# Security

# How to Identify and Report Phishing Emails

Phishing emails are one of the biggest security threats to schools. This guide helps you recognize and report them.

FVSD uses **KnowBe4** for security awareness training and the **Phish Alert Button** in Outlook for reporting suspicious emails. If you haven't completed your security awareness training, check your email for an invitation from KnowBe4.

## What Is Phishing?

Phishing is when someone sends a fake email designed to trick you into:

- Clicking a malicious link
- Entering your password on a fake login page
- Downloading a harmful attachment
- Sharing personal or financial information

These emails often look like they come from a trusted source — Microsoft, Google, a colleague, or even your principal.

## How to Spot a Phishing Email

Watch for these warning signs:

### Suspicious Sender

- The email address doesn't match who it claims to be (e.g., an email "from Microsoft" sent from `support@m1cr0soft-alerts.com`)
- A colleague's name but a different or external email address

### Urgency and Pressure

- "Your account will be locked in 24 hours"
- "Immediate action required"
- "You must verify your identity now"

### Unexpected Requests

- Asking you to click a link to "verify" your password or account
- Requesting gift cards, wire transfers, or personal information
- An unexpected attachment you weren't expecting

### Poor Writing

- Spelling and grammar mistakes
- Generic greetings like "Dear User" instead of your name
- Awkward phrasing or formatting

### Suspicious Links

- Hover over links (don't click) — does the URL match where it claims to go?
- Look for misspelled domain names (e.g., `fvsd-login.com` instead of `fvsd.ab.ca`)

## Real Examples From FVSD

Phishing emails targeting students and staff have included:

- Fake **job offers** sent to student email addresses — "You've been approved for an online part-time position" with no interview required
- Messages pretending to be from IT asking staff to "verify your email account"
- Fake shared documents — "Someone shared a file with you" with a link to a fake login page

## What to Do If You Receive a Suspicious Email

1. **Do not click** any links or download any attachments
2. **Do not reply** to the email
3. **Report it** using the **Phish Alert Button** in Outlook:
4. Click the **Phish Alert** button in the Outlook toolbar
5. This sends the email directly to IT for review and removes it from your inbox automatically
6. If you don't see the Phish Alert button, contact IT to have it enabled

## What to Do If You Clicked a Link or Entered Your Password

Don't panic — act quickly:

1. **Change your password immediately** (see the [Password Reset](https://kb.fvsd.ab.ca/01-password-reset.md) article)
2. **Contact IT right away** — email helpdesk@fvsd.ab.ca
3. Let IT know exactly what happened — what you clicked, what information you entered

The sooner you report it, the faster IT can secure your account and prevent further damage.

## Tips to Stay Safe

- **Never enter your FVSD password** on a page you reached by clicking an email link — instead, go directly to the site by typing the address yourself
- **Be skeptical of urgency** — legitimate services rarely threaten immediate account lockout
- **When in doubt, ask IT** — it's always better to check than to click
- **Talk to your students** — if you receive a suspicious email, your students may have received it too

## Contact IT

- **Submit a ticket** through the IT helpdesk
- **Email:** helpdesk@fvsd.ab.ca

# FVSD Acceptable Use Policy — Quick Reference

This is a summary of key points from FVSD's Acceptable Use Policy for technology. All staff are expected to follow these guidelines when using FVSD devices, accounts, and network resources.

## Key Points

### FVSD Devices and Accounts Are for Work Use

- FVSD computers, email, and accounts are provided for **work and educational purposes**
- Limited personal use is acceptable as long as it doesn't interfere with your duties or violate any policies
- All activity on FVSD devices and networks may be **monitored and logged**

### Passwords and Account Security

- **Do not share your password** with anyone — including colleagues, students, and family members when working from home
- **Do not use your FVSD password** for personal accounts or websites
- Lock your computer when stepping away (**Windows key + L**) — FVSD devices are configured to lock automatically after **30 minutes of inactivity**, but you should lock manually whenever you leave your device unattended
- Report any suspected unauthorized access to IT immediately

### Mobile Devices

- Any mobile device (phone, tablet) accessing FVSD data through apps like Outlook or OneDrive must have a **passcode, FaceID, or fingerprint** lock enabled
- Only **FVSD-owned devices** may connect to the internal school network — personal devices may only connect to the guest/isolated network
- Any **lost or stolen** FVSD device must be reported to IT immediately

### Email and Communication

- Use professional language in all FVSD email and chat communications
- **Do not open suspicious emails** — use the Phish Alert Button to report them (see the [Phishing Awareness](https://kb.fvsd.ab.ca/09-phishing-awareness.md) article)
- Do not send sensitive student or staff information through unsecured channels

### Student Data and Privacy

- Student information is **confidential** — only access records for students you work with directly
- Do not store student data on personal devices or personal cloud accounts
- Follow FOIP (Freedom of Information and Protection of Privacy) requirements when handling personal information

### Software and Downloads

- **Do not install software** on FVSD devices — submit a request to IT
- Do not download or use unauthorized tools, browser extensions, or applications
- Web-based tools that handle student data must be approved by IT to ensure they meet privacy requirements

### Personal Electronic Devices

- **Students** are not permitted to use, have visible, or have easily accessible any personal electronic device during the school day (8:15 AM until buses leave)
- **Staff** may only use personal devices during unassigned time — personal devices must not be visible during instructional time or in areas where students are present
- Social media platforms are restricted on school networks and devices
- Medical exemptions (e.g., glucose monitoring) require a doctor's letter submitted to the Associate Superintendent of Operations

### Cybersecurity Training

- All staff are required to **periodically complete cybersecurity awareness training** and participate in phishing tests (delivered through KnowBe4)
- This helps stay informed about emerging threats and prevent cyberattacks

### Network and Internet

- Do not attempt to bypass network filters or security controls
- Only FVSD-owned devices may connect to the internal network — personal devices may only connect to the guest/isolated network
- Report any network or security concerns to IT

### FVSD Equipment

- Take care of FVSD devices assigned to you
- Report lost, stolen, or damaged equipment to IT immediately
- Return all FVSD equipment when you leave the division or change roles

## Questions?

If you have questions about the Acceptable Use Policy or whether a specific use is appropriate, contact IT:

- **Submit a ticket** through the IT helpdesk
- **Email:** helpdesk@fvsd.ab.ca