PROTECT · EMAIL & PHISHING
Email & Phishing — Could One Message Put Your Business at Risk?
A phishing message does not need to look ridiculous. The dangerous ones look like normal business.
Why email deserves attention
Email sits at the centre of many businesses. It is used for customer conversations, invoices, password resets, supplier requests and internal decisions. That makes it useful to criminals too.
Phishing is an attempt to persuade someone to do something that benefits the attacker: click a link, open a file, reveal a password, change bank details or approve a payment.
The message may look completely ordinary
A useful warning is not simply “look for bad spelling”. Modern phishing can copy familiar brands, imitate colleagues and suppliers, use information available online and create a convincing sense of urgency.
The important skill is recognising when a request deserves an independent check.
Slow down unusual requests
Requests involving money, credentials, sensitive information or unexpected changes should receive extra attention. A message saying a supplier has changed bank details, a senior manager needs an urgent transfer or an account must be reactivated may be genuine — but the consequences justify checking.
Use a trusted contact method that does not depend on the suspicious message. For example, call a known number already held by the business rather than a number supplied in the email.
Technology and people work together
Email filtering and account protection help, but no control catches everything. Staff also need a simple way to report suspicious messages without being embarrassed for asking.
Multi-factor authentication can make a stolen password less useful to an attacker, while sensible payment processes can stop one email becoming one fraudulent transfer.
BOI ACTION
Choose one request your business should always verify.
Good candidates include a change of supplier bank details, an urgent payment request or a request for sensitive information.
Agree how staff will verify it using a separate trusted route. Make the check easy enough that people will actually use it.
A useful question for the business
Which email request could cost us the most if somebody believed a convincing fake?
Don’t assume. Check.
A familiar name, logo or email thread is not proof that a request is genuine. When the consequence matters, verify the request independently.
NOT SURE WHERE TO START?
Take the 15-Minute Business Security Check
Use ten straightforward questions to identify three priorities for sensible action.
Useful guidance
Final publication QA will verify current UK-first phishing guidance and supporting authoritative sources before release.
Continue exploring
Email risk becomes more serious when the information inside the business is poorly understood or poorly protected.
Explore the Cyber Security Guides →
Found something that may be outdated or incorrect? Let us know.
Better Decisions. Stronger Organisations.
Understand what matters. Take sensible action. Check whether it worked.