Skip to content
Cyber Experts

Glossary

Phishing

An identity-spoofing attempt via email, SMS, or message, designed to make you click a booby-trapped link or reveal credentials.

Phishing is still the number-one entry point for cyber attacks against small and mid-sized businesses. The pattern is simple: the attacker impersonates a trusted party — your bank, a supplier, a customer, the CEO — to push you to click a link, open an attachment, or type your credentials on a fake page.

Modern techniques range from mass phishing (millions of blind messages) to targeted spearphishing: an attacker can spend days studying your company, identifying your usual suppliers, and sending a perfectly credible fake invoice at the right moment in the month.

The three defences that actually reduce risk: two-factor authentication (which neutralises a stolen password), domain authentication via DMARC / SPF / DKIM (which prevents attackers from sending mail "from" you), and a team trained to recognise signals. None of these requires significant budget.

Real-world example

A communications agency receives a fake email from its usual printer asking for a bank-account change for the next invoice. With no verification process, the transfer goes to the attacker.