Back to overview

July 12, 2026 · 5 min read

Spotting Phishing: A Practical Guide for Your Team

Most successful attacks on small businesses don't start with a hacker in front of a black screen — they start with a harmless-looking email. Having handled the aftermath of a successful attack, I've seen what a single click can cost. This guide turns your team into the first line of defense.

The typical warning signs

  • Time pressure and threats: 'Your account will be locked in 24 hours.'
  • Sender addresses that are only almost right: billing@paypa1.com instead of paypal.com.
  • Unexpected attachments — especially ZIP, ISO or Office files with macros.
  • Links whose target doesn't match the displayed text (hover before you click).
  • Unusual requests from 'the boss': buy gift cards, urgent transfer, new bank details.

Why modern phishing emails are so convincing

Spelling mistakes as a tell are history. Current campaigns use flawless language, real logos and information from social networks or past data leaks. QR codes in emails and text messages ('your parcel is waiting') are now part of the toolkit too. So the deciding factor is not a gut feeling of 'looks legitimate' but a sober look at sender, link and context.

Checklist for a suspicious message

  • Don't click, don't download, don't reply.
  • Verify the sender through a second channel — a phone number from your address book, not from the email.
  • Report the email internally so colleagues are warned.
  • If someone did click: change the password immediately, inform IT, disconnect the device. Fast reporting limits the damage — blame only ensures the next incident stays hidden.

The technical safety net behind it

Awareness is the first line, technology the second: two-factor authentication makes stolen passwords largely useless, SPF/DKIM/DMARC make sender spoofing harder, and modern mail filters plus up-to-date browsers catch many campaigns. Together this creates a system where a single wrong click no longer turns into a disaster.

Phishing resistance comes from routine: short trainings, clear reporting paths and the right technical hardening. I offer both — awareness training for teams and hardening of your email environment.

Questions about your IT?

Let's talk about your project — no strings attached.

Get in touch