Blog

Web Security articles

Phishing Protection for Small Businesses: A Practical Guide

How phishing attacks target small businesses, the warning signs staff should know, and the technical and process controls that stop most attempts.

4 min read Web Security

Most cyber attacks on small businesses do not begin with sophisticated hacking. They begin with an email. A convincing message asks someone to log in, open an attachment or pay an invoice, and one click later the attacker has a password, a foothold on a computer or the company's money. Good phishing protection combines technology that stops most of these messages with people who recognise the ones that get through.

Why small businesses are targeted

Attackers do not need a business to be large; they need it to be reachable and trusting. Smaller companies often have no dedicated IT security staff, fewer approval steps for payments, and employees who handle many roles at once. A single compromised mailbox can be used to send invoices to every customer in the address book, so the business also becomes a launch pad for attacking others.

The common types of phishing

  • Credential phishing: a fake login page for Microsoft 365, Google, a bank or a delivery company, designed to capture usernames and passwords.
  • Malicious attachments: documents, archives or files disguised as invoices or shipping notices that install malware when opened.
  • Business email compromise (BEC): a message that appears to come from a director, supplier or customer, asking for an urgent payment or a change of bank details. These often contain no links or attachments at all.
  • Spear phishing: a message tailored to one person, using details from your website, social media or a previously stolen mailbox.
  • Phone and text phishing: the same tactics by SMS or a call, sometimes following up an email to make it seem genuine.

Warning signs to teach everyone

  • Urgency or secrecy: "pay this today", "don't mention this to anyone", "your account will be closed".
  • A change of payment details, especially by email alone.
  • A sender address that is almost right: an extra letter, a different ending, or a free email account using a colleague's name.
  • Links that do not match: hover over a link before clicking and check the real destination.
  • Unexpected login prompts after opening a shared document.
  • Unusual requests from someone you know, such as buying gift cards.

Training works best when it is short, regular and blame-free. Staff who fear being punished for a mistake hide it; staff who are thanked for reporting a suspicious email become your best early-warning system.

Technical controls that stop most attacks

Multi-factor authentication

Unique passwords (a password generator and a password manager make this easy) combined with multi-factor authentication for email and every cloud service is the single most effective step. A stolen password alone is then not enough. Authenticator apps and security keys are stronger than SMS codes, and phishing-resistant methods such as passkeys and hardware keys defeat even fake login pages that relay codes in real time.

Email authentication for your own domain

Publishing SPF, DKIM and an enforced DMARC policy stops attackers sending email that appears to come from your exact domain to your customers and staff. Check your setup with the SPF, DKIM and DMARC checker, and aim to move DMARC to quarantine or reject once your legitimate senders are covered.

Mail filtering

Microsoft 365 and Google Workspace both include phishing and malware filtering; make sure the stronger protection options are enabled, including attachment scanning and link checking. Add a visible "External" tag to messages from outside the company so impersonations of colleagues stand out.

Up-to-date devices

Keep operating systems, browsers and office software updated automatically, and use reputable endpoint protection. Many malicious attachments only work against unpatched software.

Process controls for payments

Business email compromise is defeated by process more than technology:

  1. Never change a supplier's bank details based on an email alone. Call them on a number you already have, not one in the message.
  2. Require a second person to approve payments above a set amount.
  3. Treat any request to bypass normal procedure as a red flag, however senior the sender appears.

What to do if someone clicks

Speed matters more than blame. Make sure everyone knows to report immediately, then:

  • Change the password for the affected account and sign it out of all sessions.
  • Check the mailbox for new forwarding rules or inbox rules that hide replies, a common attacker trick.
  • Disconnect a device from the network if an attachment was opened, and scan it.
  • If money was sent, contact your bank at once; recalls are sometimes possible within hours.
  • Warn customers or suppliers if your mailbox may have been used to contact them.

Key takeaways

  • Phishing is the most common starting point for attacks on small businesses.
  • Multi-factor authentication, email authentication and good filtering block most attempts.
  • Verify payment changes by phone and require a second approver for large payments.
  • Make reporting easy and blame-free, and act quickly when someone clicks.

Need help with this?

Netifi helps businesses around the world with Web Security. Tell us what you are working on.