THE SHORT ANSWER

Phishing and business email compromise use deceptive messages or impersonation to obtain access, information or payments. Pause, inspect the request, verify consequential instructions through a known second channel and report suspicious activity without blaming the recipient.

Treat urgency and changed instructions as verification triggers

  • Unexpected login or file link
  • New bank or payment details
  • Pressure to bypass normal approval
  • Executive or vendor impersonation
  • A request for credentials, codes or secrecy
  • A familiar message from an unusual channel

PAUSE → VERIFY → SECOND CHANNEL → REPORT

Do not use contact details supplied only inside the suspicious request. Reach the person or vendor through a known directory, established number or separate trusted workflow.

Make reporting safe and fast

People hide mistakes when reporting leads to blame. Provide a clear path to report, contain and learn; design approvals so urgency cannot silently remove checks.

Turn guidance into an owned business action

Choose one relevant account, system, data set or workflow. Record the owner, current control, most important failure, detection signal, response step and recovery dependency. Escalate specialist, legal or regulatory questions to qualified advisers for the applicable context.

Sources & further reading

  1. Phishing Guidance: Stopping the Attack Cycle at Phase One

    Cybersecurity and Infrastructure Security Agency. Current defensive guidance on phishing resistance, MFA and organisational controls. Specific authentication choices depend on service support and risk.

Examples and exercises are illustrative unless attributed to a source. No independent expert review is claimed.

A correction, a counterexample or an experience worth sharing?

Join the conversation ↗