Training

Safe browsing

Where on the internet can you safely click, and where not? With a few rules of thumb you browse a lot more safely — at the office and at home.

Food for thought first

Which of these two addresses really belongs to Microsoft: login.microsoft.com or microsoft.login-verify.com? And why?

Read the URL before you click

The web address tells you where you'll really end up. Look at the domain: that's the part right before the first single forward slash, read from the right. login.microsoft.com belongs to Microsoft; microsoft.login-verify.com does not — there, login-verify.com is the real domain. Also watch for swapped letters (rnicrosoft.com) and odd extensions.

  • Hover your mouse over a link (or press and hold on your phone) to see the real destination.
  • A padlock (https) only means the connection is encrypted — not that the site is trustworthy. Phishing sites have a padlock too.
  • Go to important sites (bank, email, portals) via your own bookmarks or by typing the address yourself.

Where not to just click

Ads and sponsored search results

Criminals buy ads above the real search result, especially for software downloads. Scroll to the organic result or type the address yourself.

Pop-ups: "your computer is infected!"

Messages asking you to call a number or install something are a scam (tech support scam). Close the tab; never call such a number.

"Update your browser/codec" messages on websites

Browsers update themselves; sites that offer updates are almost always malicious.

Links in unexpected emails, chat messages or texts

See our recognising phishing training — the same rules apply to WhatsApp and text messages (smishing).

Shortened links (bit.ly and similar)

You can't see where you'll end up. From an unknown source: don't click.

Downloads and paying

✔ Do

  • Download software from the maker's official site or the app store
  • Check the file type before opening
  • For webshops, check reviews and business registration details first
  • Only log in if you navigated to the site yourself

✘ Don't

  • Open an "invoice" ending in .exe, .js or .html
  • Download via ads
  • Pay at a shop you haven't checked
  • Enter passwords after clicking through from an email
Did you know?

Your password manager is an extra alarm bell: if it doesn't automatically fill in your password on a familiar site, you're probably on a fake domain.

Browser hygiene

  • Keep your browser up to date and use one as your default.
  • Install as few extensions as possible, and only from the official store.
  • Don't let your browser save passwords; your password manager does that better.
  • Public wifi? Use a VPN or your phone's hotspot.

Clicked something wrong anyway?

Close the page, change any passwords you used, and report it immediately to your IT administrator or Tip ICT. Reporting quickly limits the damage — staying quiet makes it worse.

Test yourself

Question 1 · self-test

You search for 'download Adobe Reader'. At the top of the results is an ad with a download link. What do you do?

Question 2 · self-test

A padlock (https) in the address bar means the website is trustworthy.

Question 3 · food for thought

How many browser extensions do you have installed — and do you know what each one is allowed to read along with?

Question 4 · self-test

A pop-up says: 'Your computer is infected! Call this number immediately.' What do you do?

Question 5 · self-test

Your browser warns that a website is unsafe, but you really need the site. What do you do?

Question 6 · food for thought

Do you use the same accounts and passwords on your personal laptop as at work — and what does that mean if that laptop gets infected?

Learn more

Want to enforce safe browsing with technology (DNS filtering, policy)?

Get in touch