Most people picture a hacker breaking through firewalls and cracking passwords. The reality is far more ordinary: the vast majority of business breaches start with an email. Someone receives a convincing message, clicks a link or opens an attachment, and hands over the keys without realising anything is wrong. That is phishing — and it remains the single most common way UK businesses are compromised.

The good news is that phishing relies on people, not just technology, which means people can also stop it. Once you and your team know what to look for, most phishing emails become obvious. This guide covers what phishing is, the red flags that give it away, what to do when one gets through, and how to build a business that shrugs them off.

#1
Most common cyber threat facing UK businesses
8 in 10
Breached businesses that identify phishing as the cause
1 click
Is all it takes to hand over credentials or trigger malware

What phishing actually is

Phishing is a fraudulent email designed to trick the recipient into doing something that compromises security — usually revealing login details, transferring money, or opening a file that installs malware. It works by impersonation: the email appears to come from someone you trust, such as your bank, a supplier, Microsoft, or even a colleague or your own boss.

Most phishing is sent in bulk, hoping a small percentage of recipients take the bait. But the more dangerous version is targeted: spear phishing is aimed at a specific person using details gathered about them, and whaling goes after senior staff and finance teams with convincing requests to approve payments or share data. Targeted attacks are harder to spot precisely because they feel personal and legitimate.

The red flags that give it away

Almost every phishing email carries at least one of these tells. Train your team to pause the moment they see one — and to treat several together as a near-certain sign.

The sender doesn’t match
The display name looks right, but the actual email address is subtly wrong — a misspelt domain, a public address, or a lookalike. Always check the real address, not just the name shown.
Check: reveal the true sender address, not just the display name
Urgency and pressure
“Your account will be suspended”, “pay within the hour”, “action required now”. Phishing manufactures panic so you act before you stop to think.
Check: legitimate organisations rarely demand instant action
Links that don’t add up
The visible text says one thing, but the real destination is different. Hover or long-press to preview the URL — if it doesn’t match the supposed sender, don’t click.
Check: preview every link before you click it
Unexpected attachments
Invoices, delivery notes or documents you weren’t expecting can carry malware. Be especially wary of files that ask you to “enable content” or macros.
Check: confirm with the sender before opening anything
Requests for credentials or payment
No legitimate provider emails you to “confirm your password”. Any request to log in via a link, change bank details, or approve an unexpected payment deserves suspicion.
Check: verify payment or bank changes by phone, not email
Odd language or greetings
Generic openings like “Dear customer”, awkward phrasing, or spelling and grammar errors often give a phishing attempt away — though the best fakes are increasingly polished.
Check: trust your instinct if something simply reads wrong
“Phishing doesn’t break in — it gets invited in. The whole attack depends on one person trusting one email for one moment. That’s exactly where it can be stopped.”

What to do if one gets through

Even careful teams occasionally click. What matters most is what happens next — fast, calm action limits the damage. If you or a member of staff has clicked a phishing link or entered details:

  • Disconnect the device from Wi-Fi or the network to stop malware spreading or communicating out.
  • Change the password for any account whose details may have been entered — and any other account that shared that password.
  • Turn on multi-factor authentication if it isn’t already active, so a stolen password alone isn’t enough to get in.
  • Report it to whoever manages your IT straight away, so they can check for wider compromise and contain it.
  • Contact your bank without delay if any financial or card details were entered.

Crucially, make reporting blame-free. Staff who fear being told off will hide their mistakes — and a hidden click is far more dangerous than a reported one.

Cyber Security

Is your team your strongest defence — or your weakest link?

Techfident’s cyber security support combines staff awareness, multi-factor authentication, email filtering and monitoring — so phishing is caught before it reaches an inbox, and handled properly when it does.

Building a business that shrugs off phishing

Spotting individual emails is the last line of defence, not the first. A resilient business layers protection so that no single mistake is catastrophic:

  • Train your team regularly — short, frequent awareness beats an annual lecture. People forget, and the tactics keep evolving.
  • Turn on multi-factor authentication everywhere — it’s the single most effective control against stolen passwords.
  • Filter email so the majority of phishing never reaches an inbox in the first place.
  • Keep software patched so malicious attachments have fewer weaknesses to exploit.
  • Get certifiedCyber Essentials gives you a proven baseline of controls that block the most common attacks.
 The bottom line

Phishing is the most common cyber threat to UK businesses because it targets people, not systems — and no firewall can fully patch human trust. But that’s also its weakness. A team that knows the red flags, backed by multi-factor authentication and email filtering, turns your biggest vulnerability into a wall of alert people. Spotting a phishing email is a skill worth teaching everyone — and it costs nothing but attention.

Common questions about phishing

A phishing email is a fraudulent message designed to trick you into revealing sensitive information — passwords, bank details, card numbers — or into clicking a malicious link or opening an infected attachment. It usually impersonates a trusted sender, such as a bank, supplier, colleague or well-known company, to lower your guard.

Look for mismatched or spoofed sender addresses, unexpected urgency, generic greetings, links whose real destination differs from the text, unexpected attachments, spelling and grammar errors, and any request to confirm a password or make a payment. One red flag is reason to pause; several together is a strong sign it’s phishing.

Act quickly. Disconnect the device from the network, change the password for any account you may have entered, enable multi-factor authentication if it isn’t already on, and report it to whoever handles your IT. If card or bank details were entered, contact your bank. The sooner it’s contained, the less damage it can do.

Combine training and technology. Teach your team to recognise the red flags, turn on multi-factor authentication everywhere, use email filtering to catch threats before they arrive, keep software patched, and make it easy for staff to report suspicious emails without blame. Certifications like Cyber Essentials give you a solid baseline.