An email arrives five minutes before class. It appears to come from your payment provider and says your account will be suspended unless you sign in immediately. Your students are waiting, so clicking the button feels easier than investigating.
That moment of pressure is exactly when a verification routine is useful. Your team does not need to become a group of security analysts. It needs a safe, repeatable answer to one question: How do we check this request without trusting the message itself?
What is a phishing email?
Phishing is a deceptive message designed to get someone to reveal information, send money, open a harmful attachment, or visit a fraudulent page. The FTC describes familiar approaches such as fabricated account problems, unexpected invoices, and requests to confirm information. 1
For a training business, imagine a fake password-reset notice for the student portal, an unexpected document from a supposed applicant, or a message claiming that an instructor’s payment details have changed. These are illustrative scenarios, not reports of incidents at Steams Online or a particular school.
Not every suspicious message contains obvious spelling mistakes. Make the requested action—not just the appearance of the email—the starting point for your review.
Recognize the request that deserves a pause
Ask whether the email is introducing a new payment destination, asking for credentials, changing a familiar process, or demanding secrecy. A routine-looking message becomes higher risk when it asks someone to bypass an established approval step.
Examine the full sender address rather than only the display name. Compare the claimed organization with the actual domain. On a computer, previewing a link destination can reveal a mismatch, but a familiar-looking link alone should not settle the question.
The FBI warns that business email compromise can involve spoofed addresses or genuinely compromised email accounts. That means a familiar name or an existing email conversation is not enough to validate a financial change. 2
Build your procedure around independent confirmation, especially when the request affects funds, account access, or private records.
Verify through a route you already trust
For an account warning, open the service through a saved bookmark or a known address rather than using the email’s sign-in button. For a payment change, call the contact using a number already held in your approved records—not a new number supplied in the same message. The FTC and FBI recommend this kind of independent verification. 1 2
A useful school procedure might require two staff members to approve a change to an instructor’s payment destination. One checks the request with the instructor; the other confirms that the approved details, rather than the emailed details, were entered. This is an example control to evaluate, not a guarantee against every fraud.
Also make the alternative process practical. Put verified provider support details and the internal reporting contact where staff can find them. A rule that says “check with someone” is incomplete when no one knows who that person is.
Separate a normal billing link from a demand for blind trust
Legitimate organizations can send invoices, account alerts, and document requests by email. The answer is not to label every message with a link as fraudulent.
Instead, give staff a way to confirm the underlying task. Does the invoice appear in the known billing portal? Was the document expected? Does the request match an existing course booking? Can the sender confirm it through the contact details already on file?
For your own communications, use consistent sender names and explain what recipients should expect. Consider telling students that they can navigate directly to their portal to review a request. Avoid training people to bypass browser warnings or send passwords back by email.
These are communication-design recommendations: the easier your legitimate process is to recognize, the less guessing students and staff have to do.
Use account protection as a second line of defense
NIST’s small-business guidance recommends unique strong passwords, password managers, and multi-factor authentication, particularly phishing-resistant options where available. 3
For your implementation plan, begin with the accounts that could unlock other systems: the primary email service, hosting account, domain registrar, administrator accounts, and payment services. Ask each provider which protection methods it supports and how recovery works.
Keep access individual rather than sharing an owner’s login. An instructor covering one class should not need the same access as the person managing refunds or hosting. Record who approves access and who removes it when a role changes.
Do not describe MFA as invincibility. Treat unexpected verification prompts as a reason to check your account through a trusted route, not a request to approve automatically.
What to do after someone interacts with a suspicious email
First, encourage immediate reporting without blame. Staff should not have to decide whether an incident is “serious enough” before telling the designated responder.
Describe what happened accurately: the message was opened, a link was followed, a file was downloaded, a password was entered, or money was sent. Those are different events and may need different responses. Preserve the original message for the responder rather than forwarding it casually around the team.
If money has been transferred following a fraudulent request, the FBI advises contacting the financial institution immediately and reporting to the Internet Crime Complaint Center. 2
For a possible credential or device compromise, use your trusted IT contact or the provider’s verified support channel. Ask them to assess password resets, active sessions, unauthorized account changes, and the device involved. Do not send passwords, student records, or suspicious files to an unverified person who offers help.
Make the response easy to practice
Run a short discussion using a fictional message: “Your training portal closes in one hour unless you confirm your password.” Ask staff to explain their next action without clicking anything.
A successful exercise is not simply spotting a typo. It is opening the known service independently, using the reporting route, and continuing the verification process even when the message feels urgent.
Keep a one-page procedure beside your operational checklists. Review it when staff join, when contact details change, and after an incident exposes a confusing step. The most useful security habit is often a modest one that people reliably follow.
When reviewing your school’s systems, include account access and staff responsibilities in the conversation—not just features. Bring those questions to a Steams Online demo.
Sources & further reading
- Federal Trade Commission. How To Recognize and Avoid Phishing Scams.
- Federal Bureau of Investigation. Business Email Compromise.
- National Institute of Standards and Technology. Cybersecurity Basics.
Sources accessed September 19, 2026. Examples and implementation suggestions are original applications, not reported study results.



