Cybersecurity

Email Phishing: Keeping Your Business Safe

Phishing emails account for the majority of successful cyberattacks on UK businesses. Combining technical controls — email authentication, filtering, and secure gateways — with regular staff training significantly reduces the risk of a costly breach.

AT

AMVIA Team

Editorial

7 min read·Mar 2026

Phishing is not a technology problem you can buy your way out of. It targets people, which is why the businesses that stay safe pair good filtering with a workforce that knows what a phishing email looks like. If you want a single accountable partner to run both sides of that, AMVIA's managed cybersecurity service is built around exactly this problem.

What is email phishing and why is it so effective?

Phishing is the practice of sending fraudulent emails designed to trick recipients into revealing credentials, transferring money or installing malware. It works because it exploits human behaviour, not software flaws — even careful staff click when an email arrives at the right moment, looking like something they were already expecting.

The tactics span a wide range. At one end sit mass-sent impersonations of HMRC, Microsoft or parcel couriers. At the other sit highly targeted attacks built from information gathered on LinkedIn, company websites and public records. The National Cyber Security Centre (NCSC) identifies phishing as the most common cause of significant cyber incidents affecting UK organisations.

The numbers back this up. In the government's Cyber Security Breaches Survey 2025, phishing was the most common breach type, identified by 85% of businesses and 86% of charities that experienced a breach. The average cost of the most disruptive breach was around £1,600 per affected business, rising to roughly £3,550 once you exclude organisations that reported no cost.

How do you recognise a phishing email?

Most phishing emails carry tell-tale signs once you know what to look for. Training staff to spot them is the foundation of any security awareness programme, because the human eye catches things filters miss. The five indicators below cover the vast majority of attacks reaching UK inboxes.

  • Urgent or threatening language — "Your account will be suspended", "Immediate action required", "You have been selected for an HMRC rebate". Urgency is engineered to override careful judgement.
  • Mismatched sender addresses — the display name reads "HSBC Security" but the real sending domain is random and unrelated to the brand.
  • Suspicious links — hovering over a link (without clicking) reveals the true destination, which often differs from the visible text or misspells a legitimate domain.
  • Unexpected attachments — macro-enabled Word files, zipped archives and PDFs with embedded links are common phishing payloads.
  • Requests that bypass normal processes — any email asking for credentials, payment authority or sensitive data outside agreed channels deserves out-of-band verification.

When in doubt, staff should verify the request through a known phone number or a fresh email to a saved contact — never by replying to the suspicious message.

What types of phishing attacks target UK businesses?

Phishing is an umbrella term covering several distinct attack styles, from bulk spray-and-pray campaigns to surgical strikes on named executives. Understanding the differences matters because each type needs a slightly different defence — broad attacks are caught by filtering, while targeted ones rely on staff awareness and strong account controls.

Attack typeWho it targetsHow it worksPrimary defence
Standard phishingMany recipients at onceBulk impersonation of brands like Microsoft, Amazon, banks, HMRCEmail gateway + filtering
Spear phishingSpecific named individualsUses real project, colleague or supplier detail to build trustStaff training + MFA
WhalingSenior executivesTargets high-value mailboxes to authorise fraudulent paymentsPayment verification process
Business email compromiseFinance and ops staffImpersonates a director or supplier, often with no link or attachmentOut-of-band approval rules
Smishing / vishingMobile usersSMS or voice follow-up to harvest verification codesAwareness + number checks

Spear phishing and business email compromise deserve particular attention. They take more effort from the attacker but achieve far higher success rates, and because BEC often carries no malicious link or attachment, automated filters struggle to catch it. That is why our phishing protection service combines technical filtering with the human controls these attacks are designed to slip past.

Which technical controls reduce phishing risk?

No single control eliminates phishing, but layered defences sharply reduce both the probability and the impact of an attack. The goal is to stop most threats at the gateway, neutralise the links and attachments that get through, and ensure that even a stolen password is not enough to break in.

  • Email authentication (SPF, DKIM, DMARC) — stops criminals spoofing your domain to phish your own staff and partners, and improves detection of spoofed inbound mail.
  • Email security gateway — scans inbound mail for malicious URLs, suspicious attachments and phishing indicators before delivery.
  • Safe Links and Safe Attachments — part of Microsoft Defender for Business, these rewrite URLs and detonate attachments in a sandbox before a user can reach them.
  • Multi-factor authentication — if credentials are phished, MFA across Microsoft 365 blocks the attacker from using them without the second factor.

AMVIA configures these as a single hardened stack built on Microsoft Defender and the Barracuda email suite — no bolt-on tools, no gaps between vendors. Microsoft's own security guidance confirms that combining authentication, filtering and MFA is the baseline for credible email protection.

How do you build a phishing-aware culture?

Technology is necessary but not sufficient. Staff awareness training — delivered regularly, not as a one-off annual slideshow — builds the habitual scepticism that catches the attacks slipping through technical filters. Culture, not a single tool, is what separates the businesses that get breached from the ones that report and contain attacks early.

Simulated phishing exercises, where controlled test emails are sent to staff, are the most effective training mechanism. Staff who click should get immediate, contextual education — never punishment. The goal is learning, not blame. An organisation where people feel safe reporting a mistake catches real attacks far earlier than one where embarrassed employees quietly delete suspicious messages and say nothing.

Phishing is consistently reported as the most disruptive form of attack — affecting an estimated 65% of breached businesses and 63% of charities in 2025 government data — which is why building reporting into everyday habits pays for itself quickly.

What should you do if you receive — or click — a phishing email?

If a suspicious email arrives, do not click links, open attachments, reply or forward it. Report it through your designated process — in Microsoft 365 this is the Report Phishing button in Outlook. Speed matters far more than certainty: reporting a false alarm costs nothing, while ignoring a real attack can be expensive.

If you believe you have already clicked a link or entered credentials, tell your IT team immediately so passwords can be changed, active sessions revoked and access logs reviewed. Quick action is the difference between a near-miss and a breach, especially where managed detection and response can spot and contain an account takeover before it spreads.

If sensitive personal data may have been exposed, check whether a UK GDPR breach notification to the ICO is required — there is a 72-hour reporting window for qualifying breaches.

Test Your Team Against Real Phishing Attacks

AMVIA's simulated phishing exercises reveal exactly how your staff respond to phishing attempts — deliver immediate, effective training to those who need it.

Frequently Asked Questions