Key takeaways
- Phishing is the most common starting point for breaches — and it is getting more convincing.
- Multi-factor authentication (MFA) blocks the vast majority of attacks that rely on stolen passwords.
- Authenticator apps and security keys are far stronger than SMS codes.
- Make reporting suspicious messages easy — and never punish the person who clicked and told you.
What modern phishing looks like
The badly spelled "prince" emails are mostly gone. Today's phishing is targeted and polished:
- Credential phishing — a perfect copy of the Microsoft 365, Google or bank login page, sent as "your mailbox is full" or "a document has been shared with you".
- Invoice and payment fraud — an email that appears to come from a supplier or your own manager, asking to update bank details or pay an urgent invoice. Often sent from a genuinely compromised account.
- Malicious attachments — fake shipping notices, CVs or quotations that install malware when opened.
- Messaging and voice — the same tricks over WhatsApp, SMS or phone calls, sometimes using AI-cloned voices.
Five signs to stop and check
- Urgency or fear — "within 24 hours", "account suspended", "the CEO needs this now".
- A login request you didn't expect — especially from a link rather than typing the address yourself.
- Small mismatches — the sender's real address, a slightly misspelled domain, a link that points somewhere else when you hover over it.
- Changes to payment details — always confirm by phone using a number you already have, never one from the email.
- Requests to bypass process — secrecy, gift cards, "don't tell anyone".
Why MFA changes everything
Passwords leak — through phishing, reused passwords from other breached websites, or malware. Multi-factor authentication adds a second proof that the attacker doesn't have: a code from an app, a push approval on your phone, or a physical security key. Even with the correct password, the login fails.
Microsoft has reported that MFA blocks well over 99% of automated account-compromise attacks. Few security measures offer that much protection for so little cost.
Not all MFA is equal
| Method | Strength | Notes |
|---|---|---|
| SMS code | Basic | Better than nothing, but vulnerable to SIM-swap and interception. |
| Authenticator app code | Good | Free and widely supported. Can still be phished by fake pages that relay codes in real time. |
| Push with number matching | Good | Number matching stops "MFA fatigue" attacks where users approve random prompts. |
| Security key / passkey | Strongest | Phishing-resistant: it only works on the genuine website. Ideal for admins and finance. |
Where to switch MFA on first
- Email and Microsoft 365 / Google Workspace — the master key to everything else.
- VPN and any remote access to the office.
- Administrator accounts on servers, firewalls and cloud services.
- Banking, payroll, accounting and payment platforms.
- Your domain registrar and website hosting.
Building a reporting culture
The fastest way to contain a phishing attack is an employee who says "I think I clicked something" within five minutes. That only happens if reporting is easy and safe. Give staff a single, obvious way to report — a button in Outlook or a WhatsApp number for IT — thank people for every report, and run short, practical awareness sessions a few times a year rather than one long annual lecture.
Phishing will never disappear, but with MFA, sensible processes and a team that knows what to look for, it stops being a business-ending risk. If you'd like help rolling out MFA or running awareness training, talk to us.



