Protecting your business from phishing attacks
How modern phishing works, the layered controls that stop it, and what to do in the first ten minutes after a click.
By the Telappliant team

Phishing has stopped looking like phishing. Messages are written in fluent British English, reference real projects, arrive from genuinely compromised supplier mailboxes and, increasingly, are followed by a voice call that sounds like someone you know.
The four types that reach UK businesses
- Credential harvesting: a convincing Microsoft 365 sign-in page behind a shared document link
- Business email compromise: a supplier's real mailbox asking you to update bank details
- MFA relay: a proxy page that captures the code as you type it and signs in live
- Callback and voice phishing: an email with no link, prompting you to ring a number
Technical controls that do the heavy lifting
- DMARC at enforcement, with SPF and DKIM aligned, so your domain cannot be spoofed
- Safe Links and attachment detonation on every user
- Impersonation protection for directors, finance and payroll
- Conditional access with device compliance, which blunts stolen-session attacks
- Phishing-resistant MFA for privileged accounts
- Blocked external auto-forwarding
The process control that stops the loss
Every change of bank details or payment instruction is verified by calling a known number held on file, never a number in the email, and always by a second person. This single rule prevents the majority of financial loss from BEC.
Training that reflects reality
Simulate what your sector actually receives, including invoice fraud and delivery notifications, and measure how quickly people report rather than how many click. Make reporting one click and thank every report, including the false ones.
The first ten minutes after a click
- Reset the password and revoke all sessions and tokens
- Check for new inbox rules, forwarding and added MFA methods
- Review sign-in logs for unfamiliar locations and successful logins
- Warn finance and anyone in the email thread
- Preserve the message and headers for analysis
Assume one gets through
Layered controls fail sometimes. Endpoint detection, alerting on mailbox rule changes, and a rehearsed response plan decide whether a click becomes an incident or a footnote.



