Glossary
Phishing
An identity-spoofing attempt via email, SMS, or message, designed to make you click a booby-trapped link or reveal credentials.
Phishing is still the number-one entry point for cyber attacks against small and mid-sized businesses. The pattern is simple: the attacker impersonates a trusted party — your bank, a supplier, a customer, the CEO — to push you to click a link, open an attachment, or type your credentials on a fake page.
Modern techniques range from mass phishing (millions of blind messages) to targeted spearphishing: an attacker can spend days studying your company, identifying your usual suppliers, and sending a perfectly credible fake invoice at the right moment in the month.
The three defences that actually reduce risk: two-factor authentication (which neutralises a stolen password), domain authentication via DMARC / SPF / DKIM (which prevents attackers from sending mail "from" you), and a team trained to recognise signals. None of these requires significant budget.
Real-world example
A communications agency receives a fake email from its usual printer asking for a bank-account change for the next invoice. With no verification process, the transfer goes to the attacker.