Phishing attacks do not always look suspicious.
A fraudulent email may appear to come from a supplier you know.
A message might look like a Microsoft 365 password warning.
An employee could receive what appears to be an urgent request from a senior manager asking them to make a payment.
That is what makes phishing so effective.
Instead of attacking technology directly, phishing often targets the person using it.
For businesses, reducing the risk therefore requires more than installing security software.
Technical controls matter, but employees also need to know what suspicious messages look like, when to verify a request and how to report something that does not seem right.
What Is a Phishing Attack?
Phishing is a form of social engineering in which an attacker attempts to persuade someone to reveal information or take an action that benefits the attacker.
That action might involve:
- Entering login details into a fake website
- Opening a malicious attachment
- Making a fraudulent payment
- Sharing confidential information
- Approving an unexpected authentication request
Phishing can arrive through email, text messages, social platforms, collaboration tools or other communication channels.
Email remains one of the most familiar forms.
Phishing Is Designed to Look Legitimate
A badly written message from an obviously fake sender is easy to ignore.
Modern phishing attempts can be much more convincing.
Attackers may copy:
- Company branding
- Email signatures
- Supplier names
- Login pages
- Invoice formats
- Familiar business language
They may also use information publicly available online to make the message feel more credible.
That is why staff should not rely only on spelling mistakes or poor design when deciding whether a message is genuine.
Spear Phishing Is More Targeted
Spear phishing focuses on a specific person or organisation.
The attacker may research:
- Employee names
- Job titles
- Suppliers
- Executives
- Current projects
A finance employee, for example, could receive a message apparently from the managing director requesting an urgent transfer.
Because the message contains familiar names and business context, it can be more convincing than a generic phishing email.
Business Email Compromise Can Be Expensive
Business email compromise, often shortened to BEC, is particularly dangerous because it targets financial and operational processes.
An attacker may impersonate:
- An executive
- Supplier
- Customer
- Employee
They may request:
- Changes to banking details
- Urgent payments
- Confidential documents
- Payroll changes
These attacks may involve compromised email accounts or carefully created lookalike addresses.
The strongest defence is often a combination of email security and strict verification procedures.
Invoice Fraud Deserves Particular Attention
A common scenario involves a message claiming that a supplier's banking details have changed.
The email may appear perfectly normal.
If the business updates the bank details and pays the next invoice, the money may go directly to the attacker.
Banking-detail changes should therefore never be approved based only on an email.
Use a separate trusted communication method to verify the request.
Verify Payment Changes Independently
If a supplier sends new banking information, contact them using details you already know to be genuine.
Do not simply phone the number contained in the suspicious email.
Use:
- A previously verified phone number
- An established contact
- An existing supplier record
This breaks the attacker's control over the communication.
A short verification call can prevent a very expensive mistake.
Urgency Is a Common Warning Sign
Phishing messages frequently create pressure.
Examples include:
- Pay this immediately.
- Your account will be closed today.
- Confirm your password now.
- I need these documents urgently.
- Do not call me because I am in a meeting.
Urgency reduces the time people spend thinking.
Employees should be encouraged to slow down when a request involves money, passwords or sensitive information.
A genuine urgent request can usually survive a brief verification step.
Fear Can Be Used Too
Some phishing messages try to frighten recipients.
They may claim:
- Your account has been compromised.
- Your email will be suspended.
- You have failed a security check.
- A payment has been rejected.
The natural reaction is to click quickly.
Instead, open the relevant service through a known bookmark or official application rather than following the link in the message.
Check the Sender Carefully
Attackers may use email addresses that look almost correct.
For example:
might be imitated as:
The difference can be easy to miss.
Employees should check the actual sender address rather than relying only on the display name.
A familiar name does not guarantee that the message came from the person shown.
Lookalike Domains Can Be Convincing
Attackers sometimes register domains closely resembling legitimate company domains.
Differences may involve:
- Additional letters
- Missing letters
- Different domain endings
- Similar-looking characters
Businesses should train employees to inspect domains carefully when dealing with sensitive requests.
Technical email protections can also help identify suspicious sender behaviour.
Be Careful With Links
A link can display one address while directing users somewhere else.
Before clicking, employees should consider:
- Was I expecting this?
- Does the domain look correct?
- Why am I being asked to log in?
- Can I reach the same service another way?
Where possible, access important services directly rather than through unexpected email links.
Fake Login Pages Are Common
A phishing email may direct someone to a login page that closely resembles:
- Microsoft 365
- Google Workspace
- Banking services
- Cloud storage
- Payroll systems
The victim enters their username and password.
The attacker captures those details.
The page may then redirect the person to the legitimate website, making the incident less obvious.
This is why the domain in the address bar matters.
Use Multi-Factor Authentication
Multi-factor authentication, or MFA, adds another requirement beyond the password.
Depending on the system, the second factor might involve:
- An authenticator application
- Security key
- Device confirmation
- One-time code
MFA can significantly reduce the usefulness of stolen passwords.
It does not eliminate phishing risk, however.
Some attacks attempt to capture session information or trick users into approving fraudulent authentication requests.
Prefer Stronger Authentication Methods Where Available
Not all MFA methods provide the same protection.
Businesses should use stronger phishing-resistant authentication methods where practical and supported by their systems.
Security keys and passkey-based approaches can provide stronger resistance against certain credential phishing attacks than basic one-time codes.
The appropriate approach depends on the organisation's systems, users and risk profile.
Never Approve Unexpected MFA Requests
Some attackers use stolen passwords to repeatedly trigger authentication prompts.
The victim may eventually approve one simply to stop the notifications.
Employees should be trained never to approve an MFA request they did not initiate.
Unexpected prompts should be treated as a potential security incident and reported.
Use Strong, Unique Passwords
Employees should not reuse the same password across several business and personal services.
If one unrelated service is compromised, reused credentials may give attackers access elsewhere.
A password manager can help users create and store unique passwords.
The business should choose an appropriate password-management system and establish clear policies around its use.
Password Managers Can Reduce Phishing Risk
Password managers offer another useful benefit.
A properly configured manager generally associates saved credentials with a specific domain.
If an employee visits a fake login site, the password manager may not automatically offer the saved credentials.
That can provide an additional warning that the page is not the genuine service.
Employees should still check domains carefully.
Protect Administrator Accounts
Administrator accounts can provide attackers with substantial access.
Reduce unnecessary exposure by:
- Limiting administrator privileges
- Using separate administrative accounts
- Applying strong MFA
- Monitoring unusual access
Employees should generally receive only the access required for their responsibilities.
A compromised ordinary user account is serious.
A compromised global administrator account can be much worse.
Apply the Principle of Least Privilege
Not every employee needs access to every system or file.
Limiting permissions reduces what an attacker can reach if an account is compromised.
Review:
- Shared folders
- Financial systems
- Customer data
- Administration tools
Access should change when people's roles change.
Employees who leave the organisation should have access removed promptly.
Train Employees Regularly
Staff awareness training is one of the most important parts of phishing prevention.
Training should cover practical scenarios rather than only definitions.
Employees should learn to recognise:
- Suspicious links
- Fake login pages
- Urgent payment requests
- Unexpected attachments
- Lookalike domains
- MFA fatigue attacks
Training should also explain exactly what employees should do when they are uncertain.
Avoid Making Training a Once-a-Year Exercise
People forget.
Threats also change.
Short, regular security reminders can be more useful than one lengthy annual session that employees immediately put out of mind.
Cybersecurity awareness can form part of:
- Staff onboarding
- Regular team communication
- Refresher training
- Security testing
The objective is to create consistent habits.
Phishing Simulations Can Be Useful
Some businesses conduct controlled phishing simulations to assess staff awareness.
These can help identify:
- Common mistakes
- Departments needing additional training
- Types of messages employees find convincing
Simulations should be used as training tools rather than opportunities to embarrass employees.
A culture where people are afraid to admit a mistake can delay incident reporting.
Make Reporting Easy
Employees should know exactly how to report a suspicious message.
That may involve:
- A dedicated phishing-report button
- IT help desk
- Security email address
- Internal reporting channel
The process should be simple.
If reporting requires a complicated form and several approvals, employees may simply delete the message and move on.
Security teams lose the opportunity to investigate a wider attack.
Encourage Fast Reporting After Mistakes
An employee who realises they clicked a suspicious link may hesitate because they are embarrassed.
That delay can make the incident worse.
Businesses should make it clear that rapid reporting matters more than hiding the mistake.
If security staff know quickly, they may be able to:
- Reset credentials
- Revoke sessions
- Block domains
- Check account activity
Minutes can matter.
Never Punish Good-Faith Reporting
If employees believe that reporting a mistaken click will automatically lead to punishment, they may remain silent.
That creates greater risk.
There is a difference between repeated disregard for security procedures and someone promptly reporting a genuine mistake.
The reporting culture should support early intervention.
Use Email Filtering
Modern email security systems can identify and block many malicious messages before they reach employees.
Depending on the system, controls may detect:
- Known malicious links
- Dangerous attachments
- Spoofed senders
- Suspicious domains
- Malware
No filtering system catches everything.
Technical controls should reduce the volume of dangerous email that employees need to evaluate, not create a false belief that everything reaching the inbox is safe.
Configure Domain Authentication
Businesses should configure appropriate email authentication standards for their own domains.
Common technologies include:
- SPF
- DKIM
- DMARC
These can help receiving mail systems evaluate whether messages claiming to come from a domain are authorised.
Configuration needs to be performed carefully because incorrect settings can affect legitimate email delivery.
Use qualified technical support where required.
DMARC Can Help Reduce Domain Spoofing
DMARC can help domain owners specify how receiving systems should handle email that fails authentication checks.
It also provides reporting that can help organisations understand how their domains are being used.
A staged implementation is often sensible.
Businesses should avoid applying restrictive policies before confirming that legitimate email systems are configured correctly.
Keep Software Updated
Phishing may begin with a deceptive email but end by exploiting outdated software.
Keep operating systems, browsers, office applications and other software patched.
Updates can close known vulnerabilities attackers may otherwise exploit through:
- Attachments
- Malicious websites
- Document files
Where practical, businesses should use managed update processes rather than relying entirely on individual employees.
Restrict Dangerous Attachments
Businesses can reduce risk by controlling which file types employees can receive or execute.
Particularly risky files may include:
- Executables
- Scripts
- Macro-enabled documents
The appropriate restrictions depend on business requirements.
Employees should be cautious with unexpected attachments even when the sender appears familiar.
Compromised accounts can send malicious files from genuine addresses.
Treat Unexpected Documents Carefully
An invoice, CV or shared document may look ordinary.
Ask:
- Was I expecting this file?
- Does the sender normally send this type of document?
- Is the message context sensible?
If something seems unusual, verify it through another channel before opening the file.
Disable Unnecessary Macros
Malicious document macros have historically been used to deliver malware.
Businesses that do not rely on macros should consider restricting them according to the capabilities of their office software and security environment.
Where macros are genuinely required, use appropriate controls.
Security configuration should reflect actual business needs rather than enabling risky functionality by default.
Protect Financial Processes
Finance departments are frequent phishing targets because they can authorise payments.
Strong financial controls might include:
- Dual approval
- Payment limits
- Independent verification
- Supplier-change procedures
- Separation of duties
An attacker should not be able to move a large amount of money simply by convincing one employee through email.
Use Dual Approval for Significant Payments
Requiring two authorised people to approve significant transfers can reduce fraud risk.
The exact threshold should reflect the organisation's size and transaction patterns.
The purpose is not to slow ordinary business unnecessarily.
It is to prevent one compromised account or manipulated employee from becoming a single point of failure.
Verify Unusual Executive Requests
Attackers often exploit hierarchy.
An employee may feel uncomfortable questioning a request that appears to come from a director.
Leadership should make it clear that employees are expected to verify unusual financial or sensitive requests.
A genuine executive should prefer a short delay over an avoidable fraudulent transfer.
Establish a Known Verification Process
Businesses can reduce uncertainty by defining in advance how unusual requests are verified.
For example:
Banking changes require verbal confirmation through an existing trusted number.
or:
Payments above a defined amount require two approvals.
Clear procedures remove the need for employees to invent a security decision under pressure.
Protect Payroll Processes
Payroll changes can also be targeted.
An attacker may impersonate an employee and request that their salary be paid into a new account.
Treat bank-detail changes carefully.
Use established identity-verification procedures before changing payment information.
Be Careful With Shared Mailboxes
Shared accounts such as:
- accounts@
- finance@
- admin@
- info@
may receive large volumes of messages and attachments.
They can also be valuable targets.
Apply appropriate access controls and MFA to the underlying accounts.
Review who genuinely needs access.
Monitor Suspicious Login Activity
Security systems may provide information about:
- Unusual locations
- New devices
- Repeated failed logins
- Impossible travel
- Suspicious sign-in patterns
Monitoring can help identify compromised accounts even when the original phishing attempt was not reported.
Alerts need appropriate investigation rather than simply being generated and ignored.
Log Important Security Events
Businesses need enough logging to investigate incidents.
Relevant logs may include:
- Authentication
- Administrative activity
- Endpoint security
Retention periods should reflect business, legal and security requirements.
Without logs, determining what an attacker accessed can become much more difficult.
Protect Endpoints
Endpoint security tools can provide additional protection on laptops and desktops.
Depending on the solution, they may detect:
- Malware
- Suspicious processes
- Dangerous files
- Unusual behaviour
Endpoint protection should be centrally managed where appropriate.
It works alongside email protection, authentication and employee awareness.
Keep Business and Personal Accounts Separate
Employees should avoid using business email addresses and passwords for unrelated personal services.
Mixing personal and company accounts increases exposure.
The organisation also has less control over the security of external consumer platforms.
Clear boundaries make access management easier.
Secure Remote Workers
Employees working from home or travelling remain phishing targets.
Remote-working security should consider:
- Managed devices
- Secure authentication
- VPN use where appropriate
- Software updates
- Public Wi-Fi risks
- Secure collaboration tools
Remote employees should have the same clear phishing-reporting process as people working from the office.
Mobile Devices Need Protection Too
Phishing messages are often harder to inspect on phones because:
- Sender details may be less visible
- URLs can be truncated
- Users may act quickly
Employees should be particularly cautious before entering passwords after following a link from an email or text message on mobile.
Business devices should also use appropriate device-management and security controls.
SMS Phishing Is Also a Risk
Phishing through SMS is often called smishing.
A message might claim to come from:
- A bank
- Courier
- Mobile network
- Government service
It may include a link asking the recipient to verify information or make a payment.
Employees should understand that company security awareness extends beyond email.
Voice Phishing Exists Too
Attackers may also phone employees.
This is sometimes referred to as vishing.
They may pretend to be:
- IT support
- Bank staff
- Executives
- Suppliers
The caller may ask for passwords, authentication codes or payment assistance.
Legitimate support staff should not need employees to disclose passwords.
Never Share Authentication Codes
One-time authentication codes should be treated as sensitive.
Employees should not provide them to someone who:
- Emails
- Calls
- Sends a message
and asks for the code.
If someone is requesting an MFA code, they may already have the victim's password.
Public Information Can Help Attackers
Attackers can research organisations through:
- Company websites
- Social media
- Press releases
They may learn:
- Who works in finance
- Who the CEO is
- Which suppliers the business uses
- Who is travelling
Businesses do not need to remove all public information.
They should recognise that attackers may use it to make phishing messages more believable.
Be Careful With Out-of-Office Messages
An automatic reply may reveal:
- Employee absence
- Travel dates
- Alternative contacts
- Management structures
Keep external out-of-office messages concise.
Avoid providing more information than the sender genuinely needs.
Backups Still Matter
A phishing attack can sometimes result in malware or ransomware.
Reliable backups can help the business recover from certain incidents.
Good backups should be:
- Regular
- Tested
- Protected
- Separated appropriately from production systems
A backup that has never been tested should not automatically be assumed to be recoverable.
Have an Incident Response Plan
The business should know what happens if phishing succeeds.
A response plan may include procedures to:
- Disable compromised accounts
- Reset credentials
- Revoke active sessions
- Investigate email rules
- Check payment activity
- Notify relevant parties
- Restore systems
Roles should be defined before the emergency occurs.
Know Who to Call
Employees and managers should know which internal or external specialists handle cyber incidents.
This might include:
- IT team
- Managed service provider
- Cybersecurity provider
- Insurer
- Legal advisers
Keep essential contact information somewhere accessible even if normal email systems become unavailable.
Cyber Insurance May Help, but It Is Not a Substitute for Security
Cyber insurance may provide financial support or access to incident-response services for certain covered events.
Policies can contain security requirements.
The existence of insurance does not remove the need for:
- MFA
- Backups
- Training
- Access controls
- Security monitoring
Businesses should understand policy conditions and exclusions before an incident occurs.
What Should You Do After Clicking a Phishing Link?
If an employee realises they clicked a suspicious link, they should follow the organisation's incident procedure immediately.
Depending on what occurred, the security team may need to:
- Investigate the device
- Reset credentials
- Revoke sessions
- Check login activity
- Block the malicious site
Employees should not simply close the browser and assume the problem has disappeared.
What If You Entered Your Password?
Report it immediately.
The account may need its credentials changed and active sessions terminated.
If the same password was reused elsewhere, those accounts may also be at risk.
Security staff should investigate whether the attacker successfully logged in or changed account settings.
Check for Malicious Email Rules
After compromising an email account, attackers may create forwarding or inbox rules designed to hide messages.
For example, they may automatically move replies from suppliers into another folder.
This allows fraud to continue without the account owner noticing.
After an email compromise, administrators should review forwarding settings and unusual inbox rules.
Review Financial Activity Quickly
If a phishing incident involved finance or supplier information, contact the appropriate financial institutions and affected parties promptly.
Fraudulent payments can become harder to recover as time passes.
Do not rely on email alone when contacting a supplier whose account may itself have been compromised.
Review What Happened
After an incident or near miss, examine how it occurred.
Ask:
- What made the message convincing?
- Which control failed?
- Was the procedure unclear?
- Was MFA present?
- Did staff know how to report it?
The objective is to reduce the likelihood of the same attack working again.
Don't Assume Small Businesses Are Too Small to Target
Attackers do not need to spend weeks researching every victim.
Automation allows criminals to target large numbers of businesses.
Smaller organisations may also have:
- Weaker controls
- Fewer security staff
- Less formal payment procedures
That can make them attractive targets.
Cybersecurity should be proportionate to risk, but size is not protection.
Create a Simple Anti-Phishing Checklist
Employees should know to pause when a message:
- Creates unusual urgency
- Requests passwords
- Requests authentication codes
- Changes payment details
- Contains an unexpected attachment
- Sends them to a login page
- Comes from a slightly unusual address
When in doubt, verify through a trusted separate channel.
Final Thoughts
Protecting a business from phishing attacks requires both technology and process.
Email filtering, multi-factor authentication, password management, software updates and access controls can make attacks harder to complete.
Staff training and business procedures are equally important.
Employees need to know when to question an unexpected message, how to verify payment changes and where to report suspicious activity.
Finance teams should have additional controls around supplier banking details, payroll changes and large payments.
Most importantly, reporting needs to happen quickly when something goes wrong.
A single mistaken click does not automatically become a major breach.
What happens next depends heavily on how quickly the business detects the incident, limits access and responds.
Phishing works by creating enough trust, pressure or confusion to make someone act before checking.
The strongest defence is a business where checking has become part of the normal way people work.




