Skip to content
Eudora Technology
Home  / Insights
Cybersecurity

How to Stop Phishing Attacks on Your Business

The 102d Strategic Signal Battalion (102d SSB), Network Enterprise Center (NEC) – Baumholder held a ribbon cutting ceremony on Smith Barracks, Oct. 17, to mark the successful compl
Photo: 102d SSB completes NETMOD in Baumholder- Enhanced cybersecurity, network performance for DoD operations in USAG Rheinland-Pfalz’s footprint by U.S. Army USAG-RP by Linda Lambiotte, Public domain, via Wikimedia Commons

Turn on phishing-resistant sign-in, write one hard rule about payment changes, and put a report button in your mail client. Those three jobs will stop more fraud this year than any amount of extra training, and a small team can finish all three inside a month. Training still matters, but it is the fourth item on the list, not the first.

Quito, Ecuador (December 8, 2022) Homeland Security Secretary Alejandro Mayorkas met with Gabriela Gallegos, Director of International Operations, at the EcuCERT National Cybersecu
Most phishing never looks dramatic. It looks like an ordinary message in an ordinary inbox on an ordinary Tuesday afternoon, which is exactly why it keeps working.Photo: DHS Secretary Alejandro Mayorkas Visits EcuCERT National Cybersecurity Center by DHSgov, Public domain, via Wikimedia Commons

What phishing actually looks like in 2026

The shape of the problem has shifted, and it is worth being precise about how. Verizon’s 2026 DBIR, the 19th edition of the report, found phishing present in 16% of breaches, unchanged from the previous year. Pretexting, where an attacker builds a believable back-and-forth rather than firing off a single lure, reached 6%. Social engineering as a whole was the third most common breach pattern at 16%, and the broader human element showed up in 62% of breaches, a slight rise from 60%.

Volume is up as well. The Anti-Phishing Working Group reported that phishing attacks rose 10.1% in the second quarter of 2026 and that June alone accounted for 425,808 attacks, the highest monthly figure since April 2023. The same report put the increase in smishing, phishing over SMS, at 40% between the first and second quarters.

In the UK, the Department for Science, Innovation and Technology’s Cyber Security Breaches Survey 2025/2026 found 43% of businesses had identified a breach or attack in the previous 12 months, and phishing was by far the most common form, experienced by 38% of businesses and 25% of charities. For 69% of the organisations that had an incident, phishing was also the most disruptive one.

Verizon 2026 DBIR – what showed up in confirmed breaches
Human element present62%
Ransomware present48%
Third party involved48%
Social engineering pattern16%
Phishing action16%
Pretexting action6%
Percentages overlap: one breach often involves several of these at once. Source: Verizon 2026 DBIR.

Two numbers explain why this is a board-level topic rather than an IT chore. IBM’s 2026 Cost of a Data Breach Report, which studied 602 breached organisations, put the global average cost at USD 4.99 million, a 12% rise and a record for the series. And the FBI’s Internet Crime Complaint Centre recorded USD 3,046,598,558 in reported business email compromise losses across 2025, out of 1,008,597 complaints of all types. BEC is phishing with an invoice attached, and it is the variant that empties bank accounts.

Why awareness training runs out of road

Here is the awkward finding. The DBIR puts the median click rate in email phishing simulations at 1.4%. That is already low. Most organisations running quarterly simulations are optimising a number that is close to its floor, and the remaining clicks come from a small group of people under time pressure rather than from general ignorance.

Meanwhile the channel moved. The DBIR’s data on voice- and text-based simulations shows a median click rate closer to 2%, roughly 40% higher than email on the same population. Verizon is candid that this sample is smaller than the email one, because few vendors run phone-based simulations yet. The direction is still clear: as people got better at spotting dodgy emails, attackers moved to the device in their pocket.

Median click rate in phishing simulations, by channel
Email phishing simulations1.4%
Voice and text message simulationsabout 2%
A 40% higher median click rate on phone-centric vectors. Source: Verizon 2026 DBIR.
Quito, Ecuador (December 8, 2022) Homeland Security Secretary Alejandro Mayorkas met with Gabriela Gallegos, Director of International Operations, at the EcuCERT National Cybersecu
Simulation scores tell you less than they used to. What matters now is how fast a suspicious message reaches someone who can revoke a session.Photo: DHS Secretary Alejandro Mayorkas Visits EcuCERT National Cybersecurity Center by DHSgov, Public domain, via Wikimedia Commons

There is a visibility problem buried in that shift too. Verizon notes that the mobile phishing attempts it counted were only detectable because the devices were managed, either company-owned or enrolled in mobile device management. If your team does company work on purely personal, unenrolled phones, those attempts are happening and nobody is counting them.

None of this means cancel the training. It means stop treating training as the control and start treating it as the thing that makes your controls tolerable. The UK survey found 58% of businesses have an agreed process for staff to follow when they meet a fraudulent email or website. That process is worth more than another slide deck.

Phishing-resistant sign-in is the one that matters

A stolen password is only useful if it still opens the door. Phishing-resistant authentication, which in practice means passkeys or a hardware security key using FIDO2 and WebAuthn, binds the login to the real domain. A convincing copy of your sign-in page cannot replay it, because the credential refuses to answer to the wrong origin. CISA’s fact sheet on implementing phishing-resistant MFA is blunt that this is the strongest form available and should be the target state.

Codes from an authenticator app are a real improvement over nothing and over SMS, but they are not phishing-resistant. An attacker-in-the-middle page relays the code in real time and walks away with the session token. Microsoft’s security team documented exactly that in May 2026 in a multi-stage campaign that used a fake code-of-conduct notice to harvest tokens from users who had MFA switched on. The second factor was present. It just was not the right kind.

Start with the accounts that would hurt most: the email tenant admins, the finance mailbox, the domain registrar, the payment gateway and anyone who can approve a bank transfer. Give them keys or passkeys first, then widen the circle. Our guide to multi-factor authentication walks through the method choices and the recovery traps in more detail, and the current password rules matter here too, because the password is still the fallback when a device is lost.

Quito, Ecuador (December 8, 2022) Homeland Security Secretary Alejandro Mayorkas met with Gabriela Gallegos, Director of International Operations, at the EcuCERT National Cybersecu
A hardware security key is the least glamorous item in a security budget and usually the best value in it.Photo: DHS Secretary Alejandro Mayorkas Visits EcuCERT National Cybersecurity Center by DHSgov, Public domain, via Wikimedia Commons

Harden the email channel itself

Two thirds of the work on the mail side is configuration you only do once. Publish SPF, sign with DKIM and set DMARC to an enforcing policy so nobody can send mail that claims to be from your domain. Turn on external-sender warnings. Block or sandbox the attachment types your business genuinely never exchanges. Switch on impersonation protection for your executives and your finance aliases, because display-name spoofing is cheap and effective.

Then look at what actually gets blocked, because the mix tells you where to spend attention. The DBIR’s breakdown of blocked phishing email shows roughly 10% carrying malware, about 5% trying to get the recipient to call the attacker back, and around 3% in the business-email-compromise shape, where someone poses as a known contact and asks for bank details to be updated ahead of a transfer. That last 3% is the expensive slice.

Four settings worth checking this week
  • DMARC is at p=quarantine or p=reject, not p=none.
  • Legacy authentication protocols that bypass modern sign-in policy are switched off.
  • Auto-forwarding rules to external addresses are blocked or alerted on.
  • Mail from your own domain arriving from outside is flagged as suspicious.

The money rule: nobody changes bank details over email

This is the cheapest control in the whole article and the one most businesses skip. Write down that bank details are never changed on the strength of an email, a PDF or a message in a chat thread. Changes are confirmed by calling the supplier on a number you already hold, not a number in the message, and the call is made by a second person who is not the one who received the request.

The APWG’s second-quarter 2026 data shows why. Wire-transfer BEC attempts rose 88% in the quarter, and the average amount the fraudsters tried to take went up 45% to USD 61,732 per attempt. One successful attempt pays for a decade of security keys.

The attack does not need to break anything technical. It only needs one person to believe a plausible email about an invoice.

Put the rule where the work happens: in the finance process document, in the supplier onboarding form, in the accounts payable checklist. A policy nobody can find is a policy nobody follows. The UK NCSC’s phishing guidance for organisations makes the same point about designing processes so that a single mistake cannot complete a payment.

Make reporting the easiest thing an employee can do

Your best detection capability is the person who thinks something is off. Make that signal cheap to send. Both Microsoft 365 and Google Workspace have a report-phishing action you can pin to the toolbar, and it is worth the ten minutes it takes to deploy. Then make two promises and keep them: reports get a human reply, and nobody is ever told off for reporting something that turned out to be legitimate.

Measure the report rate alongside the click rate. A team that reports more is a team detecting more, and it gives you something to act on while the campaign is still running. Clicking is a lagging indicator; reporting is a leading one.

Decide in advance who gets the report at 17:45 on a Friday, and what they are allowed to do without waking anyone up: reset a password, revoke active sessions, pull a message from every mailbox that received it. If a credential did get away, treat it as a containment job rather than an email problem. The same reflexes you need after a ransomware incident apply here, on a smaller scale.

What this costs, honestly

Here is what the five controls cost in practice for a team of around 25 people. The striking thing is how much of it is configuration rather than purchase.

ControlWhat it stopsTypical costEffort
Passkeys or security keys for admins and financeCredential replay, attacker-in-the-middle, password sprayFrom USD 29 per key (Yubico Security Key NFC); passkeys are free on existing devicesA day, plus a recovery plan
DMARC at enforcement, SPF and DKIMExact-domain spoofing of your own brandIncluded in your mail platformA week of monitoring, then one change
Payment-change callback ruleBusiness email compromise and invoice fraudNothingAn afternoon to write and circulate
One-click report button and a named responderShortens the window between first click and containmentIncluded in Microsoft 365 and Google WorkspaceAn hour to deploy
Short, specific training on the current luresRaises reporting, trims the residual click rateLow, and often bundled with your mail securityQuarterly, 20 minutes
Indicative costs for a 25-person team. Hardware key price from Yubico’s own store, retrieved 1 October 2026.
Quito, Ecuador (December 8, 2022) Homeland Security Secretary Alejandro Mayorkas met with Gabriela Gallegos, Director of International Operations, at the EcuCERT National Cybersecu
Most of the phishing budget goes on configuration time rather than on licences, which is why small teams can close the biggest gaps in a month.Photo: DHS Secretary Alejandro Mayorkas Visits EcuCERT National Cybersecurity Center by DHSgov, Public domain, via Wikimedia Commons

Set against that, IBM’s 2026 figure of USD 4.99 million as the global average breach cost is not a number most small businesses will ever face in full. The useful way to read it is as a direction of travel: IBM reports the average has risen 12% in a year, and that detection and escalation plus lost business now make up 63% of the total. Both of those lines shrink when somebody reports the email on day one instead of day forty.

A thirty-day plan you can actually finish

Sequencing matters more than ambition. Run it like this and the hard part is done before anyone loses interest.

  1. Week one. List every account that can move money, change DNS or read the whole mail store. That list is usually shorter and stranger than people expect.
  2. Week two. Put passkeys or hardware keys on every account from that list, and register a spare key per person so a lost device is not a lockout.
  3. Week three. Deploy the report button, name the responder, and write the payment-change rule into the finance process.
  4. Week four. Move DMARC from monitoring to enforcement, switch off legacy authentication, and block external auto-forwarding.
  5. Then quarterly. Twenty minutes on what is circulating now, and a review of report rates rather than click rates.

If one of those weeks slips, let it slip. Weeks one and two carry most of the value, and a half-finished rollout that covers your finance team still removes the attack path that costs the most.

Frequently asked questions

Is SMS-based two-factor authentication better than nothing?

Yes, clearly better than nothing, and it is a reasonable stopgap while you roll out something stronger. But it is not phishing-resistant: a relay page captures the code in real time, and SIM swapping remains a live risk. Treat SMS as a floor you are moving off, not a destination, and prioritise your finance and admin accounts for passkeys first.

How often should we run phishing simulations?

Quarterly is plenty for most small teams, and monthly usually produces fatigue rather than learning. The DBIR’s median email click rate of 1.4% suggests there is little headroom left in that metric anyway. Track how many people report a suspicious message instead, and make sure every report gets a reply from a human.

Someone clicked and entered their password. What now?

Revoke active sessions first, then reset the password, then re-register the second factor. Check mailbox rules for new auto-forwards, check for newly registered MFA methods, and pull the message from every mailbox that received it. Only then start on the question of how it got through, because the attacker is working to a clock as well.

Do we need a separate email security product?

Often not at first. Microsoft 365 and Google Workspace both include impersonation protection, link checking and attachment handling that many businesses have never switched on. Configure what you already pay for, measure what still gets through, and buy against that evidence rather than a vendor’s threat slide.

Does any of this help against voice and text message scams?

Phishing-resistant sign-in and the payment-change callback rule both do, because neither depends on the message being an email. Managed or enrolled phones also give you some visibility, which unmanaged personal devices do not. The DBIR’s phone-based simulation data showing a 40% higher click rate is a good reason to cover this channel explicitly in your training.

We set up phishing-resistant sign-in, DMARC enforcement and reporting workflows remotely for clients worldwide as part of our cybersecurity services, including the recovery planning that stops a lost key becoming a lockout. Get in touch with Eudora Technology to talk about your project.

Sources

  1. 2026 Data Breach Investigations Report (19th edition) Verizon Business · 19 May 2026
  2. Phishing Activity Trends Report, 2nd Quarter 2026 Anti-Phishing Working Group · 2026
  3. 2025 Internet Crime Report FBI Internet Crime Complaint Center · 2026
  4. Cyber Security Breaches Survey 2025/2026 UK Department for Science, Innovation and Technology · April 2026
  5. Cost of a Data Breach Report 2026 IBM X-Force · July 2026
  6. Hardware security key price list Yubico · retrieved 1 October 2026
Keep reading

Related insights