Skip to content

Cybersecurity

Phishing still works, here's why, and how to stop it

27 June 2026 · Syprical

Ask anyone who responds to cyber incidents for a living how attackers usually get in, and you’ll hear the same answer over and over: someone clicked something, or typed their password into a page they shouldn’t have. Phishing remains one of the most common starting points for business compromise, not because people are careless, but because good phishing is genuinely hard to spot.

Why it keeps working

Phishing exploits how work actually happens. A convincing email arrives at a busy moment, appears to come from a supplier or the boss, and asks for something routine: review this invoice, reset your login, approve this payment. It’s designed to bypass suspicion by looking normal.

Three things have made it worse:

  • It’s cheap and scalable. Attackers send enormous volumes; they only need a tiny success rate.
  • It’s more convincing. Fake login pages are pixel-perfect, and well-written lures (increasingly polished with AI) no longer have the tell-tale typos.
  • It targets the person, not the technology. No firewall stops an employee from voluntarily entering their password on a real-looking page.

The goal is usually one of two things: steal credentials (so the attacker can log in as your staff) or get malware running (via an attachment or link).

The defences that actually help

You can’t train your way to zero clicks. Eventually someone will click. So the strategy is layered: reduce how many bad emails arrive, make a click less catastrophic, and catch it fast when it happens.

1. MFA everywhere. If credentials are phished but the attacker still can’t log in without a second factor, you’ve turned a breach into a near-miss. This is the single most valuable control against phishing. Prefer app-based or hardware MFA over SMS where you can.

2. Email authentication (SPF, DKIM, DMARC). These make it much harder for someone to send email that appears to come from your domain, protecting your customers and your brand from impersonation. A surprising number of businesses have these misconfigured or missing.

3. Filtering and link protection. Modern email security strips or rewrites malicious links and quarantines obvious junk before it reaches an inbox.

4. Least privilege. If a phished account has access to everything, the damage is total. If it only has access to what that person needs, the blast radius is small.

5. A no-blame reporting culture. The most useful thing an employee can do is report a suspicious email quickly, even one they clicked. If people fear punishment, they stay quiet, and quiet is what attackers want. Make reporting one click and thank people for it.

A simple test for your team

Teach one rule that covers most cases: if a message creates urgency and asks you to log in, pay, or change bank details, stop and verify through a known channel, not the phone number or link in the message. A ten-second phone call to a number you already have has prevented countless fraudulent payments.

What to do this week

  • Confirm MFA is on for email and any finance systems.
  • Check your domain’s SPF, DKIM, and DMARC records are set correctly.
  • Agree on a dead-simple way for staff to report suspicious emails.

Want us to check whether your email is properly protected and run a friendly, no-shame phishing awareness session for your team? Reach out. It’s a quick win with outsized payoff.

Want help putting this into practice?

Book a free, no-obligation consult and we'll talk through your situation.

Get in touch