Almost every serious cyber attack on a small business starts the same way: not with a hooded hacker breaking through a firewall, but with an ordinary-looking email landing in someone's inbox. One click, one password typed into the wrong box, and the damage is done.
That email is called phishing, and it is the single most common way businesses get compromised. The good news is that a phishing email nearly always gives itself away if you know what to look for. Here are the warning signs worth teaching everyone on your team, and what to do when a suspicious one turns up.
What phishing actually is
Phishing is a fraudulent message, usually email, designed to trick you into doing something: clicking a dodgy link, opening an infected attachment, handing over a password, or paying a fake invoice. The sender pretends to be someone you trust, your bank, Microsoft, a supplier, even your own boss. It works because it relies on human reflexes, not technical weaknesses.
The warning signs
No single sign is proof on its own, but any of these should make you slow down and look twice.
- A sense of urgency or threat. "Your account will be suspended", "invoice overdue, pay immediately", "unusual login, act now". Fear and time pressure are the phisher's favourite tools, because they stop you thinking.
- The sender's address does not match. The display name might say "Microsoft", but the actual address is a jumble, or a lookalike domain with a letter changed. Always check the real email address, not just the name shown.
- Links that are not what they claim. Hover over a link before clicking and the real destination shows at the bottom of the screen. If the text says one thing and the address says another, do not click.
- Unexpected attachments. An invoice, delivery note or "document to review" you were not expecting is a classic way to deliver malware.
- Requests for passwords, codes or bank details. No genuine bank, supplier or IT provider will ever email asking for your password or a multi-factor code. That request is the scam.
- A change of payment details. An email that says "we have changed banks, please pay this invoice to the new account" is one of the most expensive scams going. More on that below.
The one that costs businesses the most
The most damaging phishing is not the obvious "you have won a prize" nonsense. It is quiet and businesslike. A criminal watches an email conversation, waits for a real invoice to be due, then sends a convincing message saying the bank details have changed. The money goes to the criminal, and it is often gone for good before anyone notices.
A close cousin is the fake message from "the boss" asking an urgent favour, usually to buy gift cards or make a quick payment while they are "in a meeting". The rule that defeats both: any change to payment details, and any unusual payment request, gets verified by phone on a number you already have, never a number from the email.
Why "just spot the typos" no longer works
The old advice was to look for bad spelling and clumsy grammar. That still helps sometimes, but AI tools have made it far easier for criminals to write flawless, convincing messages, and to copy a company's tone exactly. You can no longer rely on a phishing email looking amateurish. That is why the answer is process and habit, not gut feel.
What to do when one lands
Teach your team this simple drill:
- Stop. Do not click, do not open the attachment, do not reply.
- Verify another way. If it claims to be from a supplier or colleague, contact them through a number or address you already have, not the details in the email.
- Report it. Tell whoever looks after your IT, so they can check whether others got it too and block the sender.
- If in doubt, delete. A genuine sender will not mind you double-checking.
And if someone does click or hand over a password, the worst thing they can do is stay quiet out of embarrassment. Fast reporting is what limits the damage. Make it safe to own up.
The protections that back your team up
Training is the front line, but it should not stand alone. A well-protected business layers a few things together:
- Spam and email filtering to stop most phishing reaching inboxes at all.
- Multi-factor authentication so a stolen password alone is not enough to get in. This is one of the single most effective protections there is, and it is a core part of Cyber Essentials.
- Reliable backups so that if an attack does get through, you can recover rather than pay.
- Occasional simulated phishing tests to keep the team sharp and turn awareness into a habit.
How we help
For the businesses we look after, this is part of everyday cyber security support: filtering and multi-factor authentication set up properly, backups tested, and staff helped to build the instinct to pause. The aim is simple, a team that treats an unexpected email with healthy suspicion, and the technical safety nets to catch what slips through.
If you are not confident your business would spot a well-crafted phishing email, or you have never tested it, we are happy to take a look and give you an honest picture of where you stand.