Phishing is a message that impersonates someone you trust — a colleague, a supplier, a familiar service — in order to get you to hand over a password, approve a payment, or open a file. It arrives by email most of the time, and by text message or phone call often enough to matter. It works because it skips your technology entirely and goes straight to a person having a busy day.
Nearly every serious breach begins the same way: someone clicks something they shouldn't have. Phishing remains the most common entry point for attackers, and it works even on careful, capable teams. The better news is that it is also one of the most defensible problems a small business has, once you understand how it is built.
The same message is more dangerous on a phone. Verizon's 2026 report found click rates 40% higher on mobile devices. A link that looks obviously wrong on a laptop often does not on a small screen, one-handed, at a bus stop.
Figure verified 31 July 2026. Source linked above.
Why does phishing still work on careful teams?
Because it is engineered to beat human judgment rather than human intelligence. Blaming whoever clicked misses the point: a well-built phishing message is designed to arrive at the exact moment when stopping to check feels like the unreasonable choice. Three levers do most of the work.
- Urgency. A deadline such as "your account will be suspended in 24 hours" compresses the time available for thought, and a decision made in a hurry is a decision made on autopilot.
- Authority. A message that appears to come from the owner, the bookkeeper, or a supplier you deal with every week lowers your guard before you have read a single line of it.
- Context. Attackers research a business first, then reference real projects, real names, and a real invoice number, so the message reads as a continuation of work already under way.
The best phishing emails do not look suspicious. They look like Tuesday.
What does a modern phishing message look like?
Nothing like the clumsy examples people picture. The advice to watch for typos and broken grammar has aged badly, because these messages are proofread now and often assembled from real branding. What gives them away is the gap between how the message presents itself and what it actually asks you to do. The example below is typical of the genre: polished on the surface, with three quiet tells that survive any amount of proofreading.
Which requests deserve a second check every time?
A short list, and much the same one in every small business. Agree it out loud as a team rule.
| The request | Why it is a favourite lure | How to verify before acting |
|---|---|---|
| Change our bank details | One approved change quietly redirects every future payment | Call the supplier on a number you already held, never one in the message |
| Sign in to confirm something | A convincing copy of a login page collects the password | Ignore the link; open the service from your own bookmark |
| Pay this invoice today | Real invoice numbers and project names make it look routine | Match it to your own records, then confirm with whoever ordered it |
| Buy gift cards for me | Borrowed authority, and value that vanishes the moment it is sent | Speak to the person directly; assume it is false until you have |
| Text me instead of replying | Moving off email removes the colleagues who would have noticed | Keep the conversation where it started, and loop in one colleague |
Which settings reduce phishing before anyone sees it?
Two of them do most of the technical work, and both are configuration rather than purchases. The first is email authentication: the SPF, DKIM, and DMARC records published in your domain's settings. Together they tell receiving mail servers which systems are genuinely allowed to send as your business, so messages that forge your name are far more likely to be rejected before they ever reach a customer, a supplier, or a colleague.
The second is multi-factor authentication on every account that would hurt to lose, starting with email. Phishing usually ends with a stolen password, and multi-factor means a stolen password on its own is not enough to get in. Beyond those two, turn on the link and attachment scanning your email provider already includes, and switch on the banner that marks messages from outside your organisation so an impersonated colleague is visible at a glance.
How do you build a team that reports rather than hides?
By making verification ordinary and reporting a non-event. Start with one rule that applies to everyone, the owner included: anything involving money or credentials gets confirmed out of band. A quick call to a number you already had, before a payment goes out or bank details change. That single habit defeats most invoice-fraud attempts, because the entire scheme depends on the request never being checked against reality.
Then run short, regular awareness sessions and the occasional simulated message. The purpose is not to catch anyone out or publish a scoreboard; it is to make "pause and verify" a reflex and to make forwarding a suspicious email feel unremarkable. Say plainly that nobody will be blamed for reporting, or for clicking and then saying so immediately. The minutes between a click and a report are worth more than any written policy.
The bottom line
You cannot patch human nature, but you can surround it. Email authentication, multi-factor authentication, a verify-before-you-pay rule, and a team that reports rather than hides — together these turn phishing from an open door into a manageable nuisance.