Coming from Notes security basicsMicrosoft SecuritySecurity & Account4 min

Staying Secure

Security Awareness

Phishing Detection Challenge

You'll see 4 emails. For each one, decide: is it a real email or a phishing attempt? Learn to spot the red flags that protect you and Seaway data.

Urgent language

Creates panic to rush you

Wrong sender

Fake or misspelled domains

Asks for passwords

IT never asks via email

Suspicious links

Hover before you click

Interactive - Spot the phishing emails

What's Changing

The security tools behind the scenes are moving from the Notes/Domino environment to Microsoft's enterprise security platform. For you, the day-to-day doesn't change much, but there are a few things you should know to keep your account (and the corporation's data) safe.

What Stays the Same

  • The rules - don't click suspicious links, don't share your password, report anything weird
  • Common sense applies - if an email looks off, it probably is
  • IT has your back - the security team monitors for threats so you don't have to

Spotting Phishing Emails

Phishing emails are fake emails that try to trick you into giving up your password or clicking a dangerous link. They're the #1 security threat for any organization.

Red Flags to Watch For

  • Urgent language: "Your account will be locked in 24 hours!"
  • Unexpected attachments from people you don't know
  • Slightly wrong email addresses: support@microsooft.com (notice the double 'o')
  • Requests for your password - Microsoft (and the SLSMC IT Service Desk) will NEVER ask for your password via email
  • Links that don't match - hover over a link before clicking. If it says "microsoft.com" but the actual URL goes somewhere else, don't click

What to Do If You Get a Suspicious Email

  1. Don't click any links in the email
  2. Don't open any attachments
  3. Don't reply to the email
  4. Click the Report button in Outlook (if available) or report it to the SLSMC IT Service Desk
  5. Delete the email

What to Do If You Accidentally Clicked

Don't panic. Just:

  1. Change your password immediately at portal.office.com
  2. Tell the SLSMC IT Service Desk right away
  3. They'll check your account and make sure everything is secure

Phishing Examples to Watch For

Beyond generic phishing, here are scam patterns that could target SLSMC staff:

  • Fake invoice emails - "Your invoice is attached" from an address that looks like a supplier but isn't
  • Fake shipping or transit documents - "Please review the attached vessel transit notice" with a malicious attachment or link
  • Supplier payment redirect - "We've changed our bank account, please update your records" (always verify by phone)
  • Fake IT messages - "Your mailbox is full, click here to upgrade" from an address that's not the real SLSMC IT Service Desk

If an email asks you to do something urgent involving money, passwords, or operational data - stop and verify by phone before acting.

The Report Button in Outlook

When you spot a suspicious email:

  1. Select the email (don't click any links in it)
  2. In the ribbon, go to Home > Report
  3. Choose Report phishing or Report junk
  4. The email goes directly to the IT security team for analysis

This is faster than forwarding and gives IT the technical details they need to investigate.

Password Best Practices

Instead of a complex password like Tr4ff!c#9 that's hard to remember, use a passphrase:

  • "ColdCanalMorning2026!" - long, easy to remember, hard to crack
  • "LockGateOpensAt#7" - personal to you, meaningless to an attacker
  • Use different passphrases for work and personal accounts
  • Never share your password with anyone, including people who say they're from IT
  • If you think your password has been compromised, change it immediately at passwordreset.microsoftonline.com and contact the SLSMC IT Service Desk

Consider using the Microsoft Authenticator app's password vault or Edge's built-in password manager instead of memorizing everything.

Working Securely at SLSMC

On Shared Computers

  • Always sign out when you're done using a shared computer
  • Don't save your password in the browser on shared machines
  • Lock your screen when you step away (press Windows + L)

On Your Personal Devices

  • Keep your phone locked with a PIN, fingerprint, or face ID
  • Keep apps updated - Microsoft pushes security updates regularly
  • Don't connect to unknown Wi-Fi without checking with IT

With Sensitive Information

SLSMC staff handle sensitive personal and operational information. Under Canada's privacy law (PIPEDA):

  • Never email SINs, credit card numbers, or financial details - use the secure channels IT provides
  • Don't store work data on personal devices or personal cloud accounts (personal email, USB sticks, etc.)
  • Lock your screen every time you step away - press Windows + L. Sensitive information may be visible on your screen. Even 30 seconds away is enough for someone to see something they shouldn't
  • Don't plug in unknown USB drives - a USB drive from a vendor or visitor could unknowingly be carrying malware. Ask them to email the files instead
  • Follow SLSMC privacy practices - when in doubt, ask your manager

Tips for SLSMC Staff

  • MFA is your best friend - it protects your account even if your password is stolen
  • When in doubt, don't click - it's always safer to check with IT first
  • The IT Service Desk is there to help, not judge - if you click something suspicious, reporting it quickly is the best response
  • Updates are important - when your computer asks to update, do it. Those updates include security fixes

Need Help?

If you suspect a security issue:

  1. Report it immediately - don't wait
  2. Contact the SLSMC IT Service Desk