Cyber Guardians Internship (Jun ’26) | Session 4 – Email Security
By SAS Foundation
A student receives an email.
It looks legitimate.
The school logo is familiar. The subject line says: Urgent Fee Confirmation Required. There is a link waiting to be clicked.
Nothing appears unusual.
But behind that single click could be identity theft, stolen credentials, malware infection, or unauthorized access to an entire digital ecosystem.
This is not a futuristic scenario.
It is happening every day.
And that is exactly why Session 4 of the Cyber Guardians Internship (Jun ’26), conducted by SAS Foundation, focused on one of the most important yet underestimated aspects of cyber awareness—Email Security.
Because in today’s connected world, cyber security is no longer only an IT topic.
It is a life skill.
The Invisible Front Door to Our Digital Lives
For most people, email is simply a communication tool.
For cyber attackers, it is often the preferred entry point.
Students today use email to access:
- Educational platforms
- Cloud storage
- Social media accounts
- Banking notifications
- Government services
- Career opportunities
- Online communities
Email has evolved into something much larger.
It has become our digital identity passport.
Compromise an email account, and attackers may gain access to an entire connected ecosystem.
That realization became one of the most powerful learning moments during this session.
Safe Browsing Is the First Layer of Cyber Defence
Before moving into email security, participants revisited concepts from the previous module on safe browsing.
Students explored an important distinction:
Browsing is intentional. Surfing is random.
That difference matters.
Responsible digital users do not move online blindly—they evaluate, verify, and make conscious decisions.
Key concepts reinforced included:
- Looking for HTTPS-secured websites
- Identifying trusted domains
- Recognizing suspicious website behavior
- Understanding browser privacy practices
- Clearing browser cache responsibly
- Avoiding credential storage on public devices
- Building secure browsing habits
The message was clear:
Security does not begin after an attack.
Security begins before the click.
Spam vs Phishing: Similar Appearance, Different Intent
One of the most eye-opening discussions during the session focused on understanding the difference between spam and phishing.
Spam emails are generally unsolicited communications intended to attract attention or promote content.
Phishing emails are far more dangerous.
Their objective is deception.
Attackers design phishing emails to imitate trusted institutions and manipulate emotions to obtain:
- Passwords
- Financial information
- Account access
- Personal details
- Device permissions
Students learned how cybercriminals exploit urgency and trust to trigger impulsive decisions.
The Psychology Behind Modern Phishing Attacks
Cyber attacks are increasingly becoming human attacks.
Most successful phishing attempts do not rely on advanced technology.
They rely on emotions.
Students explored how attackers commonly use:
Fear
“Your account will be suspended.”
Urgency
“Verify within 24 hours.”
Curiosity
“See your confidential result.”
Trust
Messages appearing from known organizations.
Excitement
“You have won a reward.”
Understanding this psychological layer helped students realize that cyber awareness is not just technical knowledge—it is decision-making intelligence.
Red Flags Every Student Must Learn to Recognize
During the session, participants practiced identifying indicators of suspicious emails.
Key warning signs included:
✓ Generic greetings such as “Dear User”
✓ Mismatched sender domains
✓ Unexpected attachments
✓ Urgent language and threats
✓ Poor grammar and formatting
✓ Missing organizational information
✓ Suspicious hyperlinks
Students also learned the importance of hovering over links before interacting.
One simple habit.
One powerful layer of protection.
Malware Often Arrives Disguised
Another major discussion focused on malicious attachments.
Files may appear harmless but hide dangerous executable actions.
Examples demonstrated included misleading naming patterns and disguised documents.
Students learned:
- To avoid opening unexpected attachments
- To inspect file types carefully
- To question unfamiliar senders
- To avoid reacting emotionally to messages
This created an important mindset shift:
Trust should be verified—not assumed.
Building Strong Digital Habits Before Incidents Happen
Technology alone cannot secure users.
Human behavior remains the strongest security layer.
Students explored practical protective measures including:
Enable Two-Factor Authentication
Adding an extra layer beyond passwords.
Create Strong Passwords
Using complexity and uniqueness.
Update Applications Regularly
Reducing exposure to known vulnerabilities.
Use Security Tools Responsibly
Spam filters and antivirus solutions improve resilience.
Avoid Public Wi-Fi for Sensitive Activities
Especially while accessing email accounts.
These habits may seem small individually.
Together, they create digital resilience.
What To Do If You Clicked a Suspicious Email
One of the most practical parts of the session focused on response—not fear.
Students learned immediate actions:
- Disconnect internet access
- Stop further interaction
- Run a security scan
- Change passwords
- Inform parents or responsible authorities
- Report incidents through official channels
The objective was simple:
Prepared users recover faster.
Beyond Technology: Creating Responsible Digital Citizens
The most meaningful insight from the session was not about tools.
It was about responsibility.
Cyber security education should not aim to create fear.
It should create confidence.
Students who understand risks become:
- More informed learners
- More responsible citizens
- Better digital decision-makers
- Future leaders of safe technology ecosystems
At SAS Foundation, we believe youth empowerment must include digital empowerment.
Because tomorrow’s innovators must also become tomorrow’s protectors.
Assignment Challenge: From Learners to Awareness Leaders
Students concluded the session with a practical challenge:
Create a phishing awareness campaign and draft an educational email that helps others recognize cyber threats.
The goal was not only to learn.
The goal was to teach.
Because awareness multiplies when shared.
Final Reflection
Every inbox tells a story.
Some messages open opportunities.
Others test awareness.
The difference often comes down to one decision.
Pause.
Verify.
Think.
Because the safest click may sometimes be the one you never make.
Join us as we continue empowering youth with future-ready skills through the Cyber Guardians Internship.
Become a member. Join hands with SAS Foundation and help create a safer, smarter, and more resilient digital future.







