Coconut Security Essentials

Security is part of doing the job well.

Every Coconut virtual professional is trusted with someone's inbox, accounts and customer data. Protecting that access is not an IT chore. It is the job. This page is the short version: five minutes to read, and yours to keep.

9
Core topics
5 min
This page
30 min
The course
Day 1
Then regularly

Why this exists

A virtual professional holds real keys.

Remote work means the door to a client's business is a login on your laptop. That is a lot of trust, and it is why a few simple habits matter more here than almost anywhere else.

The access you hold

Inboxes, CRMs, social accounts, payment dashboards, customer lists. One account of yours can reach every one of them.

Attacks are fast and ordinary

Almost none of them look like hacking. They look like a normal message on a busy day, asking for one small thing, right now.

You are the control that works

Tools filter a lot, but the last check is always a person deciding whether to click, send or approve. That person is you.

The whole picture

Nine things every Coconut VA should know

These are the nine topics the course walks through, one step at a time. Here they are in summary, if reading is all you need today.

1

Phishing, smishing & vishing

Fake messages by email, SMS or phone call, built to make you hand something over.

  • Urgency and fear are the tell, not bad spelling
  • Hover a link and read the real domain before clicking
  • No real IT team, bank or client ever asks for your code
2

Impersonation & urgent requests

Someone posing as your client, your manager or a vendor to move money or data.

  • Authority plus urgency plus secrecy means stop and verify
  • New bank details always get confirmed on a known number
  • Verify on a channel the message did not come from
3

Passwords, 2FA & access

One reused password is the difference between one bad day and every account falling.

  • Long and unique beats short and clever
  • A password manager, never a notes file or a spreadsheet
  • Two-factor on everything, and never read a code aloud
4

Devices, browsers & downloads

Your work machine is a client's office. Anyone at that machine is inside it.

  • Lock the screen, even for a minute, even at home
  • Keep the OS, browser and extensions updated
  • "Install this plugin to continue" is never true
5

Malware & ransomware

The program that should not be running, and the version of it that locks the files.

  • Your access is its access, including shared drives
  • If files start renaming themselves, disconnect first
  • Nobody pays anything, and nobody decides alone
6

Client data & confidentiality

Customer lists, invoices and personal details belong to the client, wherever they sit.

  • Collect and keep only what the work needs
  • Never move client data to a personal account or drive
  • Named access on a need-to-know basis, not shared logins
7

Working safely with AI

The tool is not the risk. What gets pasted into it is.

  • Treat the chat box like a public website
  • Ask about the shape of the task, not the real record
  • Approved tools only, and check before trying a new one
8

Payments & card details

When money is involved the rules get simpler and a lot stricter.

  • Card numbers never rest with a person
  • A change of bank details is confirmed by voice
  • Gift cards and crypto are not business payments
9

Spotting trouble & speaking up

Almost every incident was visible before it was obvious.

  • Know the signals: odd logins, resets, mail rules, sent items
  • Review connected apps and active sessions periodically
  • Report in minutes, not tomorrow. That is the whole job

Keep this part

The ground rules

If you remember nothing else from this page, remember these twelve.

  • Slow down when a message is urgent. Urgency is the most common tool in every attack. A real emergency survives a two-minute check.

  • Verify on a different channel. If the request came by email, confirm by a call or a chat you already use. Never with the contact details inside the message.

  • Never share a password or a 2FA code. Not with IT, not with a client, not with a colleague. There is no legitimate reason for the request.

  • Read the domain before you click. Hover the link, look at what comes just before the first slash, and type the address yourself when in doubt.

  • Use a password manager, one password per account. Long and unique. No spreadsheets, no notes app, no reusing the good one.

  • Turn on two-factor everywhere it is offered. Especially email, because email resets everything else.

  • Lock your screen and keep your machine updated. Every time you step away, including at home. Updates are the cheapest protection there is.

  • Install nothing that a web page told you to install. Extensions, plugins, "required security updates", codecs. Approved software only.

  • Ask AI about the shape of the task, not the real record. Strip out names, numbers, contracts and credentials before you paste. The draft comes out just as good.

  • Card details never rest with you, and bank changes are confirmed by voice. Not in chat, not in a screenshot, not "just until it clears". A supplier updating their account gets a phone call first.

  • Keep client data in client systems. No personal drives, no personal email, no pasting confidential material into unapproved AI tools.

  • Report immediately, even if you think you caused it. Speed is what limits the damage. Nobody at Coconut is punished for reporting fast.

Pattern recognition

Red flags, at a glance

Any one of these deserves a pause. Two together deserve a verification call.

"Act now" or a countdown to something bad
"Keep this between us" or "don't tell the team"
A request to skip the usual process or approval
New bank details, or a change to where money goes
Gift cards, crypto, or an unusual payment method
Anyone asking for a password or a 2FA code
A familiar name writing from an unfamiliar address
A domain that is almost right: rn for m, 0 for o
A move to WhatsApp, SMS or a personal number
An attachment or link you were not expecting
A login page that appeared after a redirect
A site telling you to install something to continue

When it happens

If something goes wrong

Clicking a bad link is not a character flaw. It happens to careful people on busy days. What matters is the next fifteen minutes.

1

Stop

Close the page. Send nothing else, approve nothing else, and do not try to "fix it quietly" first.

2

Secure

Change the password on the affected account, sign out of all active sessions, and reset two-factor.

3

Report

Tell your Coconut contact right away, and the client if their accounts are involved. Minutes matter far more than a polished explanation.

4

Preserve

Keep the message, the link and the timestamps. Screenshot before deleting anything. That record is what makes the cleanup possible.

Reporting early is always the right call.

An account secured in ten minutes is an incident. The same account left quiet until tomorrow is a breach. Coconut treats a fast report as someone doing their job properly, and that will not change.

Practice, don't just read

Nine steps. About thirty minutes.

The course takes the same nine topics and puts you inside them: the suspicious email, the urgent chat, the prompt with too much in it. The habit is already there when it counts.