How to Protect Your Business From Phishing Attacks

August 21, 2026

Article by Krystal

Phishing attacks do not always look suspicious. A fraudulent email may appear to come from a supplier you know. A message might look like a Microsoft 365 password warning. An employee could receive what appears to be an urgent request from a senior manager asking them to make a payment. That is what makes phishing […]

Phishing attacks do not always look suspicious.

A fraudulent email may appear to come from a supplier you know.

A message might look like a Microsoft 365 password warning.

An employee could receive what appears to be an urgent request from a senior manager asking them to make a payment.

That is what makes phishing so effective.

Instead of attacking technology directly, phishing often targets the person using it.

For businesses, reducing the risk therefore requires more than installing security software.

Technical controls matter, but employees also need to know what suspicious messages look like, when to verify a request and how to report something that does not seem right.

What Is a Phishing Attack?

Phishing is a form of social engineering in which an attacker attempts to persuade someone to reveal information or take an action that benefits the attacker.

That action might involve:

  • Entering login details into a fake website
  • Opening a malicious attachment
  • Making a fraudulent payment
  • Sharing confidential information
  • Approving an unexpected authentication request

Phishing can arrive through email, text messages, social platforms, collaboration tools or other communication channels.

Email remains one of the most familiar forms.

Phishing Is Designed to Look Legitimate

A badly written message from an obviously fake sender is easy to ignore.

Modern phishing attempts can be much more convincing.

Attackers may copy:

  • Company branding
  • Email signatures
  • Supplier names
  • Login pages
  • Invoice formats
  • Familiar business language

They may also use information publicly available online to make the message feel more credible.

That is why staff should not rely only on spelling mistakes or poor design when deciding whether a message is genuine.

Spear Phishing Is More Targeted

Spear phishing focuses on a specific person or organisation.

The attacker may research:

  • Employee names
  • Job titles
  • Suppliers
  • Executives
  • Current projects

A finance employee, for example, could receive a message apparently from the managing director requesting an urgent transfer.

Because the message contains familiar names and business context, it can be more convincing than a generic phishing email.

Business Email Compromise Can Be Expensive

Business email compromise, often shortened to BEC, is particularly dangerous because it targets financial and operational processes.

An attacker may impersonate:

  • An executive
  • Supplier
  • Customer
  • Employee

They may request:

  • Changes to banking details
  • Urgent payments
  • Confidential documents
  • Payroll changes

These attacks may involve compromised email accounts or carefully created lookalike addresses.

The strongest defence is often a combination of email security and strict verification procedures.

Invoice Fraud Deserves Particular Attention

A common scenario involves a message claiming that a supplier's banking details have changed.

The email may appear perfectly normal.

If the business updates the bank details and pays the next invoice, the money may go directly to the attacker.

Banking-detail changes should therefore never be approved based only on an email.

Use a separate trusted communication method to verify the request.

Verify Payment Changes Independently

If a supplier sends new banking information, contact them using details you already know to be genuine.

Do not simply phone the number contained in the suspicious email.

Use:

  • A previously verified phone number
  • An established contact
  • An existing supplier record

This breaks the attacker's control over the communication.

A short verification call can prevent a very expensive mistake.

Urgency Is a Common Warning Sign

Phishing messages frequently create pressure.

Examples include:

  • Pay this immediately.
  • Your account will be closed today.
  • Confirm your password now.
  • I need these documents urgently.
  • Do not call me because I am in a meeting.

Urgency reduces the time people spend thinking.

Employees should be encouraged to slow down when a request involves money, passwords or sensitive information.

A genuine urgent request can usually survive a brief verification step.

Fear Can Be Used Too

Some phishing messages try to frighten recipients.

They may claim:

  • Your account has been compromised.
  • Your email will be suspended.
  • You have failed a security check.
  • A payment has been rejected.

The natural reaction is to click quickly.

Instead, open the relevant service through a known bookmark or official application rather than following the link in the message.

Check the Sender Carefully

Attackers may use email addresses that look almost correct.

For example:

accounts@company.co.za

might be imitated as:

accounts@cornpany.co.za

The difference can be easy to miss.

Employees should check the actual sender address rather than relying only on the display name.

A familiar name does not guarantee that the message came from the person shown.

Lookalike Domains Can Be Convincing

Attackers sometimes register domains closely resembling legitimate company domains.

Differences may involve:

  • Additional letters
  • Missing letters
  • Different domain endings
  • Similar-looking characters

Businesses should train employees to inspect domains carefully when dealing with sensitive requests.

Technical email protections can also help identify suspicious sender behaviour.

Be Careful With Links

A link can display one address while directing users somewhere else.

Before clicking, employees should consider:

  • Was I expecting this?
  • Does the domain look correct?
  • Why am I being asked to log in?
  • Can I reach the same service another way?

Where possible, access important services directly rather than through unexpected email links.

Fake Login Pages Are Common

A phishing email may direct someone to a login page that closely resembles:

  • Microsoft 365
  • Google Workspace
  • Banking services
  • Cloud storage
  • Payroll systems

The victim enters their username and password.

The attacker captures those details.

The page may then redirect the person to the legitimate website, making the incident less obvious.

This is why the domain in the address bar matters.

Use Multi-Factor Authentication

Multi-factor authentication, or MFA, adds another requirement beyond the password.

Depending on the system, the second factor might involve:

  • An authenticator application
  • Security key
  • Device confirmation
  • One-time code

MFA can significantly reduce the usefulness of stolen passwords.

It does not eliminate phishing risk, however.

Some attacks attempt to capture session information or trick users into approving fraudulent authentication requests.

Prefer Stronger Authentication Methods Where Available

Not all MFA methods provide the same protection.

Businesses should use stronger phishing-resistant authentication methods where practical and supported by their systems.

Security keys and passkey-based approaches can provide stronger resistance against certain credential phishing attacks than basic one-time codes.

The appropriate approach depends on the organisation's systems, users and risk profile.

Never Approve Unexpected MFA Requests

Some attackers use stolen passwords to repeatedly trigger authentication prompts.

The victim may eventually approve one simply to stop the notifications.

Employees should be trained never to approve an MFA request they did not initiate.

Unexpected prompts should be treated as a potential security incident and reported.

Use Strong, Unique Passwords

Employees should not reuse the same password across several business and personal services.

If one unrelated service is compromised, reused credentials may give attackers access elsewhere.

A password manager can help users create and store unique passwords.

The business should choose an appropriate password-management system and establish clear policies around its use.

Password Managers Can Reduce Phishing Risk

Password managers offer another useful benefit.

A properly configured manager generally associates saved credentials with a specific domain.

If an employee visits a fake login site, the password manager may not automatically offer the saved credentials.

That can provide an additional warning that the page is not the genuine service.

Employees should still check domains carefully.

Protect Administrator Accounts

Administrator accounts can provide attackers with substantial access.

Reduce unnecessary exposure by:

  • Limiting administrator privileges
  • Using separate administrative accounts
  • Applying strong MFA
  • Monitoring unusual access

Employees should generally receive only the access required for their responsibilities.

A compromised ordinary user account is serious.

A compromised global administrator account can be much worse.

Apply the Principle of Least Privilege

Not every employee needs access to every system or file.

Limiting permissions reduces what an attacker can reach if an account is compromised.

Review:

  • Shared folders
  • Financial systems
  • Customer data
  • Administration tools

Access should change when people's roles change.

Employees who leave the organisation should have access removed promptly.

Train Employees Regularly

Staff awareness training is one of the most important parts of phishing prevention.

Training should cover practical scenarios rather than only definitions.

Employees should learn to recognise:

  • Suspicious links
  • Fake login pages
  • Urgent payment requests
  • Unexpected attachments
  • Lookalike domains
  • MFA fatigue attacks

Training should also explain exactly what employees should do when they are uncertain.

Avoid Making Training a Once-a-Year Exercise

People forget.

Threats also change.

Short, regular security reminders can be more useful than one lengthy annual session that employees immediately put out of mind.

Cybersecurity awareness can form part of:

  • Staff onboarding
  • Regular team communication
  • Refresher training
  • Security testing

The objective is to create consistent habits.

Phishing Simulations Can Be Useful

Some businesses conduct controlled phishing simulations to assess staff awareness.

These can help identify:

  • Common mistakes
  • Departments needing additional training
  • Types of messages employees find convincing

Simulations should be used as training tools rather than opportunities to embarrass employees.

A culture where people are afraid to admit a mistake can delay incident reporting.

Make Reporting Easy

Employees should know exactly how to report a suspicious message.

That may involve:

  • A dedicated phishing-report button
  • IT help desk
  • Security email address
  • Internal reporting channel

The process should be simple.

If reporting requires a complicated form and several approvals, employees may simply delete the message and move on.

Security teams lose the opportunity to investigate a wider attack.

Encourage Fast Reporting After Mistakes

An employee who realises they clicked a suspicious link may hesitate because they are embarrassed.

That delay can make the incident worse.

Businesses should make it clear that rapid reporting matters more than hiding the mistake.

If security staff know quickly, they may be able to:

  • Reset credentials
  • Revoke sessions
  • Block domains
  • Check account activity

Minutes can matter.

Never Punish Good-Faith Reporting

If employees believe that reporting a mistaken click will automatically lead to punishment, they may remain silent.

That creates greater risk.

There is a difference between repeated disregard for security procedures and someone promptly reporting a genuine mistake.

The reporting culture should support early intervention.

Use Email Filtering

Modern email security systems can identify and block many malicious messages before they reach employees.

Depending on the system, controls may detect:

  • Known malicious links
  • Dangerous attachments
  • Spoofed senders
  • Suspicious domains
  • Malware

No filtering system catches everything.

Technical controls should reduce the volume of dangerous email that employees need to evaluate, not create a false belief that everything reaching the inbox is safe.

Configure Domain Authentication

Businesses should configure appropriate email authentication standards for their own domains.

Common technologies include:

  • SPF
  • DKIM
  • DMARC

These can help receiving mail systems evaluate whether messages claiming to come from a domain are authorised.

Configuration needs to be performed carefully because incorrect settings can affect legitimate email delivery.

Use qualified technical support where required.

DMARC Can Help Reduce Domain Spoofing

DMARC can help domain owners specify how receiving systems should handle email that fails authentication checks.

It also provides reporting that can help organisations understand how their domains are being used.

A staged implementation is often sensible.

Businesses should avoid applying restrictive policies before confirming that legitimate email systems are configured correctly.

Keep Software Updated

Phishing may begin with a deceptive email but end by exploiting outdated software.

Keep operating systems, browsers, office applications and other software patched.

Updates can close known vulnerabilities attackers may otherwise exploit through:

  • Attachments
  • Malicious websites
  • Document files

Where practical, businesses should use managed update processes rather than relying entirely on individual employees.

Restrict Dangerous Attachments

Businesses can reduce risk by controlling which file types employees can receive or execute.

Particularly risky files may include:

  • Executables
  • Scripts
  • Macro-enabled documents

The appropriate restrictions depend on business requirements.

Employees should be cautious with unexpected attachments even when the sender appears familiar.

Compromised accounts can send malicious files from genuine addresses.

Treat Unexpected Documents Carefully

An invoice, CV or shared document may look ordinary.

Ask:

  • Was I expecting this file?
  • Does the sender normally send this type of document?
  • Is the message context sensible?

If something seems unusual, verify it through another channel before opening the file.

Disable Unnecessary Macros

Malicious document macros have historically been used to deliver malware.

Businesses that do not rely on macros should consider restricting them according to the capabilities of their office software and security environment.

Where macros are genuinely required, use appropriate controls.

Security configuration should reflect actual business needs rather than enabling risky functionality by default.

Protect Financial Processes

Finance departments are frequent phishing targets because they can authorise payments.

Strong financial controls might include:

  • Dual approval
  • Payment limits
  • Independent verification
  • Supplier-change procedures
  • Separation of duties

An attacker should not be able to move a large amount of money simply by convincing one employee through email.

Use Dual Approval for Significant Payments

Requiring two authorised people to approve significant transfers can reduce fraud risk.

The exact threshold should reflect the organisation's size and transaction patterns.

The purpose is not to slow ordinary business unnecessarily.

It is to prevent one compromised account or manipulated employee from becoming a single point of failure.

Verify Unusual Executive Requests

Attackers often exploit hierarchy.

An employee may feel uncomfortable questioning a request that appears to come from a director.

Leadership should make it clear that employees are expected to verify unusual financial or sensitive requests.

A genuine executive should prefer a short delay over an avoidable fraudulent transfer.

Establish a Known Verification Process

Businesses can reduce uncertainty by defining in advance how unusual requests are verified.

For example:

Banking changes require verbal confirmation through an existing trusted number.

or:

Payments above a defined amount require two approvals.

Clear procedures remove the need for employees to invent a security decision under pressure.

Protect Payroll Processes

Payroll changes can also be targeted.

An attacker may impersonate an employee and request that their salary be paid into a new account.

Treat bank-detail changes carefully.

Use established identity-verification procedures before changing payment information.

Be Careful With Shared Mailboxes

Shared accounts such as:

  • accounts@
  • finance@
  • admin@
  • info@

may receive large volumes of messages and attachments.

They can also be valuable targets.

Apply appropriate access controls and MFA to the underlying accounts.

Review who genuinely needs access.

Monitor Suspicious Login Activity

Security systems may provide information about:

  • Unusual locations
  • New devices
  • Repeated failed logins
  • Impossible travel
  • Suspicious sign-in patterns

Monitoring can help identify compromised accounts even when the original phishing attempt was not reported.

Alerts need appropriate investigation rather than simply being generated and ignored.

Log Important Security Events

Businesses need enough logging to investigate incidents.

Relevant logs may include:

  • Authentication
  • Email
  • Administrative activity
  • Endpoint security

Retention periods should reflect business, legal and security requirements.

Without logs, determining what an attacker accessed can become much more difficult.

Protect Endpoints

Endpoint security tools can provide additional protection on laptops and desktops.

Depending on the solution, they may detect:

  • Malware
  • Suspicious processes
  • Dangerous files
  • Unusual behaviour

Endpoint protection should be centrally managed where appropriate.

It works alongside email protection, authentication and employee awareness.

Keep Business and Personal Accounts Separate

Employees should avoid using business email addresses and passwords for unrelated personal services.

Mixing personal and company accounts increases exposure.

The organisation also has less control over the security of external consumer platforms.

Clear boundaries make access management easier.

Secure Remote Workers

Employees working from home or travelling remain phishing targets.

Remote-working security should consider:

  • Managed devices
  • Secure authentication
  • VPN use where appropriate
  • Software updates
  • Public Wi-Fi risks
  • Secure collaboration tools

Remote employees should have the same clear phishing-reporting process as people working from the office.

Mobile Devices Need Protection Too

Phishing messages are often harder to inspect on phones because:

  • Sender details may be less visible
  • URLs can be truncated
  • Users may act quickly

Employees should be particularly cautious before entering passwords after following a link from an email or text message on mobile.

Business devices should also use appropriate device-management and security controls.

SMS Phishing Is Also a Risk

Phishing through SMS is often called smishing.

A message might claim to come from:

  • A bank
  • Courier
  • Mobile network
  • Government service

It may include a link asking the recipient to verify information or make a payment.

Employees should understand that company security awareness extends beyond email.

Voice Phishing Exists Too

Attackers may also phone employees.

This is sometimes referred to as vishing.

They may pretend to be:

  • IT support
  • Bank staff
  • Executives
  • Suppliers

The caller may ask for passwords, authentication codes or payment assistance.

Legitimate support staff should not need employees to disclose passwords.

Never Share Authentication Codes

One-time authentication codes should be treated as sensitive.

Employees should not provide them to someone who:

  • Emails
  • Calls
  • Sends a message

and asks for the code.

If someone is requesting an MFA code, they may already have the victim's password.

Public Information Can Help Attackers

Attackers can research organisations through:

  • Company websites
  • LinkedIn
  • Social media
  • Press releases

They may learn:

  • Who works in finance
  • Who the CEO is
  • Which suppliers the business uses
  • Who is travelling

Businesses do not need to remove all public information.

They should recognise that attackers may use it to make phishing messages more believable.

Be Careful With Out-of-Office Messages

An automatic reply may reveal:

  • Employee absence
  • Travel dates
  • Alternative contacts
  • Management structures

Keep external out-of-office messages concise.

Avoid providing more information than the sender genuinely needs.

Backups Still Matter

A phishing attack can sometimes result in malware or ransomware.

Reliable backups can help the business recover from certain incidents.

Good backups should be:

  • Regular
  • Tested
  • Protected
  • Separated appropriately from production systems

A backup that has never been tested should not automatically be assumed to be recoverable.

Have an Incident Response Plan

The business should know what happens if phishing succeeds.

A response plan may include procedures to:

  • Disable compromised accounts
  • Reset credentials
  • Revoke active sessions
  • Investigate email rules
  • Check payment activity
  • Notify relevant parties
  • Restore systems

Roles should be defined before the emergency occurs.

Know Who to Call

Employees and managers should know which internal or external specialists handle cyber incidents.

This might include:

  • IT team
  • Managed service provider
  • Cybersecurity provider
  • Insurer
  • Legal advisers

Keep essential contact information somewhere accessible even if normal email systems become unavailable.

Cyber Insurance May Help, but It Is Not a Substitute for Security

Cyber insurance may provide financial support or access to incident-response services for certain covered events.

Policies can contain security requirements.

The existence of insurance does not remove the need for:

  • MFA
  • Backups
  • Training
  • Access controls
  • Security monitoring

Businesses should understand policy conditions and exclusions before an incident occurs.

What Should You Do After Clicking a Phishing Link?

If an employee realises they clicked a suspicious link, they should follow the organisation's incident procedure immediately.

Depending on what occurred, the security team may need to:

  • Investigate the device
  • Reset credentials
  • Revoke sessions
  • Check login activity
  • Block the malicious site

Employees should not simply close the browser and assume the problem has disappeared.

What If You Entered Your Password?

Report it immediately.

The account may need its credentials changed and active sessions terminated.

If the same password was reused elsewhere, those accounts may also be at risk.

Security staff should investigate whether the attacker successfully logged in or changed account settings.

Check for Malicious Email Rules

After compromising an email account, attackers may create forwarding or inbox rules designed to hide messages.

For example, they may automatically move replies from suppliers into another folder.

This allows fraud to continue without the account owner noticing.

After an email compromise, administrators should review forwarding settings and unusual inbox rules.

Review Financial Activity Quickly

If a phishing incident involved finance or supplier information, contact the appropriate financial institutions and affected parties promptly.

Fraudulent payments can become harder to recover as time passes.

Do not rely on email alone when contacting a supplier whose account may itself have been compromised.

Review What Happened

After an incident or near miss, examine how it occurred.

Ask:

  • What made the message convincing?
  • Which control failed?
  • Was the procedure unclear?
  • Was MFA present?
  • Did staff know how to report it?

The objective is to reduce the likelihood of the same attack working again.

Don't Assume Small Businesses Are Too Small to Target

Attackers do not need to spend weeks researching every victim.

Automation allows criminals to target large numbers of businesses.

Smaller organisations may also have:

  • Weaker controls
  • Fewer security staff
  • Less formal payment procedures

That can make them attractive targets.

Cybersecurity should be proportionate to risk, but size is not protection.

Create a Simple Anti-Phishing Checklist

Employees should know to pause when a message:

  • Creates unusual urgency
  • Requests passwords
  • Requests authentication codes
  • Changes payment details
  • Contains an unexpected attachment
  • Sends them to a login page
  • Comes from a slightly unusual address

When in doubt, verify through a trusted separate channel.

Final Thoughts

Protecting a business from phishing attacks requires both technology and process.

Email filtering, multi-factor authentication, password management, software updates and access controls can make attacks harder to complete.

Staff training and business procedures are equally important.

Employees need to know when to question an unexpected message, how to verify payment changes and where to report suspicious activity.

Finance teams should have additional controls around supplier banking details, payroll changes and large payments.

Most importantly, reporting needs to happen quickly when something goes wrong.

A single mistaken click does not automatically become a major breach.

What happens next depends heavily on how quickly the business detects the incident, limits access and responds.

Phishing works by creating enough trust, pressure or confusion to make someone act before checking.

The strongest defence is a business where checking has become part of the normal way people work.