Join our Newsletter — 33% off our NHI Course
Home› FAQ› Cyber Security› What should organisations tell employees to do when…
Cyber Security

What should organisations tell employees to do when a suspicious text arrives?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 29, 2026 Domain: Cyber Security

Organisations should tell employees to stop, verify, and redirect. That means avoiding the embedded link, checking the request through a known website or phone number, and reporting the message through approved security channels. Clear guidance matters because one quick tap can expose credentials, personal data, or financial information to attackers.

What should organisations tell employees to do first?

The right instruction is simple and memorable: stop, verify, and redirect. Employees should not tap the link, reply in-thread, or trust the display name alone. Instead, they should treat the message as untrusted until they confirm the request through a known website, saved contact method, or internal help channel.

This works because suspicious texts often rely on urgency and familiarity. A short, clear rule helps people break the click-first habit and gives them a safer path that still lets legitimate requests get handled quickly.

How should the verification step be framed?

Verification should be specific, not vague. Telling employees to “check if it is real” is weaker than telling them to use a known website address they type themselves or a phone number already on file. That distinction matters because attackers rely on spoofed links, lookalike domains, and reply channels that feel legitimate at a glance.

Well-written guidance also separates verification from denial. The employee is not being asked to investigate the sender, only to verify the request out of band before taking any action. That keeps the process fast enough to use under pressure and reduces the chance that people improvise their own judgment call.

What should happen after a suspicious text is received?

Employees should know exactly where to send the message next. Approved security channels, such as a report button, forwarding address, or service desk workflow, should be the default so the organisation can review the message, warn others, and take any needed response steps. If the message was opened, the guidance should also say what to do next, such as changing passwords or contacting support if any information was entered.

A good employee instruction is one that closes the loop. Reporting is not only about helping security teams, it also creates a record that can be used to spot campaigns, protect other staff, and measure whether the awareness process is actually being followed.

Risk and Threat Considerations

Suspicious texts are risky because they compress the attacker’s job into one prompt action. If an employee clicks a malicious link, enters credentials, or approves a payment request without verification, the result can be account compromise, data exposure, or financial fraud. The safest response pattern is to slow the decision down before the attacker can turn urgency into action.

Failure mechanism: The message uses social engineering, spoofed links, and time pressure to bypass normal caution, then captures credentials, installs malware, or redirects the user to a fake site.

Impact: One missed text can lead to stolen accounts, fraud, exposed personal or customer data, and a wider phishing campaign against the organisation.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
CIS Controls v8CIS-14 — Security Awareness and Skills TrainingStaff phishing response hinges on user training and reporting behavior.
Recommendation — Train users to pause, verify, and report suspicious texts through approved channels.
NIST CSF 2.0PR.AT-01 — Awareness and Training Policy and ProceduresClear user guidance and training reduce phishing success and improve reporting.
RS.CO-02 — Report IncidentsEmployees must report suspected phishing so security teams can respond quickly.
Recommendation — Teach employees the exact response rule for suspicious messages and verify it is remembered. Provide a simple reporting path for suspicious texts and make it the default action.
NIST SP 800-53 Rev 5AT-2 — Awareness TrainingPhishing-resistant employee behavior depends on awareness training and repeatable instructions.
IR-6 — Incident ReportingUsers need an approved route to report suspected phishing messages.
Recommendation — Include suspicious-text handling in recurring awareness training with clear do-not-click guidance. Establish a report-and-triage process for suspicious texts and ensure employees know how to use it.

Practitioner Guidance

What to prioritise: Give employees a single, short rule they can remember under pressure, and make the safe verification path easy to use on mobile. If the reporting path is slower than replying to the text, people will bypass it.

What to verify: Confirm that staff know to validate requests through a known channel, not by using the phone number or link in the message. Test the instruction with realistic examples, because “looks suspicious” is not enough when the message is well crafted.

Common mistake: Overly broad advice such as “be careful with texts” leaves too much room for improvisation. The better control is a concrete behavioural script: do not click, verify through a known source, then report.

Practitioner takeaway: The best employee instruction is one that is fast, repeatable, and hard to misunderstand, because the control only works if people can apply it in the moment they feel rushed.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 29, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org