Guide

How to Protect Your Business from Phishing Attacks

A practical guide for UK businesses — explaining what this means, why it matters, and what you should do about it.

Overview

43% of UK businesses experienced a cybersecurity breach or attack in the past 12 months, equating to approximately 612,000 businesses (DSIT Cyber Security Breaches Survey 2025). 67% of medium businesses and 74% of large businesses reported breaches in 2025.

Learn more

Why is phishing the top threat to UK businesses?

Phishing is the single most common way criminals breach UK organisations, and the numbers are not improving. It exploits people, not just technology, which is why no firewall alone stops it. The defence is overlapping layers that each cover another's blind spot — managed end to end by AMVIA's cybersecurity team.

In the past 12 months, 43% of UK businesses experienced a cybersecurity breach or attack — approximately 612,000 businesses (DSIT Cyber Security Breaches Survey 2025). Among larger firms the figures climb: 67% of medium businesses and 74% of large businesses reported breaches in 2025, and 85% of those breaches involved phishing (DSIT 2025). Phishing is not a niche risk — it is the primary attack vector every UK business has to plan for, which is why it anchors our managed email security service.

What are the main types of phishing attacks?

Phishing is no longer just dodgy emails. Attackers now run multi-channel campaigns across email, SMS, voice and QR codes, and tailor the most damaging attacks to named individuals. Recognising each variant is the first step to defending against it.

  • Mass phishing — high-volume generic emails impersonating Royal Mail, HMRC, Microsoft or banks. Profitable even if one in a thousand recipients clicks.
  • Spear phishing — targeted emails using the victim's role, projects or colleagues to bypass suspicion. Far more effective than mass phishing.
  • Business email compromise (BEC) — the most financially damaging form: an attacker impersonates an executive, supplier or solicitor to trigger a payment or data transfer. Often contains no link or attachment, so technical filters struggle. See our dedicated business email compromise page.
  • Smishing and vishing — fraudulent SMS messages and phone calls, increasingly paired with email in the same campaign.
  • Quishing — malicious QR codes that hide the destination URL, defeating the "check the link" instinct users have learned for email.

Which technical controls stop phishing?

Technical controls are your first and most scalable line of defence: if a phishing email never reaches the inbox, no one can click it. The four that matter most are email authentication, filtering, Microsoft Defender for Office 365 and multi-factor authentication — configured together, not in isolation.

Email authentication (DMARC, DKIM, SPF). SPF lists which servers may send mail for your domain; DKIM cryptographically signs outbound mail; DMARC ties them together and tells receiving servers to monitor, quarantine or reject failures. Publishing DMARC at `p=reject` stops criminals spoofing your domain to phish your customers and suppliers. The NCSC recommends DMARC for all UK organisations. We set this up on the DMARC, DKIM and SPF setup page.

Inbound filtering. Modern filtering uses machine learning to catch phishing that signature tools miss, blocking malicious senders and scanning attachments before delivery.

Microsoft Defender for Office 365. Adds anti-phishing policies, Safe Links (checks URLs at click time, catching time-delayed threats), Safe Attachments (detonates suspicious files in a sandbox) and anti-impersonation protection. Plan 1 covers the essentials for most SMEs; Plan 2 adds threat hunting and automated response.

Multi-factor authentication (MFA). If credentials are stolen, MFA stops the attacker using them. Yet only 40% of UK businesses have two-factor authentication enabled (DSIT 2025) — so enforcing it closes one of the largest remaining gaps. The NCSC lists MFA among its top recommendations for organisations of every size.

What process controls prevent business email compromise?

Process controls catch the attacks that slip past technology — especially BEC, where the email looks legitimate and carries no payload. Two simple, enforced procedures stop most invoice fraud and payment-diversion attempts before money leaves the account.

  • Payment and supplier-change verification. Require that any change to supplier bank details, or any emailed payment request, is confirmed verbally using a phone number from your own records — never a number in the email. Document it, enforce it without exception.
  • Frictionless suspicious-email reporting. In Microsoft 365 the Report Message add-in enables one-click reporting to your security team. Every reported email is intelligence: if one employee got it, others probably did too.
  • A tested incident response plan. A basic plan defines who to call, how to contain (reset passwords, revoke sessions, isolate devices) and how to communicate. AMVIA helps clients build and test these as part of incident response.

How does staff training reduce phishing risk?

Training is the human layer — and it is the difference between a reported phishing email and a six-figure wire fraud. Effective programmes change behaviour, not just knowledge, by testing staff with realistic simulations and coaching at the point of failure.

Regular simulated phishing campaigns send safe but realistic emails and measure who clicks, who enters credentials and who reports correctly. Employees who interact get immediate, targeted training — far more effective than an annual classroom session. Pair that with security awareness training covering email, SMS, voice and QR-code attacks, refreshed at least annually. AMVIA delivers monthly campaigns through its phishing simulation training programme with reporting on how susceptibility falls over time.

In-house vs managed phishing protection — which is right?

Most UK SMEs do not have the in-house time or specialist tooling to run layered phishing defence continuously. The table below compares running it yourself against a single managed provider.

CapabilityIn-house / DIYAMVIA managed email security
DMARC, DKIM, SPFConfigured once, rarely monitoredConfigured to `p=reject` and monitored continuously
Microsoft Defender for Office 365Default policies, often untunedPolicies tuned, Safe Links/Attachments enforced
Phishing simulationsAd hoc or noneMonthly campaigns with trend reporting
Threat monitoringBusiness hours, best effort24/7 UK security operations centre
Incident responseImprovised under pressureDocumented, tested playbooks
AccountabilitySplit across vendorsOne provider, security-first

This is the AMVIA model: one accountable provider, security comes first, and the work is done by Microsoft-certified engineers — backed by our Cyber Essentials Plus certification.

How much does phishing protection cost?

Phishing protection is one of the most cost-effective security investments a UK business can make. The average cost of the single most disruptive breach is approximately £1,205 for micro and small businesses (DSIT 2025), and materially higher for medium and large organisations.

Layered protection combines tooling you may already own (Microsoft Defender for Office 365 is included in Microsoft 365 Business Premium at £16.90 per user/month, ex VAT — microsoft.com/en-gb) with managed configuration, monitoring and training. The cost of getting it right is a small fraction of the cost of a single successful business email compromise.

Phishing prevention checklist for UK SMEs

  • DMARC published at `p=reject` for all company domains
  • SPF and DKIM configured for every sending source
  • Microsoft Defender for Office 365 anti-phishing policies enabled
  • Safe Links and Safe Attachments activated
  • MFA enforced on all user accounts
  • Written payment-verification policy requiring verbal confirmation
  • One-click suspicious-email reporting in place
  • Monthly phishing simulation campaigns
  • Annual security awareness training for all staff
  • Documented, tested incident response plan
  • Regular review of authentication reports and filtering effectiveness

Key Points

What you need to know.

Why It Matters

43% of UK businesses experienced a cybersecurity breach or attack in the past 12 months, equating to approximately 612,000 businesses (DSIT Cyber Security Breaches Survey 2025).

How It Works

67% of medium businesses and 74% of large businesses reported breaches in 2025.

UK Requirements

Relevant UK regulations, standards, and compliance considerations.

Getting Started

Practical first steps for businesses of any size.

Key Considerations

Assess your current position and identify gaps

Understand relevant UK regulations and standards

Implement appropriate technical controls

Train staff on security awareness

Review and update regularly

Consider managed service options for specialist areas

Frequently Asked Questions

Need Help With This?

AMVIA can assess your current position and recommend practical next steps.