The 15-Second SIV Rule: Stop, Inspect, Verify Before You Act
Phishing and impersonation work best when they feel ordinary. The attempts that catch careful people are rarely the clumsy ones full of spelling mistakes. They are the messages, calls, and requests that arrive at exactly the right moment: when you are waiting for an invoice, expecting a delivery, running payroll, dealing with an official procedure, or trying to help a colleague before you leave for the day.
That timing is the whole trick. When a request lines up with something already on your mind, your brain treats it as expected and skips the questions it would normally ask. Attackers do not need to fool you for a long time. They need one automatic click, one quick reply, one code shared before you think. Their advantage is speed, and the defense is to take it away from them.
The 15-Second SIV Rule is built for that single moment of decision, the few seconds before you click a link, open an attachment, reply to an unexpected request, send money, or share a verification code. It does not ask you to become suspicious of everything. It asks you to insert a short, deliberate pause where an attacker wants an instant reaction.
Three steps, five seconds each
Stop — 5 seconds. Do not let urgency make the decision for you. Notice the pressure. If a message makes you feel rushed, worried, or eager to help immediately, that feeling is doing exactly what the sender intended. Naming it is often enough to break the spell.
Inspect — 5 seconds. Look at what is actually in front of you: the sender, the domain, the link, the attachment, the context, and the action being requested. You are not verifying yet, only reading closely enough to see whether anything is off.
Verify — 5 seconds. Decide how you will confirm the request through an independent, trusted channel. Not the phone number in the email. Not the link in the text. A route you choose yourself.
The verification itself will usually take longer than fifteen seconds, and that is fine. The pause is not the whole defense. Its only job is to interrupt the automatic reaction the scammer is trying to trigger, so the slower, more careful part of your judgment gets a chance to speak.
What "Inspect" really means
Five seconds is enough to catch what gives most attacks away, once you know where to look.
- Sender: a friendly display name means nothing on its own. Look at the real address or number behind it.
- Domain: read it character by character. Attackers rely on look-alikes and extra words, a swapped letter or an added hyphen you would normally skim past.
- Link: preview the real destination before you tap. The visible text and the actual address are often not the same.
- Attachment: ask whether a file was expected from this person, and whether the type makes sense. An unexpected invoice, receipt, or resume is a classic delivery method.
- Context: does the timing genuinely fit something you were already waiting for, or did the message itself plant that idea? Attackers manufacture the context as often as they exploit a real one.
- Action: what are you actually being asked to do? Money, credentials, a one-time code, or a change of bank details should raise the bar every time.
What "Verify" really means
Verification fails when you confirm a request using the same channel that delivered it. If the email is fake, the phone number in its signature is fake too. If the text is a scam, the link it offers leads exactly where the scammer wants.
An independent channel is one you reach on your own terms: a number you already have saved, a website you type yourself, a colleague you speak to directly. For anything involving money, access, or a code, treat a single message as a request, never as authorization. Payments, credential resets, and changes to payment details deserve confirmation through a second route before you act. If you cannot verify, the correct move is to not act, and to report it.
Where the rule earns its keep
The 15-Second SIV Rule matters most in the handful of moments attackers target on purpose: an invoice that needs paying, a delivery that needs rescheduling, a payroll or bank-detail change, an official-looking procedure with a deadline, a manager who needs a favor quickly, or any request for a verification code. These are the situations where the cost of one wrong reflex is highest, and where a fifteen-second pause is cheapest.
The SIV checklist
Keep this where you will see it, next to your screen or saved on your phone.
Stop
- Am I feeling rushed, worried, or eager to help? Name the feeling.
- Would waiting five minutes cause real harm? Almost always, no.
Inspect
- Is the display name backed by the real address or number?
- Read the domain slowly. Any look-alike letters or extra words?
- What is the link's actual destination?
- Was this attachment expected, and does the file type fit?
- Does the timing fit something I was already waiting for?
- Is the action money, credentials, a code, or a change of bank details?
Verify
- Confirm through a channel I already trust, not the one in the message.
- Never approve payments, share codes, or change payment details on a single message.
- If I cannot verify, I do not act. I report it.
Turning it into a habit
A rule you have read is not the same as a rule you will use under pressure. The pause has to be automatic by the time a real attempt lands, and the only way there is practice against realistic examples. Working through simulated phishing scenarios, ones that copy the tone and timing of the real thing, trains the reflex far better than a list of warning signs ever will. Our free phishing awareness simulator lets you do exactly that, and the full method behind the rule is laid out step by step in our anti-phishing workbook. [Insert links: CyberAwareness simulator + KDP workbook product page]
For a team, the same rule scales into a shared standard. When everyone knows the three steps and the checklist sits on the wall, a suspicious payment request stops being one person's judgment call and becomes a process the whole office follows. For organizations that want tracking, reporting, and their own branded scenarios, the enterprise version of our awareness training builds the SIV habit across every employee. [Insert link: CyberAwareness Pro / enterprise page]
The point of the pause
You will not out-think every attacker, and you do not need to. Most attempts succeed on speed alone, on the gap between the message landing and your reaction. Fifteen seconds closes that gap. Stop, Inspect, Verify, and the ordinary-looking request that would have caught you at the wrong moment gets the second look it deserves.
0 comments