alphaPlan · Workshop pilot
Verify before you trust
A 90-minute practical workshop on suspicious messages, identity verification and decisions under pressure.
Audience
- • Secondary-school learners, community groups and workplace teams. No technical background required.
Prerequisites
- • None
Outcomes
- • Identify several signals in a suspicious request
- • Choose a separate, trusted verification channel
- • Explain and revise a decision under pressure
Prepare
- • Open the linked lesson and supplied suspicious-message activity
- • Print one learner sheet per participant and one set of three pressure cards per three teams
- • Use the supplied fictional message; local adaptation is optional and must remain clearly fictional
Materials
- • Printed learner sheets, scenario, pressure cards and facilitator notes
- • Pens or markers
- • Optional projector or shared screen for the digital activity
Group logistics
- • Use teams of 3 to 5. With 4 people, form two pairs; with about 12, form three teams of four; with about 30, form six teams of five.
- • Give cards 1, 2 and 3 to teams in rotation. Repeat cards when there are more than three teams. With one to three people, work individually or as one small team and test more than one card.
- • In the whole-group debrief, give each team 30 seconds to state its reusable rule and one changed decision. Compare different responses to repeated cards instead of reading every worksheet entry.
No-internet or no-projector fallback
- • Internet and projection are optional. If either fails, continue the core workshop with the printed learner sheets, supplied scenario, pressure cards and facilitator notes.
- • Skip the optional video and digital links. The printed pack contains the decisions, clues, complications and debrief needed to meet the same outcomes.
Supplied fictional message
- From
- Shërbimi i Llogarive <ndihma@hyrje-sigurt.example>
- Subject
- Urgent: confirm your account before 18:00
Hello,
We detected an unusual sign-in to your account. Access will be suspended today unless you confirm your identity.
Open the link below and enter your password and the one-time code sent to your phone.
hyrje-sigurt.example/konfirmo
Account support team
Fictional educational message. It does not represent a real Albanian institution, address or service.
Facilitation plan
01Pause before deciding
10 min · groupGive every participant the supplied fictional message and learner sheet. Everyone records an initial decision before discussion. If participants identify phishing immediately, pivot from naming it to asking which clues raise suspicion, what they do not prove, which action stays safe if the suspicion is wrong and how urgency, authority or a live caller changes the pressure.
Listen for: Expect mixed decisions. Do not correct them yet; ask which clue or assumption supports each decision. Fast recognition is only the start: learners must separate warning signs from conclusive proof and name an independent verification channel.Transition: Say: ‘We have decisions. Now let us test the evidence before defending them.’
02How manipulation works
15 min · explanationTeach only four essentials: urgency or authority creates pressure; the request asks for a secret or risky action; a contact channel supplied by the request is not independent; and a clue raises concern but does not prove identity or fraud. Use no more than five minutes to explain them. Skip channel-name history and an exhaustive red-flag lecture. Use the remaining time to ask what is still unproven and which action remains safe if suspicion is wrong.
Open shared materialhttps://codeforalbania.com/en/learn/cybersecurity/04-social-engineering/phishing-smishing-vishing
Listen for: Before moving on, learners should distinguish a warning sign from conclusive proof and explain why independent verification is safe under uncertainty.Transition: Say: ‘A clue changes our confidence. Let us inspect several clues together.’
03Inspect the evidence
20 min · pairsPairs complete the evidence map on the supplied worksheet or use the digital activity. For every clue, they record what it suggests and what it does not prove.
Open shared materialhttps://codeforalbania.com/en/learn/cybersecurity/04-social-engineering/phishing-smishing-vishing
Listen for: Strong responses identify pressure, a request for secrets, a supplied link and a process bypass without relying on spelling alone.Transition: Say: ‘Evidence tells us to verify. It does not tell us to trust the channel offered by the message.’
04Build a verification route
15 min · groupEach team chooses a separate channel known before the message arrived and writes the exact words it would use to verify the request.
Listen for: The plan should refuse the supplied link and secrets, name a saved bookmark, official app or previously known number, and ask whether the warning was genuinely issued.Transition: Say: ‘A good rule must survive pressure, so now the situation will become harder.’
05Pressure test
20 min · groupGive each team one supplied complication card. Teams revise the details of their plan without abandoning independent verification.
Listen for: The exact route may change, but participants should still pause, protect secrets and use contact details independent of the request.Transition: Say: ‘Keep the part of your rule that survived every complication.’
06Make the rule reusable
10 min · debriefEach team states one rule it can use tomorrow and one situation where the rule needs adaptation. Compare it with the supplied strong verification example.
Listen for: A reusable rule contains three ideas: pause, protect secrets, verify through a route the request did not provide.
Pressure-test cards
Complication 1
A caller says they are the sender and asks you to read the one-time code aloud.
Complication 2
The message appears to be forwarded by your manager with: ‘Please do this now.’
Complication 3
A second message says the deadline is now ten minutes away.
Participant decision sheet
For each moment, record the evidence, your decision, the strongest objection and what would change your mind.
Facilitator debrief
- • Which clue changed your decision?
- • What made your verification channel trustworthy?
- • What would make this rule fail in real life?
Strong verification example: I will not use the link or share a code. I will open the service from my saved bookmark or call the published number I already know and ask: ‘Was this account warning sent by you?’
Pilot status: run this workshop, record actual timing and report unclear instructions before calling it workshop-ready.
shënim: ky material u krijua në kuadër të projektit 'U.S. Cybersecurity Leadership in AI for Albania', financuar nga departamenti i shtetit i shteteve të bashkuara. mendimet, gjetjet dhe përfundimet e paraqitura këtu janë të autorit(ëve) dhe nuk pasqyrojnë domosdoshmërisht ato të departamentit të shtetit të shteteve të bashkuara.
Disclaimer: This material was created on behalf of the 'U.S. Cybersecurity Leadership in AI for Albania' project, funded by the United States Department of State. The opinions, findings, and conclusions stated herein are those of the author(s) and do not necessarily reflect those of the United States Department of State.
DisclaimerFound something unclear, outdated or improvable? Suggest an improvement