Skip to main content

The Importance of Being Vigilant on the Internet

Media The Importance of Being Vigilant on the Internet

The internet has transformed the way businesses communicate, manage information and serve their customers.

Employees can access email from almost anywhere, collaborate through Microsoft 365, use cloud applications and communicate with customers in seconds. However, this convenience also creates opportunities for cyber criminals.

Many cyber attacks do not begin with advanced hacking techniques. They start with a convincing email, a false login page, an unexpected phone call or a link that appears genuine.

That is why vigilance is one of the most important parts of cyber security.

What Does Being Vigilant Online Mean?

Being vigilant means remaining alert when using email, websites, applications and online services.

It involves pausing before clicking, questioning unusual requests and checking whether something is genuine before providing information or taking action.

Online vigilance does not mean being suspicious of everything. It means developing habits that help you recognise when something does not look right.

These habits may include:

  • Checking who sent an email
  • Looking carefully at website addresses
  • Questioning unexpected payment requests
  • Avoiding unknown attachments
  • Using strong, unique passwords
  • Reporting suspicious activity quickly
  • Keeping devices and applications updated

A few seconds of caution can prevent a serious security incident.

Why Is Internet Vigilance Important?

Cyber criminals often target people because it can be easier to manipulate a user than to break through a well-configured security system.

A criminal may attempt to persuade an employee to:

  • Reveal a password
  • Approve a fraudulent payment
  • Open an infected attachment
  • Visit a false login page
  • Install malicious software
  • Share confidential information
  • Bypass an established process

The message may appear to come from a customer, colleague, director, bank, supplier or trusted technology company.

Modern scams can be professional, well written and highly convincing. They may use genuine company names, copied branding and personal information found online.

Being vigilant helps employees recognise these warning signs before damage is caused.

Phishing Remains a Major Threat

Phishing is a form of social engineering where criminals impersonate a trusted organisation or person.

A phishing email may claim that:

  • Your password is about to expire
  • A document has been shared with you
  • Your Microsoft 365 account has been blocked
  • An invoice is overdue
  • A payment needs approval
  • A parcel could not be delivered
  • You have received a voicemail
  • A customer has sent an important file

The attacker usually wants the recipient to click a link, enter login details or open an attachment.

Once an account has been compromised, the criminal may use it to access business information, send further phishing messages or attempt financial fraud.

Check the Sender Carefully

The display name shown on an email should not automatically be trusted.

An email may appear to come from a familiar person while using an unrelated or slightly altered email address.

For example, a criminal may replace one letter, add an extra word or use a different domain ending.

Before acting on an unusual request, check:

  • The full sender address
  • Whether the domain is correct
  • Whether the writing style seems normal
  • Whether the request was expected
  • Whether the sender is creating unnecessary urgency

When money, passwords or sensitive information are involved, confirm the request through a separate communication method.

Do not reply directly to the suspicious message. Use a known telephone number or start a new email using a trusted address.

Be Cautious With Links

A link can appear legitimate while taking you to a completely different website.

Before clicking, consider:

  • Were you expecting the message?
  • Does the address use the correct domain?
  • Are there spelling mistakes?
  • Is the link shortened or disguised?
  • Is the sender pressuring you to act quickly?
  • Is the page asking for information it should already know?

On a computer, hovering over a link may reveal its true destination. On a mobile device, pressing and holding the link may display a preview.

However, avoid interacting with suspicious links where possible.

It is often safer to open your browser and visit the organisation’s website directly.

Look Closely at Login Pages

False Microsoft 365 and banking login pages are commonly used to steal credentials.

A fake page may look almost identical to the genuine service.

Always check the website address before entering a username, password or authentication code.

Warning signs can include:

  • Misspelled domain names
  • Additional words in the address
  • Unusual domain endings
  • Poor formatting
  • Unexpected requests for repeated sign-ins
  • Requests to download software
  • Pages opened through suspicious emails

A padlock symbol does not guarantee that a website is trustworthy. It only indicates that the connection to that website is encrypted.

Criminal websites can also use encryption.

Treat Attachments With Care

Attachments can contain malicious software or documents designed to steal credentials.

Be particularly cautious with unexpected:

  • Word documents
  • Excel spreadsheets
  • PDF files
  • ZIP archives
  • HTML files
  • Executable files
  • Shared document notifications

A file appearing to be an invoice or delivery notice does not make it safe.

Before opening an attachment, confirm that it came from the expected person and that the content makes sense in the context of your business relationship.

Never enable macros or security exceptions simply because a document asks you to.

Do Not Trust Urgency

Cyber criminals frequently create urgency because they do not want the recipient to stop and think.

Messages may claim that:

  • An account will be closed
  • A payment must be made immediately
  • A customer is waiting
  • A director needs an urgent transfer
  • A security issue requires immediate action
  • A confidential request must not be discussed

Urgency is not proof that a request is genuine.

Employees should feel comfortable slowing the process down, checking the details and involving another person when necessary.

A legitimate colleague or supplier should understand the need to verify a sensitive request.

Be Alert to Payment Fraud

Business email compromise can be extremely costly.

A criminal may impersonate a director, supplier or customer and request:

  • An urgent bank transfer
  • A change of bank details
  • Payment to a new account
  • Copies of invoices
  • Payroll changes
  • Purchase of gift cards
  • Confidential financial information

Changes to payment details should always be verified using a known contact method.

Do not rely solely on email, even when the message appears to come from an established supplier.

Businesses should use documented approval procedures for payments and account changes.

Use Strong, Unique Passwords

Reusing passwords allows one compromised service to place several accounts at risk.

Employees should use a different password for every business service.

A strong password should be:

  • Long
  • Difficult to guess
  • Unique to the account
  • Unrelated to personal information
  • Stored securely

A reputable password manager can help users create and store unique passwords without needing to remember every one.

Passwords should never be shared by email, instant message or written on notes attached to the computer.

Enable Multi-Factor Authentication

Multi-factor authentication adds another layer of protection beyond the password.

It may require the user to approve a notification, enter a temporary code or use a security key.

This can prevent some account compromises when a password has been stolen.

However, users must remain vigilant.

Attackers may repeatedly send authentication prompts in the hope that someone approves one by mistake. They may also create false pages that request authentication codes.

Never approve a sign-in notification that you did not initiate.

Unexpected prompts should be reported immediately.

Keep Devices Updated

Outdated operating systems, browsers and applications may contain known security vulnerabilities.

Updates often include fixes for these weaknesses.

Businesses should make sure that:

  • Operating systems receive security updates
  • Browsers remain current
  • Business applications are patched
  • Unsupported software is removed
  • Mobile devices are updated
  • Network equipment is maintained

Updates should ideally be centrally managed and monitored rather than left entirely to individual users.

Be Careful With Public Wi-Fi

Public Wi-Fi can be convenient, but it should not automatically be trusted.

Criminals may create networks with names similar to those used by hotels, cafés, airports or conference venues.

Employees should avoid accessing highly sensitive systems over unknown networks unless suitable protections are in place.

Safer options may include:

  • Using a trusted mobile connection
  • Confirming the correct network with staff
  • Using a properly configured business VPN
  • Avoiding confidential activity on public devices
  • Keeping file sharing disabled

Even when using a VPN, users should remain cautious about which networks they join.

Protect Personal Information

Information shared publicly can help criminals create convincing scams.

Social media profiles may reveal:

  • Job roles
  • Employee names
  • Suppliers
  • Business travel
  • Office locations
  • Senior management
  • Projects
  • Holiday dates
  • Email formats

An attacker may use this information to impersonate a colleague or create a believable request.

Employees should consider what they share publicly and review privacy settings regularly.

Watch for Fake Support Calls

Online threats are not limited to email.

Criminals may telephone employees while pretending to represent:

  • Microsoft
  • A bank
  • An internet provider
  • An IT support company
  • A software vendor
  • A customer or supplier

They may claim that a computer is infected or ask the employee to install remote-access software.

Legitimate support providers should follow agreed identification and verification procedures.

Employees should not provide passwords, authentication codes or remote access to unexpected callers.

When uncertain, end the call and contact the organisation through a trusted number.

Artificial Intelligence Can Make Scams More Convincing

Artificial intelligence can help criminals produce convincing emails, messages, images and voice recordings.

Poor spelling and grammar can no longer be relied upon as obvious signs of fraud.

An attacker may create a message that closely matches the tone of a director, supplier or colleague.

This makes verification processes even more important.

Businesses should not rely solely on recognising a suspicious writing style. Sensitive actions should require independent confirmation and appropriate approval.

Report Suspicious Activity Quickly

Employees sometimes hesitate to report suspicious emails because they are worried about making a mistake or wasting someone’s time.

That delay can make an incident more difficult to contain.

Employees should immediately report:

  • Suspicious emails
  • Unexpected authentication prompts
  • Accidentally clicked links
  • Entered passwords on questionable websites
  • Opened suspicious attachments
  • Lost devices
  • Unusual account behaviour
  • Unexpected payment requests

Reporting an incident quickly does not mean the employee is at fault.

A supportive reporting culture helps the IT team investigate the issue, reset credentials and protect other users before the attack spreads.

What Should You Do After Clicking a Suspicious Link?

If you believe you have clicked a malicious link:

  1. Stop interacting with the page.
  2. Do not download or open anything.
  3. Contact your IT support provider immediately.
  4. Explain exactly what happened.
  5. Change your password if instructed.
  6. Review and revoke unexpected sign-in sessions.
  7. Do not approve authentication prompts.
  8. Follow the incident response process.

Do not wait to see whether anything happens.

Early action can significantly reduce the impact of a compromise.

Security Awareness Training Matters

Employees cannot be expected to recognise modern cyber threats without guidance.

Security awareness training can help users understand:

  • Phishing
  • Password security
  • Payment fraud
  • Safe internet use
  • Data handling
  • Multi-factor authentication
  • Social engineering
  • Incident reporting

Training should be practical, relevant and repeated regularly.

A single annual presentation is unlikely to create lasting behavioural change.

Short reminders, simulated phishing exercises and regular security updates can help keep the risks visible.

Technology Still Plays an Important Role

Vigilance is essential, but employees should not be expected to provide the business’s only line of defence.

Strong technical controls may include:

  • Email filtering
  • Microsoft Defender
  • Safe Links
  • Safe Attachments
  • Multi-factor authentication
  • Conditional Access
  • Managed devices
  • Endpoint detection and response
  • DNS and web filtering
  • Application control
  • Data loss prevention
  • Security monitoring

The strongest protection combines aware employees with properly configured and managed technology.

Create Clear Business Procedures

Employees are more likely to make safe decisions when procedures are clear.

Businesses should define how staff must handle:

  • Payment requests
  • Changes to supplier bank details
  • Password resets
  • Requests for confidential information
  • New software installations
  • Remote access
  • Lost devices
  • Suspicious emails
  • Security incidents

These processes should be easy to understand and practical to follow.

If security procedures are too complicated, employees may bypass them to complete their work.

Encourage Employees to Pause

One of the simplest cyber security habits is to pause before acting.

Before clicking, replying or approving, ask:

  • Was I expecting this?
  • Does the request make sense?
  • Is the sender genuine?
  • Am I being pressured?
  • Is this asking for sensitive information?
  • Can I verify it another way?

That short pause can prevent a rushed decision from becoming a major incident.

Online Vigilance Outside the Workplace

Personal online security can also affect the business.

Employees may use personal email accounts for password recovery, access business systems from home devices or discuss their work on social media.

Good habits should therefore continue outside the office.

These include:

  • Securing home Wi-Fi
  • Updating personal devices
  • Protecting personal email accounts
  • Avoiding password reuse
  • Reviewing social media privacy
  • Being cautious with online downloads

A compromised personal account may sometimes be used to target the employee’s workplace.

Signs of a Possible Account Compromise

Employees should report unusual behaviour such as:

  • Passwords suddenly not working
  • Unexpected multi-factor authentication requests
  • Messages appearing in the sent folder
  • New mailbox forwarding rules
  • Missing or deleted emails
  • Login alerts from unfamiliar locations
  • Colleagues receiving unusual messages
  • Changes to security settings
  • Unknown devices connected to the account

These signs do not always confirm a compromise, but they should be investigated promptly.

Vigilance Should Become Part of Business Culture

Cyber security is most effective when employees understand that they are part of the organisation’s protection.

This does not mean blaming users when something goes wrong.

It means creating a culture where:

  • Employees are encouraged to ask questions
  • Suspicious activity is reported quickly
  • Mistakes are investigated constructively
  • Security guidance is clear
  • Managers follow the same procedures
  • Employees receive regular training
  • Technical controls support good decisions

Everyone should feel responsible for protecting the business, its customers and its information.

How Hamilton Group Can Help

Hamilton Group helps UK businesses reduce online risk through a combination of technology, monitoring, support and employee awareness.

We can assist with:

  • Cyber security assessments
  • Microsoft 365 security
  • Email protection
  • Multi-factor authentication
  • Microsoft Defender
  • Endpoint security
  • Device management
  • Web and DNS filtering
  • Security awareness training
  • Phishing simulations
  • Backup and recovery
  • Incident response planning
  • Ongoing IT support

We aim to make first contact on IT support requests within 15 minutes, helping customers receive prompt assistance when suspicious activity or security concerns are reported.

The internet is an essential business tool, but it should never be used without caution. A vigilant workforce, supported by strong technical controls and clear procedures, can significantly reduce the risk of cyber attacks.

To discuss cyber security, staff awareness training or managed IT support for your business, contact Hamilton Group on 0330 043 0069.