← All articles Backup & Security

How to stop phishing emails: a guide for business owners

Most cyber attacks on small businesses don't start with clever hacking. They start with an email: a fake invoice, a "your mailbox is full" warning, or a message that looks like it's from the boss asking for an urgent payment. That's phishing. The good news: a few settings and simple habits stop most of it.

How to spot a phishing email

The fake invoice scam (and how to stop it)

Criminals send an email that looks like it's from a regular supplier, saying their bank details have changed. Sometimes they break into the supplier's real mailbox and reply inside a genuine email thread, so it looks completely normal.

The fix is a simple rule: never change payment details based on an email alone. Call the supplier on a number you already have — not one from the email — before paying. Make it company policy, so staff feel safe to check even when the "boss" says it's urgent.

Six settings that stop most phishing

  1. Two-step login (MFA) on every mailbox. A stolen password alone is then not enough to get in.
  2. SPF, DKIM and DMARC on your domain. These stop criminals sending emails that appear to come from your own company. See how SPF, DKIM and DMARC work.
  3. Use the protection you already pay for. Microsoft 365 and Google Workspace both include phishing and attachment protection, but it's often left on basic settings.
  4. Tag outside emails. A small "External" warning on emails from outside your company makes fake "boss" emails easy to spot.
  5. Keep computers and browsers updated, with antivirus running on every device.
  6. Make reporting easy. A "report phishing" button, or one person everyone can forward suspicious emails to.

Train your team — 10 minutes a month

Short and regular beats a long yearly session. Share real phishing emails your company has received, thank people who report them, and never punish someone for clicking — if they're afraid, they'll hide it, and hidden mistakes cost the most.

What to do if someone clicked

  1. Act fast and don't hide it — minutes matter.
  2. If a password was entered: change it straight away, sign the account out everywhere and check two-step login is on.
  3. Check the mailbox for new rules — attackers often add a rule that forwards or hides emails.
  4. If an attachment was opened: disconnect that computer from the network and run a full scan.
  5. If money was sent: call your bank immediately. In India, also report it at cybercrime.gov.in or call 1930.
  6. Warn clients and suppliers if your mailbox sent out suspicious emails.

Phishing is also the most common way ransomware gets in — our ransomware protection checklist covers the next layer of defence.

Frequently asked questions

What is phishing?

Phishing is a fake message — usually an email, sometimes WhatsApp or SMS — designed to trick you into clicking a link, opening an attachment, sharing a password or sending money.

Do Microsoft 365 and Google Workspace stop phishing?

Both block many phishing emails, but no filter catches everything. Two-step login, correct SPF, DKIM and DMARC records and a team that knows what to look for close the gaps.

What should I do if we sent money to a scammer?

Call your bank straight away and ask them to stop or recall the payment, then report it to the police. In India, report it at cybercrime.gov.in or call the 1930 helpline.

Get a free email security check

We'll check your two-step login, SPF, DKIM, DMARC and phishing protection settings, and tell you exactly what to fix.

More articles

WhatsApp