08/10/2026
How did you do? Let’s check your answers!✏️
1️⃣ Password reset email: NO.
Even if the email looks legitimate, don’t use the link inside it. Go directly to Microsoft 365 through your normal login instead. Phishing emails are designed to look like the real thing.
2️⃣ Urgent request from your boss: NO, not yet.
If someone is asking for sensitive information, money, credentials, or something unusual, verify the request another way first. A familiar name in your inbox doesn’t guarantee the person behind the message is actually who they say they are.
3️⃣ Unexpected DocuSign request: NO, not automatically.
If you weren’t expecting it, verify it before opening. Attackers can impersonate people you know or use compromised accounts to make a malicious request look completely normal.
4️⃣ QR code from a client: NO.
QR codes aren’t automatically safer than links. They can send you to malicious websites just as easily, and they make it harder to see where you’re actually going before you scan.
5️⃣ You clicked, but nothing happened: YES.
Report it. Immediately. No pop-up or obvious reaction doesn’t mean nothing happened. The sooner your IT or security team knows, the sooner they can investigate and respond.
If a few of these made you stop and think, that’s the point.
Cybersecurity threats don’t always arrive with bad spelling, suspicious attachments, and an obvious scammer on the other end. Sometimes they look like your boss, your client, a document you recognize, or a login page you’ve seen a hundred times.
That’s why practical cybersecurity training matters.
Reno Cyber Solutions offers a free, two-hour, on-site CLE course for legal teams that covers the real-world threats your firm is actually facing, while your attorneys earn CLE credit without leaving the office.
DM us today to schedule a training for your firm.