Technology is essential for cybersecurity, but employees also make security decisions every day.
An employee may receive:
- A fake Microsoft 365 login request
- An urgent payment instruction
- A suspicious attachment
- An unexpected MFA approval request
- A fraudulent supplier-bank change
- A message pretending to come from management
One incorrect action can expose credentials, business information or company systems.
CISA recommends regular employee phishing education rather than treating cybersecurity awareness as a once-a-year activity. Employees should know how to recognise suspicious messages, verify unusual requests through trusted channels and report incidents quickly.
What Employees Should Know
Every employee should understand five basic rules:
1. Think before clicking
Unexpected links and attachments should be treated carefully.
2. Verify unusual requests
Payment changes, password requests and confidential instructions should be independently confirmed.
3. Never approve unexpected MFA requests
An authentication request the employee did not initiate may indicate someone is trying to access their account.
4. Report suspicious activity immediately
Fast reporting gives IT teams a better chance to contain an incident.
5. Protect company information
Sensitive business information should only be shared through approved systems and authorised channels.
Microsoft also recommends employee education as a key phishing defence and advises organisations to train employees to report suspicious communication to their security or IT teams.
Training Should Be Practical
Security training should use situations employees actually experience:
Finance: fake invoices and bank-detail changes
Executives: impersonation and urgent confidential requests
HR: fraudulent employee-information requests
General staff: phishing, fake login pages and malicious attachments
IT administrators: privileged-account and authentication attacks
For organisations using eligible Microsoft Defender for Office 365 Plan 2 licensing, Microsoft provides Attack Simulation Training for running realistic but harmless phishing simulations and targeted employee training.
How Junubia Host Can Help
Junubia Host can help Tanzanian organisations with:
- Cybersecurity-awareness assessment
- Phishing-awareness training
- Microsoft 365 security guidance
- Employee reporting procedures
- Finance and executive fraud-awareness training
- Security-policy guidance
- Phishing simulation planning
- Incident-reporting readiness
Call to Action
Your Employees Can Be Your First Line of Detection
Request a Cybersecurity Awareness & Phishing Readiness Assessment from Junubia Host Tanzania.



