How to Protect Your Business from Phishing Attacks
A practical guide for UK businesses — explaining what this means, why it matters, and what you should do about it.
Overview
43% of UK businesses experienced a cybersecurity breach or attack in the past 12 months, equating to approximately 612,000 businesses (DSIT Cyber Security Breaches Survey 2025). 67% of medium businesses and 74% of large businesses reported breaches in 2025.
Learn moreWhy is phishing the top threat to UK businesses?
Phishing is the single most common way criminals breach UK organisations, and the numbers are not improving. It exploits people, not just technology, which is why no firewall alone stops it. The defence is overlapping layers that each cover another's blind spot — managed end to end by AMVIA's cybersecurity team.
In the past 12 months, 43% of UK businesses experienced a cybersecurity breach or attack — approximately 612,000 businesses (DSIT Cyber Security Breaches Survey 2025). Among larger firms the figures climb: 67% of medium businesses and 74% of large businesses reported breaches in 2025, and 85% of those breaches involved phishing (DSIT 2025). Phishing is not a niche risk — it is the primary attack vector every UK business has to plan for, which is why it anchors our managed email security service.
What are the main types of phishing attacks?
Phishing is no longer just dodgy emails. Attackers now run multi-channel campaigns across email, SMS, voice and QR codes, and tailor the most damaging attacks to named individuals. Recognising each variant is the first step to defending against it.
- Mass phishing — high-volume generic emails impersonating Royal Mail, HMRC, Microsoft or banks. Profitable even if one in a thousand recipients clicks.
- Spear phishing — targeted emails using the victim's role, projects or colleagues to bypass suspicion. Far more effective than mass phishing.
- Business email compromise (BEC) — the most financially damaging form: an attacker impersonates an executive, supplier or solicitor to trigger a payment or data transfer. Often contains no link or attachment, so technical filters struggle. See our dedicated business email compromise page.
- Smishing and vishing — fraudulent SMS messages and phone calls, increasingly paired with email in the same campaign.
- Quishing — malicious QR codes that hide the destination URL, defeating the "check the link" instinct users have learned for email.
Which technical controls stop phishing?
Technical controls are your first and most scalable line of defence: if a phishing email never reaches the inbox, no one can click it. The four that matter most are email authentication, filtering, Microsoft Defender for Office 365 and multi-factor authentication — configured together, not in isolation.
Email authentication (DMARC, DKIM, SPF). SPF lists which servers may send mail for your domain; DKIM cryptographically signs outbound mail; DMARC ties them together and tells receiving servers to monitor, quarantine or reject failures. Publishing DMARC at `p=reject` stops criminals spoofing your domain to phish your customers and suppliers. The NCSC recommends DMARC for all UK organisations. We set this up on the DMARC, DKIM and SPF setup page.
Inbound filtering. Modern filtering uses machine learning to catch phishing that signature tools miss, blocking malicious senders and scanning attachments before delivery.
Microsoft Defender for Office 365. Adds anti-phishing policies, Safe Links (checks URLs at click time, catching time-delayed threats), Safe Attachments (detonates suspicious files in a sandbox) and anti-impersonation protection. Plan 1 covers the essentials for most SMEs; Plan 2 adds threat hunting and automated response.
Multi-factor authentication (MFA). If credentials are stolen, MFA stops the attacker using them. Yet only 40% of UK businesses have two-factor authentication enabled (DSIT 2025) — so enforcing it closes one of the largest remaining gaps. The NCSC lists MFA among its top recommendations for organisations of every size.
What process controls prevent business email compromise?
Process controls catch the attacks that slip past technology — especially BEC, where the email looks legitimate and carries no payload. Two simple, enforced procedures stop most invoice fraud and payment-diversion attempts before money leaves the account.
- Payment and supplier-change verification. Require that any change to supplier bank details, or any emailed payment request, is confirmed verbally using a phone number from your own records — never a number in the email. Document it, enforce it without exception.
- Frictionless suspicious-email reporting. In Microsoft 365 the Report Message add-in enables one-click reporting to your security team. Every reported email is intelligence: if one employee got it, others probably did too.
- A tested incident response plan. A basic plan defines who to call, how to contain (reset passwords, revoke sessions, isolate devices) and how to communicate. AMVIA helps clients build and test these as part of incident response.
How does staff training reduce phishing risk?
Training is the human layer — and it is the difference between a reported phishing email and a six-figure wire fraud. Effective programmes change behaviour, not just knowledge, by testing staff with realistic simulations and coaching at the point of failure.
Regular simulated phishing campaigns send safe but realistic emails and measure who clicks, who enters credentials and who reports correctly. Employees who interact get immediate, targeted training — far more effective than an annual classroom session. Pair that with security awareness training covering email, SMS, voice and QR-code attacks, refreshed at least annually. AMVIA delivers monthly campaigns through its phishing simulation training programme with reporting on how susceptibility falls over time.
In-house vs managed phishing protection — which is right?
Most UK SMEs do not have the in-house time or specialist tooling to run layered phishing defence continuously. The table below compares running it yourself against a single managed provider.
| Capability | In-house / DIY | AMVIA managed email security |
|---|---|---|
| DMARC, DKIM, SPF | Configured once, rarely monitored | Configured to `p=reject` and monitored continuously |
| Microsoft Defender for Office 365 | Default policies, often untuned | Policies tuned, Safe Links/Attachments enforced |
| Phishing simulations | Ad hoc or none | Monthly campaigns with trend reporting |
| Threat monitoring | Business hours, best effort | 24/7 UK security operations centre |
| Incident response | Improvised under pressure | Documented, tested playbooks |
| Accountability | Split across vendors | One provider, security-first |
This is the AMVIA model: one accountable provider, security comes first, and the work is done by Microsoft-certified engineers — backed by our Cyber Essentials Plus certification.
How much does phishing protection cost?
Phishing protection is one of the most cost-effective security investments a UK business can make. The average cost of the single most disruptive breach is approximately £1,205 for micro and small businesses (DSIT 2025), and materially higher for medium and large organisations.
Layered protection combines tooling you may already own (Microsoft Defender for Office 365 is included in Microsoft 365 Business Premium at £16.90 per user/month, ex VAT — microsoft.com/en-gb) with managed configuration, monitoring and training. The cost of getting it right is a small fraction of the cost of a single successful business email compromise.
Phishing prevention checklist for UK SMEs
- DMARC published at `p=reject` for all company domains
- SPF and DKIM configured for every sending source
- Microsoft Defender for Office 365 anti-phishing policies enabled
- Safe Links and Safe Attachments activated
- MFA enforced on all user accounts
- Written payment-verification policy requiring verbal confirmation
- One-click suspicious-email reporting in place
- Monthly phishing simulation campaigns
- Annual security awareness training for all staff
- Documented, tested incident response plan
- Regular review of authentication reports and filtering effectiveness
Key Points
What you need to know.
Why It Matters
43% of UK businesses experienced a cybersecurity breach or attack in the past 12 months, equating to approximately 612,000 businesses (DSIT Cyber Security Breaches Survey 2025).
How It Works
67% of medium businesses and 74% of large businesses reported breaches in 2025.
UK Requirements
Relevant UK regulations, standards, and compliance considerations.
Getting Started
Practical first steps for businesses of any size.
Key Considerations
Assess your current position and identify gaps
Understand relevant UK regulations and standards
Implement appropriate technical controls
Train staff on security awareness
Review and update regularly
Consider managed service options for specialist areas
Frequently Asked Questions
Layer email gateway filtering with anti-impersonation policies, DMARC at `p=reject` to block domain spoofing, Safe Links for point-of-click URL scanning, Safe Attachments for sandbox detonation, and MFA on every account. Only 40% of UK businesses have two-factor authentication enabled (DSIT 2025), so enforcing MFA alone closes one of the largest gaps in most organisations' defences.
Simulations send realistic but harmless phishing emails and track who clicks, who enters credentials and who reports correctly. Employees who interact receive immediate, contextual training at the point of failure — far more effective than annual classroom sessions. Run consistently over successive campaigns, click rates fall, directly lowering exposure to the phishing behind 85% of breaches (DSIT 2025).
No single control catches every variant. Gateway filters block known threats but miss novel attacks; DMARC stops spoofing but not lookalike domains; MFA neutralises stolen credentials but not malware. Business email compromise often contains no links at all. Combining filtering, authentication, endpoint protection, payment verification and training means each layer compensates for the others' blind spots.
Microsoft Defender for Office 365 provides strong anti-phishing, Safe Links and Safe Attachments protection, but default policies are rarely tuned and need monitoring to stay effective. It also does not cover process controls like payment verification or the human layer of staff training. Defender is a core component of layered protection, not a complete defence by itself.
Core technical controls — DMARC monitoring, Defender policy tuning and MFA enforcement — can typically be deployed within days for a Microsoft 365 environment. Phishing simulation and awareness training then run continuously to build resilience over time. AMVIA starts with a free security audit to identify the gaps that matter most first.
Need Help With This?
AMVIA can assess your current position and recommend practical next steps.
Related Resources
Email Security and Phishing Protection for UK Businesses
Comprehensive guide to cybersecurity for UK businesses. Expert advice, key considerations, and actionable steps to strengthen your…
The Complete Guide to Managed Cybersecurity for UK…
Comprehensive guide to cybersecurity for UK businesses. Expert advice, key considerations, and actionable steps to strengthen your…
What Is Email Security? A Guide for UK Business Owners
In-depth explainer on email security? a guide for uk business owners for UK businesses. Key concepts, best practices, and practical…
What Is Business Email Compromise (BEC)? UK SME Guide
In-depth explainer on business email compromise (bec)? uk sme guide for UK businesses. Key concepts, best practices, and practical…
Protect your business → Get Cybersecurity Assessment