Organisations should tell employees to stop, verify, and redirect. That means avoiding the embedded link, checking the request through a known website or phone number, and reporting the message through approved security channels. Clear guidance matters because one quick tap can expose credentials, personal data, or financial information to attackers.
What should organisations tell employees to do first?
The right instruction is simple and memorable: stop, verify, and redirect. Employees should not tap the link, reply in-thread, or trust the display name alone. Instead, they should treat the message as untrusted until they confirm the request through a known website, saved contact method, or internal help channel.
This works because suspicious texts often rely on urgency and familiarity. A short, clear rule helps people break the click-first habit and gives them a safer path that still lets legitimate requests get handled quickly.
How should the verification step be framed?
Verification should be specific, not vague. Telling employees to “check if it is real” is weaker than telling them to use a known website address they type themselves or a phone number already on file. That distinction matters because attackers rely on spoofed links, lookalike domains, and reply channels that feel legitimate at a glance.
Well-written guidance also separates verification from denial. The employee is not being asked to investigate the sender, only to verify the request out of band before taking any action. That keeps the process fast enough to use under pressure and reduces the chance that people improvise their own judgment call.
What should happen after a suspicious text is received?
Employees should know exactly where to send the message next. Approved security channels, such as a report button, forwarding address, or service desk workflow, should be the default so the organisation can review the message, warn others, and take any needed response steps. If the message was opened, the guidance should also say what to do next, such as changing passwords or contacting support if any information was entered.
A good employee instruction is one that closes the loop. Reporting is not only about helping security teams, it also creates a record that can be used to spot campaigns, protect other staff, and measure whether the awareness process is actually being followed.
Risk and Threat Considerations
Suspicious texts are risky because they compress the attacker’s job into one prompt action. If an employee clicks a malicious link, enters credentials, or approves a payment request without verification, the result can be account compromise, data exposure, or financial fraud. The safest response pattern is to slow the decision down before the attacker can turn urgency into action.
Failure mechanism: The message uses social engineering, spoofed links, and time pressure to bypass normal caution, then captures credentials, installs malware, or redirects the user to a fake site.
Impact: One missed text can lead to stolen accounts, fraud, exposed personal or customer data, and a wider phishing campaign against the organisation.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CIS Controls v8, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS-14 — Security Awareness and Skills Training | Staff phishing response hinges on user training and reporting behavior. |
| Recommendation — Train users to pause, verify, and report suspicious texts through approved channels. | ||
| NIST CSF 2.0 | PR.AT-01 — Awareness and Training Policy and Procedures | Clear user guidance and training reduce phishing success and improve reporting. |
| RS.CO-02 — Report Incidents | Employees must report suspected phishing so security teams can respond quickly. | |
| Recommendation — Teach employees the exact response rule for suspicious messages and verify it is remembered. Provide a simple reporting path for suspicious texts and make it the default action. | ||
| NIST SP 800-53 Rev 5 | AT-2 — Awareness Training | Phishing-resistant employee behavior depends on awareness training and repeatable instructions. |
| IR-6 — Incident Reporting | Users need an approved route to report suspected phishing messages. | |
| Recommendation — Include suspicious-text handling in recurring awareness training with clear do-not-click guidance. Establish a report-and-triage process for suspicious texts and ensure employees know how to use it. | ||
Practitioner Guidance
What to prioritise: Give employees a single, short rule they can remember under pressure, and make the safe verification path easy to use on mobile. If the reporting path is slower than replying to the text, people will bypass it.
What to verify: Confirm that staff know to validate requests through a known channel, not by using the phone number or link in the message. Test the instruction with realistic examples, because “looks suspicious” is not enough when the message is well crafted.
Common mistake: Overly broad advice such as “be careful with texts” leaves too much room for improvisation. The better control is a concrete behavioural script: do not click, verify through a known source, then report.
Practitioner takeaway: The best employee instruction is one that is fast, repeatable, and hard to misunderstand, because the control only works if people can apply it in the moment they feel rushed.
Related resources from NHI Mgmt Group
- How can organisations tell normal AI use from suspicious AI use?
- How can organisations turn employees into an effective sensor for suspicious activity?
- What should organisations do when employees report suspicious payment or banking emails?
- What do employees get wrong when they try to verify a suspicious email or text?