Key takeaways
- Phishing is the most common way attackers get in
- Layer filtering, domain authentication, MFA and training
- Always verify payment changes by phone
- Make reporting suspicious emails easy
Phishing emails pretend to come from someone you trust, a bank, a supplier or even your CEO, to trick staff into clicking a link, opening an attachment or sending money. They are cheap to send and surprisingly effective.
Common phishing tactics
Watch for these patterns:
- Fake invoices or payment change requests from 'suppliers'
- Urgent messages from executives asking for gift cards or transfers
- Login pages that look like Microsoft 365 or your bank
- Shipping or delivery notices with malicious links
- Attachments that ask you to 'enable content'
Layer 1: Email filtering
Advanced email security scans links and attachments, checks sender reputation and uses AI to spot impersonation. Suspicious messages are quarantined before users see them.
Layer 2: Authentication
Configure SPF, DKIM and DMARC for your domain so attackers can't easily send email pretending to be you, and so receiving servers can verify your genuine messages.
Layer 3: Multi-factor authentication
Even if a password is stolen, MFA stops attackers logging in. It's the single most effective control against account takeover.
Layer 4: People
Short, regular awareness training and simulated phishing tests teach staff what to look for. Make it easy to report suspicious emails, and thank people when they do.
What to do if someone clicks
Mistakes happen. What matters is how quickly you respond:
- Report it to IT immediately; don't feel embarrassed
- Change the password if credentials were entered
- Check for new inbox rules or forwarding
- Scan the device for malware
- Review sign-in logs for unusual activity
- Warn colleagues if the same email was widely received
Building a reporting culture
Staff should feel safe reporting suspicious emails, even if they've already clicked. A single 'Report phishing' button in Outlook or Gmail makes it easy. When people see that reports are acted on and appreciated, they report more, and attacks are caught earlier.
Why phishing works
Phishing succeeds because it targets people, not technology. Attackers research companies through websites and social media, then craft emails that look like everyday business: an invoice from a known supplier, a shared document from a colleague, a delivery notice or a password expiry warning. Messages often create urgency so the reader acts before thinking. Increasingly, attackers use compromised real mailboxes, so the email genuinely comes from a trusted contact. This is why layered defences, combining technology and awareness, are essential.
Protecting your domain's reputation
Attackers can also use your company's name to target your customers and suppliers. Publishing SPF, DKIM and DMARC records tells the world which servers are allowed to send email for your domain. Starting with a DMARC monitoring policy lets you see who is sending on your behalf, then gradually move to a policy that rejects unauthorised messages. This protects your brand, improves delivery of your genuine emails and makes impersonation attacks against your partners much harder.
Testing your defences
Simulated phishing campaigns show how well staff recognise suspicious emails. Send realistic but harmless test emails, measure who clicks and who reports, and follow up with short, supportive training for those who need it. Repeat every few months with different themes, such as invoices, deliveries or password resets. Over time, click rates fall and reporting rates rise, which is exactly what you want. Combined with technical controls, this measurable improvement significantly reduces the chance that a real phishing email succeeds.
Verify payment changes
Business email compromise often targets finance. Always confirm new bank details by phone using a known number, never by replying to the email.
Frequently asked questions
An email authentication standard that tells receiving servers how to handle messages that fail checks, making it harder for attackers to impersonate your domain.
Short sessions every few months work better than one long annual course.
No filter is perfect, which is why multiple layers, including trained staff, are essential.
A scam where attackers impersonate executives or suppliers, often using a compromised mailbox, to trick staff into paying fake invoices.




