Phishing for SMBs: recognise it, block it, recover fast
Phishing remains the top cause of cyber incidents at small businesses. Five signals to identify it, three controls that neutralise most of the risk.
Phishing is still the number-one cause of cyber incidents at small and mid-sized businesses. Not the spectacular ransomware that makes the news, the simple booby-trapped email that ends up compromising a mailbox, redirecting a wire transfer, or opening the door to a patient attacker.
The good news: three technical controls neutralise most of the risk, and none requires significant budget. Here's the short version.
Phishing in 2026: what has changed
Two evolutions worth knowing:
- Messages are now credible. The bad spelling and dodgy layouts that made phishing easy to spot in 2015 are gone. Attackers now use LLMs to produce perfectly written copy in any language with the expected tone.
- Targeting is sharper. Spearphishing, personalised phishing, is now within reach of average attackers. Two hours on LinkedIn and your website yields enough context to send a credible "from your usual supplier" email asking for a bank-account change at the right moment of the month.
Consequence: the old advice ("watch for typos!", "check the sender address!") isn't enough anymore. You need technical controls.
The 5 signals that still don't lie
Even when the content is credible, these signals betray most attempts:
- The sender's domain, not the display name, the part after
@.paypa1-security.comisn'tpaypal.com. - Unjustified urgency, "action required within 24 hours", "your account will be suspended", "confirm by tonight". Real institutions don't operate this way.
- A request outside the usual frame, your supplier doesn't change their bank account by email without a courtesy call.
- A link to hover before clicking, hovering (not clicking) shows the real destination at the bottom of the browser. If it doesn't match the link text, it's suspicious.
- An unexpected attachment, particularly
.zip,.iso,.docm,.xlsm. A lawyer doesn't send a court summons as a.zip.
The three controls that change the risk
1. Two-factor authentication (MFA)
Even if an attacker steals a password via phishing, they can't log in without the second factor. On the 5 critical accounts of an SMB (email, banking, payroll, payment processor, hosting), enabling 2FA takes 30 minutes and blocks most of the attacks we see.
2. Domain authentication (DMARC, SPF, DKIM)
Without these three standards, anyone can send mail "from" your domain. Your customers receive fake invoices in your name and you discover the issue when the money is gone. Configuring DMARC in reject mode closes that door.
3. Calibrated team training
Not generic "cyber awareness" once a year. A short, focused training on the attacks your team actually sees, with a light quarterly test. This is exactly what module 3 of Essentials produces.
And if an attack succeeds anyway?
Three things to do in the first 24 hours:
- Cut access of the compromised account: password change + global sign-out + check inbox rules (attackers often create a rule that forwards mail to an external address).
- Notify those who could have received messages from this account, clients, suppliers. Quick transparency beats a silence that ends in lost trust.
- Document the incident: who, when, how. If you have cyber insurance, they'll ask for these elements.
Going further
For agencies and e-commerce stores particularly exposed:
- Cybersecurity for digital agencies, why your studio is a prime target
- Cybersecurity for e-commerce, why attacks spike at peak season
To put all this in place in 7 days, Essentials is our reference training, €297, lifetime access, 30-day money-back guarantee.