Anti-Phishing Policy
Authorized By: Chief Information Security Officer (CISO)
Purpose/Overview
Section titled “Purpose/Overview”Phishing remains one of the leading causes of cybersecurity breaches, with many successful attacks originating from deceptive emails. The purpose of this policy is to outline key practices designed to strengthen Safire’s resilience against phishing threats, distinct from general malware defenses, and to reduce the risk of compromise through human error.
This policy applies to all employees, contractors, third parties, and temporary staff who access Safire’s systems, networks, or information, whether using company-issued devices or personal devices (BYOD).
Policy
Section titled “Policy”- All Employees: Every user of Safire systems serves as a primary line of defense. Each user must adhere to the following:
Unknown Senders: If an email is from an unknown sender, do not provide personal information, open attachments, click links, or enter data into pop-up boxes.
Verification of Known Senders: Even if an email appears to be from a known sender, verify the identity before engaging. Hover over the sender’s display name to reveal the actual email address and ensure it matches the expected domain.
Suspicious Links/Requests: If any email contains a link or requests sensitive data (including CUI, FCI, or proprietary information), independently verify the request (e.g., call the sender via a known number) before taking action. Never provide credentials, CUI, or FCI in response to email requests.
Visual Inspection: Scrutinize suspicious emails for grammar errors, spelling mistakes, urgent tones, or inconsistencies in the email address.
Attachments: If an email looks suspicious or illegitimate, do not open any attachments. When receiving a document from an external source that is expected, always open it in “Protected View” or “Read-Only” mode first.
Reporting: Bring any suspicious emails to the attention of the IT Security Team immediately.
Procedure: Do not merely forward the email (which can strip headers). Instead, forward the suspicious email as an attachment (or u se the designated “Report Phishing” button in the email client) to the IT Security Team.
- CISO, IT, and Compliance: The technical team is responsible for the following defense-in-depth measures:
Ensure all workstations and laptops run updated antivirus and endpoint detection software. Maintain and configure active anti-phishing technology at the email gateway.
Ensure all employees and contractors participate in a phishing awareness program at least annually with role-based training for employees who handle CUI or FCI.
Compliance
Section titled “Compliance”Compliance Measurement
Section titled “Compliance Measurement”Monitoring: The policy owner shall ensure that phishing simulations are conducted on a periodic basis, but not less than quarterly.
Independent Audit: The Compliance department (in coordination with HR and IT) shall engage a qualified third party to conduct a comprehensive phishing simulation that targets the entire organization annually.
Verification: Compliance with this policy will be verified through:
Phishing simulation reports.
Internal and external audits.
Alerts generated by security tools indicating an employee has engaged with a malicious payload.
Exceptions: Due to the critical nature of this security control, no exceptions are to be made to this policy without the explicit written approval of the CEO, following a risk assessment by the CISO.
Non-Compliance
Section titled “Non-Compliance”Phishing Simulation Failures: Employees who fail a phishing simulation shall be subject to the following remediation path:
First offense (24-month period): The employee must attend mandatory additional phishing awareness training.
Second offense (24-month period): The employee must attend a formal discussion with
management regarding the criticality of compliance and repeat the phishing awareness training.
Third or subsequent offense: The employee may be subject to disciplinary action, in accordance with Safire’s HR and disciplinary policies, depending on the circumstances and risk profile.
Actual Security Incidents: Employees who fall victim to an actual phishing attack may be required to undergo intensive security training and a review of their access privileges. In cases of gross negligence or willful misconduct, employees may be subject to disciplinary action, up to and including termination of employment.
Related Standards, Policies, Plans, and Procedures
Section titled “Related Standards, Policies, Plans, and Procedures”Acceptable Use Policy Incident Response Plan
Referenced Terms
- CUI
- Information that requires safeguarding or dissemination controls pursuant to and consistent with applicable law, regulations, and government-wide policies.
Revision History
- 2026-08-20 — Darren Rush
- Merge pull request #2 from safire-dev/dev (
16cb681)