Email Phishing: Keeping Your Business Safe
Phishing emails account for the majority of successful cyberattacks on UK businesses. Combining technical controls — email authentication, filtering, and secure gateways — with regular staff training significantly reduces the risk of a costly breach.
AMVIA Team
Editorial
Phishing is not a technology problem you can buy your way out of. It targets people, which is why the businesses that stay safe pair good filtering with a workforce that knows what a phishing email looks like. If you want a single accountable partner to run both sides of that, AMVIA's managed cybersecurity service is built around exactly this problem.
What is email phishing and why is it so effective?
Phishing is the practice of sending fraudulent emails designed to trick recipients into revealing credentials, transferring money or installing malware. It works because it exploits human behaviour, not software flaws — even careful staff click when an email arrives at the right moment, looking like something they were already expecting.
The tactics span a wide range. At one end sit mass-sent impersonations of HMRC, Microsoft or parcel couriers. At the other sit highly targeted attacks built from information gathered on LinkedIn, company websites and public records. The National Cyber Security Centre (NCSC) identifies phishing as the most common cause of significant cyber incidents affecting UK organisations.
The numbers back this up. In the government's Cyber Security Breaches Survey 2025, phishing was the most common breach type, identified by 85% of businesses and 86% of charities that experienced a breach. The average cost of the most disruptive breach was around £1,600 per affected business, rising to roughly £3,550 once you exclude organisations that reported no cost.
How do you recognise a phishing email?
Most phishing emails carry tell-tale signs once you know what to look for. Training staff to spot them is the foundation of any security awareness programme, because the human eye catches things filters miss. The five indicators below cover the vast majority of attacks reaching UK inboxes.
- Urgent or threatening language — "Your account will be suspended", "Immediate action required", "You have been selected for an HMRC rebate". Urgency is engineered to override careful judgement.
- Mismatched sender addresses — the display name reads "HSBC Security" but the real sending domain is random and unrelated to the brand.
- Suspicious links — hovering over a link (without clicking) reveals the true destination, which often differs from the visible text or misspells a legitimate domain.
- Unexpected attachments — macro-enabled Word files, zipped archives and PDFs with embedded links are common phishing payloads.
- Requests that bypass normal processes — any email asking for credentials, payment authority or sensitive data outside agreed channels deserves out-of-band verification.
When in doubt, staff should verify the request through a known phone number or a fresh email to a saved contact — never by replying to the suspicious message.
What types of phishing attacks target UK businesses?
Phishing is an umbrella term covering several distinct attack styles, from bulk spray-and-pray campaigns to surgical strikes on named executives. Understanding the differences matters because each type needs a slightly different defence — broad attacks are caught by filtering, while targeted ones rely on staff awareness and strong account controls.
| Attack type | Who it targets | How it works | Primary defence |
|---|---|---|---|
| Standard phishing | Many recipients at once | Bulk impersonation of brands like Microsoft, Amazon, banks, HMRC | Email gateway + filtering |
| Spear phishing | Specific named individuals | Uses real project, colleague or supplier detail to build trust | Staff training + MFA |
| Whaling | Senior executives | Targets high-value mailboxes to authorise fraudulent payments | Payment verification process |
| Business email compromise | Finance and ops staff | Impersonates a director or supplier, often with no link or attachment | Out-of-band approval rules |
| Smishing / vishing | Mobile users | SMS or voice follow-up to harvest verification codes | Awareness + number checks |
Spear phishing and business email compromise deserve particular attention. They take more effort from the attacker but achieve far higher success rates, and because BEC often carries no malicious link or attachment, automated filters struggle to catch it. That is why our phishing protection service combines technical filtering with the human controls these attacks are designed to slip past.
Which technical controls reduce phishing risk?
No single control eliminates phishing, but layered defences sharply reduce both the probability and the impact of an attack. The goal is to stop most threats at the gateway, neutralise the links and attachments that get through, and ensure that even a stolen password is not enough to break in.
- Email authentication (SPF, DKIM, DMARC) — stops criminals spoofing your domain to phish your own staff and partners, and improves detection of spoofed inbound mail.
- Email security gateway — scans inbound mail for malicious URLs, suspicious attachments and phishing indicators before delivery.
- Safe Links and Safe Attachments — part of Microsoft Defender for Business, these rewrite URLs and detonate attachments in a sandbox before a user can reach them.
- Multi-factor authentication — if credentials are phished, MFA across Microsoft 365 blocks the attacker from using them without the second factor.
AMVIA configures these as a single hardened stack built on Microsoft Defender and the Barracuda email suite — no bolt-on tools, no gaps between vendors. Microsoft's own security guidance confirms that combining authentication, filtering and MFA is the baseline for credible email protection.
How do you build a phishing-aware culture?
Technology is necessary but not sufficient. Staff awareness training — delivered regularly, not as a one-off annual slideshow — builds the habitual scepticism that catches the attacks slipping through technical filters. Culture, not a single tool, is what separates the businesses that get breached from the ones that report and contain attacks early.
Simulated phishing exercises, where controlled test emails are sent to staff, are the most effective training mechanism. Staff who click should get immediate, contextual education — never punishment. The goal is learning, not blame. An organisation where people feel safe reporting a mistake catches real attacks far earlier than one where embarrassed employees quietly delete suspicious messages and say nothing.
Phishing is consistently reported as the most disruptive form of attack — affecting an estimated 65% of breached businesses and 63% of charities in 2025 government data — which is why building reporting into everyday habits pays for itself quickly.
What should you do if you receive — or click — a phishing email?
If a suspicious email arrives, do not click links, open attachments, reply or forward it. Report it through your designated process — in Microsoft 365 this is the Report Phishing button in Outlook. Speed matters far more than certainty: reporting a false alarm costs nothing, while ignoring a real attack can be expensive.
If you believe you have already clicked a link or entered credentials, tell your IT team immediately so passwords can be changed, active sessions revoked and access logs reviewed. Quick action is the difference between a near-miss and a breach, especially where managed detection and response can spot and contain an account takeover before it spreads.
If sensitive personal data may have been exposed, check whether a UK GDPR breach notification to the ICO is required — there is a 72-hour reporting window for qualifying breaches.
Test Your Team Against Real Phishing Attacks
AMVIA's simulated phishing exercises reveal exactly how your staff respond to phishing attempts — deliver immediate, effective training to those who need it.
Frequently Asked Questions
Check the sender's actual email address — not just the display name — and hover over any links to see the real destination URL. Be sceptical of urgent requests for credentials, payment or personal data; legitimate organisations never ask for your password by email. When in doubt, contact the supposed sender through a known, trusted channel.
Act fast. Change the employee's password immediately, revoke active sessions, and check email forwarding rules and app permissions for signs of compromise. Review access logs for unusual activity. If sensitive data or payment credentials may have been exposed, follow your incident response plan and assess whether a UK GDPR breach report to the ICO is required.
No. Email security gateways catch a high proportion of known phishing, but sophisticated targeted attacks — especially those using fresh, clean infrastructure — bypass filters. This is why staff training and multi-factor authentication are essential alongside technical controls, not alternatives to them. Phishing remains the single most common breach type for UK businesses.
BEC is a form of phishing where criminals impersonate executives, suppliers or colleagues to deceive staff into transferring money or sharing sensitive data. Unlike malware-based phishing, BEC often involves no malicious link or attachment — it succeeds through social engineering alone, which makes it particularly hard to filter automatically and best stopped with payment verification rules.
Annual training is a starting point but insufficient alone. Regular simulated phishing exercises — quarterly at minimum — combined with timely education at the point of failure are far more effective. The threat landscape shifts constantly, so training should reflect current tactics, including SMS phishing (smishing) and voice phishing (vishing), not just email.
No technical or training programme eliminates phishing risk entirely. The realistic goal is to reduce the chance of a successful attack to a level unlikely to cause significant harm, and to ensure controls like MFA limit the damage if credentials are stolen. Verizon's 2025 Data Breach Investigations Report found stolen credentials were the most common initial-access vector, so layered defence beats any single control.
Related Reading
Business Email Security
A comprehensive guide to protecting your business email from phishing, spoofing and malware.
Phishing Recognition & Response
How to train employees to recognise phishing attempts and respond effectively when targeted.
What Is DMARC?
DMARC prevents criminals from spoofing your domain in phishing emails — find out how to implement it.
Protect your business → Get Cybersecurity Assessment