The most common way businesses get compromised is not a genius hacker - it is one person clicking one convincing email. Phishing works because it targets people, not systems, and a little awareness is one of the cheapest, most effective defenses you have.
Why phishing works
A phishing message is designed to make you act before you think: a fake alert, an urgent request from the "boss," a login page that looks exactly right. It exploits trust and urgency, not technical flaws - which is why no software alone can stop it, and why recognizing it matters.
Warning signs
- Urgency or a threat - "act now or your account will be closed."
- A request to log in, pay, or share credentials via a link.
- A sender address that is subtly wrong, or a display name that does not match the real address.
- Links that, on hover, go somewhere other than where they claim.
- Unexpected attachments, or a message that is slightly off in tone or wording.
Common tactics
Watch for impersonation of a boss or vendor (often asking for payment or gift cards), fake invoices and delivery notices, and "your password is expiring" pages that harvest logins. Spear phishing is the targeted version - personalized with details about you or your company to seem more convincing.
What to do when one arrives
Do not click links or open attachments. Verify through a channel you trust - call the person on a known number rather than replying. Report it to whoever handles your IT so others can be warned. And if someone did click, act fast: change the password, turn on MFA if it is not already, and get help. Awareness pairs with the technical controls in business email security and a broader security baseline.
Want to train your team to spot these? Tell us about your setup and we will help build the awareness and the controls behind it.
