To avoid phishing, stop and check any unexpected message before you click or pay, and confirm anything unusual through a contact method you already trust. Back that habit up with multi-factor authentication and email filtering, so one wrong click doesn't turn into a breach.
That's the short answer to how to avoid phishing. The rest of this guide is for the people who actually open the emails, from your Office Manager to the new starter in their second week.
It matters because phishing is still the attack most UK businesses face. According to the government's Cyber Security Breaches Survey 2025/2026, 38% of businesses experienced phishing in the last year. Among businesses that were breached, 88% said phishing was involved.
The signs of a phishing email
The old advice was to look for bad spelling. That no longer holds. Businesses interviewed for the survey were worried that AI-written phishing emails now arrive with perfect grammar.
Look at what the email wants from you instead:
- Urgency or pressure. "Payment overdue today." "Your account will be closed." Real suppliers rarely give you an hour.
- A change to bank details. Any email asking you to pay a different account should be confirmed by phone, using a number you already had or head to their website to find the number.
- A login link you weren't expecting. A "Microsoft" email asking you to verify your account is a classic lure.
- A sender address that doesn't quite match. The display name says your MD. The address behind it says something else entirely.
- An unexpected attachment, especially one asking you to enable content or open a shared file.
Not sure whether it's genuine? Worried about offending a supplier by checking? Pick up the phone anyway, and never reply to the email itself to ask.
Phishing doesn't only arrive by email
Smishing is phishing by text message. The fake parcel delivery fee and the "unusual activity on your account" text are the familiar versions. Forward any suspicious text to 7726, a free service most UK mobile networks support, which the NCSC explains here.
Phone scammers are becoming more patient. One large business in the survey described a call that nearly cost them half a million pounds. The attackers had researched the person they targeted for 12 months beforehand.
How to check a website before you log in
A padlock in the address bar only means the connection is encrypted. It doesn't mean the site is genuine.
The safest habit is not to log in through links at all. Type the address yourself or use a bookmark. Both Google Chrome (Enhanced protection, under Security settings) and Microsoft Edge (Defender SmartScreen) have built-in phishing protection that warns you about known fake sites. Make sure it's switched on across your team's devices.
A password manager helps here too. It won't autofill your details on a look-alike site, because the address doesn't match the real one it saved.
Is multi-factor authentication effective against phishing?
Yes, with one caveat. Multi-factor authentication (MFA) means a stolen password alone isn't enough to get into an account. That's why it's one of the most effective things a small business can switch on. Yet only 47% of UK businesses require it.
The caveat is that some types can still be phished. If a fake login page asks for your one-time code and you type it in, the attacker can use it straight away. The NCSC's guidance on MFA recommends phishing-resistant options, such as passkeys, wherever your systems support them.
Train your team, then test them
Knowing how to protect yourself from phishing attacks is a skill, and skills fade without practice. Only 19% of UK businesses ran any cyber security training last year, and 22% tested staff with mock phishing emails.
You don't need a big budget to start. The NCSC's Top Tips for Staff training is free, aimed at small organisations and takes under 30 minutes. We've written about why cyber security training pays off in more detail.
The most useful thing you can teach isn't a list of red flags, though. It's that reporting a mistake quickly will never get anyone in trouble. People who fear blame stay quiet, and silence is what turns a click into a breach.
What to do if you've clicked a phishing link
- Tell your IT partner straight away. Minutes matter more than embarrassment.
- Disconnect the device from the network if you downloaded or opened anything.
- Change the password for any account you entered details into, using a different device, and anywhere else you've reused it.
- Call your bank immediately if you shared payment or banking details.
- Report it (see below).
How to report phishing in the UK
- Suspicious emails: forward to report@phishing.gov.uk, the NCSC's free Suspicious Email Reporting Service.
- Suspicious texts: forward to 7726.
- If you've lost money or been hacked: report it to Report Fraud, which replaced Action Fraud. Businesses under a live cyber attack can call 0300 123 2040. In Scotland, call Police Scotland on 101.
Stopping phishing before it reaches an inbox
Training reduces mistakes. It can't eliminate them. That's why the strongest protection sits in front of your people, not behind them.
Good email security checks whether a sender is who they claim to be before a message is delivered. It also catches emails pretending to come from your own staff. Noble IT's cyber security service does exactly that. Identity threat detection then watches for the moment a login looks wrong, so a stolen password gets caught even if the phishing email got through.
Your team carries on with their day. We deal with the rest.
Right. Let's talk.
Want to know how exposed your team is to phishing right now? Our 360 Review looks at how your business is set up, including email security and MFA, then gives you a clear list of what to fix first. No obligations.
Statistics: Cyber Security Breaches Survey 2025/2026, Department for Science, Innovation and Technology and the Home Office, published 30 April 2026.
Share this article: