Phishing is an email, message or call designed to make somebody act — enter credentials, approve a payment, open an attachment — by looking like something legitimate. It is the way most small businesses are actually attacked, because it needs no technical sophistication, only a plausible pretext and one distracted person on a busy afternoon.
The standard response is awareness training, and the honest position on training is that it helps a little and is nowhere near sufficient. Click rates fall after a session and drift back within months. What holds is changing the situation rather than the person: making the dangerous actions harder to complete by mistake, and making reporting so easy that you hear about attempts early.
What people should be able to recognise
- Urgency plus authority. Nearly every successful pretext combines somebody important and something that must happen now.
- A request to change payment details, or an invoice from a familiar supplier with a new bank account. This is the attack that costs small businesses the most money.
- A login page reached by clicking a link. Legitimate services do ask you to log in; the safe habit is to reach the site the way you normally do rather than through the message.
- Requests that bypass a normal process — a payment outside the approval route, a document shared from a personal account, a colleague messaging from a new number.
- Attachments that ask you to enable something, and files that are not the type they appear to be.
What actually reduces the damage
- Phishing-resistant authentication on the accounts that matter. A passkey does not care that the page looked convincing, which is covered in two factor authentication.
- A verification rule for money: any change of bank details is confirmed by a phone call to a number you already had, never one supplied in the message. Write it down and apply it to the owner as well.
- One-click reporting, and thanks for every report including the false alarms. The teams that get hurt are the ones where reporting feels like admitting stupidity.
- A named person to ask, and permission to interrupt them. Most phishing succeeds in the gap where somebody was unsure and did not want to bother anybody.
- No blame for clicking. The cost of a click is minutes if reported immediately and months if hidden, and everything about how you react determines which one you get.
Simulated phishing campaigns are worth running and easy to run badly. A simulation designed to catch people — a fake bonus, a fake disciplinary notice — produces resentment, teaches staff to distrust internal email, and lowers real reporting. Measure the reporting rate rather than the click rate: a team where forty per cent report the simulation is far safer than one where five per cent clicked and nobody said anything.
The one that gets small businesses
Invoice fraud deserves separate mention because it is where the losses concentrate. The pattern is consistent: a supplier relationship is observed or a mailbox is read, and a genuine-looking invoice arrives with changed bank details, often at a moment when a payment is genuinely expected. The defences are unglamorous — verify changes by a known phone number, keep supplier bank details in a system rather than in email, require a second pair of eyes above a threshold — and are covered alongside the payment process in payment approval and accounts payable.
Where Ettex fits
Ettex Teams holds who has access to what, and the passkey option removes the credential an attacker is usually fishing for. Supplier bank details belong in a record rather than in a mail thread, which is what Ettex CRM and Ettex Books are for, and the approval step in Ettex Invoices.
What we do not do: there is no email security gateway, no attachment scanning, no phishing simulation platform and no awareness training programme. Those are separate products, some worth buying. What we can honestly influence is that the sensitive actions — approving a payment, changing a supplier's details — happen in a place with a record and a second approver rather than in a mailbox.
Frequently asked
Does phishing awareness training work?
A little, and it fades. Click rates recover within months. Phishing-resistant authentication, a verification rule for payment changes, and blame-free reporting do considerably more.
Should you run simulated phishing campaigns?
Yes, if you measure reporting rather than clicking, and if the pretexts are not cruel. Simulations designed to humiliate reduce real reporting, which is the opposite of the goal.
What is the most expensive phishing attack for small businesses?
Invoice fraud — a real supplier, a real expected payment, changed bank details. Verifying any change of details by a phone number you already had prevents most of it.
What should someone do after clicking a phishing link?
Say so immediately. Change the password, revoke sessions, and check for mail rules that were added. The cost of a reported click is minutes; the cost of a hidden one is months.