Telappliant
Cyber Security Guide · 15 August 2026

Protecting your business from phishing attacks

How modern phishing works, the layered controls that stop it, and what to do in the first ten minutes after a click.

By the Telappliant team

A finance worker verifying a suspicious invoice email by phone

Phishing has stopped looking like phishing. Messages are written in fluent British English, reference real projects, arrive from genuinely compromised supplier mailboxes and, increasingly, are followed by a voice call that sounds like someone you know.

The four types that reach UK businesses

  • Credential harvesting: a convincing Microsoft 365 sign-in page behind a shared document link
  • Business email compromise: a supplier's real mailbox asking you to update bank details
  • MFA relay: a proxy page that captures the code as you type it and signs in live
  • Callback and voice phishing: an email with no link, prompting you to ring a number

Technical controls that do the heavy lifting

  • DMARC at enforcement, with SPF and DKIM aligned, so your domain cannot be spoofed
  • Safe Links and attachment detonation on every user
  • Impersonation protection for directors, finance and payroll
  • Conditional access with device compliance, which blunts stolen-session attacks
  • Phishing-resistant MFA for privileged accounts
  • Blocked external auto-forwarding

The process control that stops the loss

Every change of bank details or payment instruction is verified by calling a known number held on file, never a number in the email, and always by a second person. This single rule prevents the majority of financial loss from BEC.

Training that reflects reality

Simulate what your sector actually receives, including invoice fraud and delivery notifications, and measure how quickly people report rather than how many click. Make reporting one click and thank every report, including the false ones.

The first ten minutes after a click

  • Reset the password and revoke all sessions and tokens
  • Check for new inbox rules, forwarding and added MFA methods
  • Review sign-in logs for unfamiliar locations and successful logins
  • Warn finance and anyone in the email thread
  • Preserve the message and headers for analysis

Assume one gets through

Layered controls fail sometimes. Endpoint detection, alerting on mailbox rule changes, and a rehearsed response plan decide whether a click becomes an incident or a footnote.

Next steps

Frequently asked questions

Further reading

Related guides

More practical guidance from the Telappliant team on the same topic.

Talk to a UK technology partner

Book a practical, no-pressure consultation. We'll review your current setup, show where AI communications, cloud telephony or managed IT could improve customer experience and reduce admin - and tell you straight if you don't need us.

  • UK-based people, real account management
  • Honest recommendations - even if it's not us
  • Practical AI where it adds value, not hype
UK business team reviewing plans together before a consultation
Call us Book consultation