Free Phishing Awareness Quiz

Ten realistic UK business scenarios -- emails and messages your team could receive today. For each one, decide whether it is phishing or legitimate, then get instant feedback on what the tell was. No signup, no data collected.

Why phishing remains the most common entry point

According to the UK government's Cyber Security Breaches Survey 2024, phishing was the most common type of cyber attack experienced by UK businesses, cited by 84% of those reporting a breach. The scenarios in this quiz are based on the patterns most frequently seen in real incidents: impersonation of cloud software providers, HMRC, invoice fraud and internal IT helpdesk requests.

Recognising phishing is a skill that degrades without practice. A single staff member clicking one malicious link is enough to give an attacker a foothold inside a business network. Regular awareness training -- backed up by technical controls such as DMARC, multi-factor authentication and endpoint protection -- is how that risk is reduced to a manageable level.

The most common phishing tells

The questions in this quiz illustrate the most reliable signals. Look for these in any message that asks you to act urgently:

Frequently asked questions

What should I do if I click a phishing link?

Act immediately. Disconnect the device from the network if you suspect malware was downloaded. Change the password for any account you entered credentials into, starting with your email and any accounts that share the same password. Enable multi-factor authentication if it was not already on. Report the incident to your IT contact or managed security provider and notify your line manager. If financial details were entered, contact your bank directly.

How do I report a suspicious email in the UK?

Forward suspicious emails to the NCSC Suspicious Email Reporting Service at report@phishing.gov.uk. For suspicious text messages, forward them to 7726 (spells SPAM on most keypads). If the email is impersonating HMRC, you can also report it to phishing@hmrc.gov.uk. Inside your organisation, report to whoever manages IT security so they can warn colleagues if the same message is circulating.

How does DMARC help protect against phishing?

DMARC is an email authentication standard that tells receiving mail servers what to do with messages that fail SPF or DKIM checks. When set to a policy of quarantine or reject, it prevents attackers from sending emails that appear to come from your domain -- protecting your customers and suppliers as much as your own staff. Our email security service covers DMARC setup and ongoing monitoring, and you can test your current configuration with our free security checker.

What should I do if I entered my credentials into a phishing site?

Change the compromised password immediately on every service where it is used. If you entered Microsoft 365, Google Workspace or any cloud service credentials, check the account's recent sign-in activity for sessions you do not recognise and revoke them. Enable multi-factor authentication if it is not already on. Report the incident internally and, if the account has access to company financial systems or customer data, escalate to your data protection officer -- a breach may need to be reported to the ICO within 72 hours.

Turn awareness into a measurable programme

A quiz is a starting point. Our security awareness training gives your whole team regular, structured exposure to current phishing techniques -- with reporting so you can track improvement over time.

Talk to Us About Training

Also free: our Website & Email Security Checker, Password Strength & Breach Checker and Cyber Essentials Readiness Self-Assessment -- no signup required for any of them.