Securing email against phishing
The vast majority of successful attacks on businesses don't start by breaking through a firewall, but with a single click on a fraudulent email. Phishing is cheap, effective and targets the most vulnerable link — the human. Defence has two layers: technical and human.
Why email specifically
Email is the most direct route to an employee, and attackers know it. A fraudulent message looks like an invoice, a bank alert or an instruction from the boss — and one click, one entered password or one opened attachment is enough. No expensive security system helps if an employee hands over access voluntarily.
Technical defence
Some attacks can be stopped before they even reach the user:
- Email authentication — SPF, DKIM and DMARC make it harder to spoof your domain.
- A solid spam and anti-malware filter that catches known threats and dangerous attachments.
- Multi-factor authentication — even with the password, an attacker can't sign in without the second factor.
- Tagging external email so it's immediately clear a message isn't from inside the company.
Multi-factor authentication is by far the most effective single measure. It stops the vast majority of attacks built on a stolen password.
The human layer
Technology never catches everything, so people's readiness is decisive. It's not a one-off training, but a habit:
- Short, regular training with real phishing examples.
- A simple rule: for any request for a password, payment or sensitive data, verify by another channel first.
- A clear, non-punitive way to report a suspicious email.
The goal isn't to make people afraid to click. It's for them to recognise what's suspicious and have somewhere to report it without feeling they did something wrong.
When someone clicks
Assume it will happen one day. What matters is being able to react fast:
- Immediately change the affected account's password and sign out all sessions.
- Check whether the attacker set up mail-forwarding rules.
- Review what the account had access to and warn others if further spread is likely.
A practical plan
- Deploy email authentication and multi-factor authentication.
- Enable external-message tagging and a solid filter.
- Introduce short regular training and simple reporting.
- Prepare a procedure for when someone clicks.
Want to protect your business from phishing?
I'll set up email defences and help with staff training. The initial consultation is free.
Book a consultation