure everything is secure
Phishing Examples to Watch For
Beyond generic phishing, here are scam patterns that could target SLSMC staff:
- Fake invoice emails - "Your invoice is attached" from an address that looks like a supplier but isn't
- Fake shipping or transit documents - "Please review the attached vessel transit notice" with a malicious attachment or link
- Supplier payment redirect - "We've changed our bank account, please update your records" (always verify by phone)
- Fake IT messages - "Your mailbox is full, click here to upgrade" from an address that's not the real SLSMC IT Service Desk
If an email asks you to do something urgent involving money, passwords, or operational data - stop and verify by phone before acting.
The Report Button in Outlook
When you spot a suspicious email:
- Select the email (don't click any links in it)
- In the ribbon, go to Home > Report
- Choose Report phishing or Report junk
- The email goes directly to the IT security team for analysis
This is faster than forwarding and gives IT the technical details they need to investigate.
Password Best Practices
Instead of a complex password like Tr4ff!c#9 that's hard to remember, use a passphrase:
- "ColdCanalMorning2026!" - long, easy to remember, hard to crack
- "LockGateOpensAt#7" - personal to you, meaningless to an attacker
- Use different passphrases for work and personal accounts
- Never share your password with anyone, including people who say they're from IT
- If you think your password has been compromised, change it immediately at passwordreset.microsoftonline.com and contact the SLSMC IT Service Desk
Consider using the Microsoft Authenticator app's password vault or Edge's built-in password manager instead of memorizing everything.
Working Securely at SLSMC
On Shared Computers
- Always sign out when you're done using a shared computer
- Don't save your password in the browser on shared machines
- Lock your screen when you step away (press Windows + L)
On Your Personal Devices
- Keep your phone locked with a PIN, fingerprint, or face ID
- Keep apps updated - Microsoft pushes security updates regularly
- Don't connect to unknown Wi-Fi without checking with IT
With Sensitive Information
SLSMC staff handle sensitive personal and operational information. Under Canada's privacy law (PIPEDA):
- Never email SINs, credit card numbers, or financial details - use the secure channels IT provides
- Don't store work data on personal devices or personal cloud accounts (personal email, USB sticks, etc.)
- Lock your screen every time you step away - press Windows + L. Sensitive information may be visible on your screen. Even 30 seconds away is enough for someone to see something they shouldn't
- Don't plug in unknown USB drives - a USB drive from a vendor or visitor could unknowingly be carrying malware. Ask them to email the files instead
- Follow SLSMC privacy practices - when in doubt, ask your manager
Tips for SLSMC Staff
- MFA is your best friend - it protects your account even if your password is stolen
- When in doubt, don't click - it's always safer to check with IT first
- The IT Service Desk is there to help, not judge - if you click something suspicious, reporting it quickly is the best response
- Updates are important - when your computer asks to update, do it. Those updates include security fixes
Need Help?
If you suspect a security issue:
- Report it immediately - don't wait
- Contact the SLSMC IT Service Desk
