Turn on phishing-resistant sign-in, write one hard rule about payment changes, and put a report button in your mail client. Those three jobs will stop more fraud this year than any amount of extra training, and a small team can finish all three inside a month. Training still matters, but it is the fourth item on the list, not the first.

What phishing actually looks like in 2026
The shape of the problem has shifted, and it is worth being precise about how. Verizon’s 2026 DBIR, the 19th edition of the report, found phishing present in 16% of breaches, unchanged from the previous year. Pretexting, where an attacker builds a believable back-and-forth rather than firing off a single lure, reached 6%. Social engineering as a whole was the third most common breach pattern at 16%, and the broader human element showed up in 62% of breaches, a slight rise from 60%.
Volume is up as well. The Anti-Phishing Working Group reported that phishing attacks rose 10.1% in the second quarter of 2026 and that June alone accounted for 425,808 attacks, the highest monthly figure since April 2023. The same report put the increase in smishing, phishing over SMS, at 40% between the first and second quarters.
In the UK, the Department for Science, Innovation and Technology’s Cyber Security Breaches Survey 2025/2026 found 43% of businesses had identified a breach or attack in the previous 12 months, and phishing was by far the most common form, experienced by 38% of businesses and 25% of charities. For 69% of the organisations that had an incident, phishing was also the most disruptive one.
Two numbers explain why this is a board-level topic rather than an IT chore. IBM’s 2026 Cost of a Data Breach Report, which studied 602 breached organisations, put the global average cost at USD 4.99 million, a 12% rise and a record for the series. And the FBI’s Internet Crime Complaint Centre recorded USD 3,046,598,558 in reported business email compromise losses across 2025, out of 1,008,597 complaints of all types. BEC is phishing with an invoice attached, and it is the variant that empties bank accounts.
Why awareness training runs out of road
Here is the awkward finding. The DBIR puts the median click rate in email phishing simulations at 1.4%. That is already low. Most organisations running quarterly simulations are optimising a number that is close to its floor, and the remaining clicks come from a small group of people under time pressure rather than from general ignorance.
Meanwhile the channel moved. The DBIR’s data on voice- and text-based simulations shows a median click rate closer to 2%, roughly 40% higher than email on the same population. Verizon is candid that this sample is smaller than the email one, because few vendors run phone-based simulations yet. The direction is still clear: as people got better at spotting dodgy emails, attackers moved to the device in their pocket.

There is a visibility problem buried in that shift too. Verizon notes that the mobile phishing attempts it counted were only detectable because the devices were managed, either company-owned or enrolled in mobile device management. If your team does company work on purely personal, unenrolled phones, those attempts are happening and nobody is counting them.
None of this means cancel the training. It means stop treating training as the control and start treating it as the thing that makes your controls tolerable. The UK survey found 58% of businesses have an agreed process for staff to follow when they meet a fraudulent email or website. That process is worth more than another slide deck.
Phishing-resistant sign-in is the one that matters
A stolen password is only useful if it still opens the door. Phishing-resistant authentication, which in practice means passkeys or a hardware security key using FIDO2 and WebAuthn, binds the login to the real domain. A convincing copy of your sign-in page cannot replay it, because the credential refuses to answer to the wrong origin. CISA’s fact sheet on implementing phishing-resistant MFA is blunt that this is the strongest form available and should be the target state.
Codes from an authenticator app are a real improvement over nothing and over SMS, but they are not phishing-resistant. An attacker-in-the-middle page relays the code in real time and walks away with the session token. Microsoft’s security team documented exactly that in May 2026 in a multi-stage campaign that used a fake code-of-conduct notice to harvest tokens from users who had MFA switched on. The second factor was present. It just was not the right kind.
Start with the accounts that would hurt most: the email tenant admins, the finance mailbox, the domain registrar, the payment gateway and anyone who can approve a bank transfer. Give them keys or passkeys first, then widen the circle. Our guide to multi-factor authentication walks through the method choices and the recovery traps in more detail, and the current password rules matter here too, because the password is still the fallback when a device is lost.

Harden the email channel itself
Two thirds of the work on the mail side is configuration you only do once. Publish SPF, sign with DKIM and set DMARC to an enforcing policy so nobody can send mail that claims to be from your domain. Turn on external-sender warnings. Block or sandbox the attachment types your business genuinely never exchanges. Switch on impersonation protection for your executives and your finance aliases, because display-name spoofing is cheap and effective.
Then look at what actually gets blocked, because the mix tells you where to spend attention. The DBIR’s breakdown of blocked phishing email shows roughly 10% carrying malware, about 5% trying to get the recipient to call the attacker back, and around 3% in the business-email-compromise shape, where someone poses as a known contact and asks for bank details to be updated ahead of a transfer. That last 3% is the expensive slice.
- DMARC is at
p=quarantineorp=reject, notp=none. - Legacy authentication protocols that bypass modern sign-in policy are switched off.
- Auto-forwarding rules to external addresses are blocked or alerted on.
- Mail from your own domain arriving from outside is flagged as suspicious.
The money rule: nobody changes bank details over email
This is the cheapest control in the whole article and the one most businesses skip. Write down that bank details are never changed on the strength of an email, a PDF or a message in a chat thread. Changes are confirmed by calling the supplier on a number you already hold, not a number in the message, and the call is made by a second person who is not the one who received the request.
The APWG’s second-quarter 2026 data shows why. Wire-transfer BEC attempts rose 88% in the quarter, and the average amount the fraudsters tried to take went up 45% to USD 61,732 per attempt. One successful attempt pays for a decade of security keys.
The attack does not need to break anything technical. It only needs one person to believe a plausible email about an invoice.
Put the rule where the work happens: in the finance process document, in the supplier onboarding form, in the accounts payable checklist. A policy nobody can find is a policy nobody follows. The UK NCSC’s phishing guidance for organisations makes the same point about designing processes so that a single mistake cannot complete a payment.
Make reporting the easiest thing an employee can do
Your best detection capability is the person who thinks something is off. Make that signal cheap to send. Both Microsoft 365 and Google Workspace have a report-phishing action you can pin to the toolbar, and it is worth the ten minutes it takes to deploy. Then make two promises and keep them: reports get a human reply, and nobody is ever told off for reporting something that turned out to be legitimate.
Measure the report rate alongside the click rate. A team that reports more is a team detecting more, and it gives you something to act on while the campaign is still running. Clicking is a lagging indicator; reporting is a leading one.
Decide in advance who gets the report at 17:45 on a Friday, and what they are allowed to do without waking anyone up: reset a password, revoke active sessions, pull a message from every mailbox that received it. If a credential did get away, treat it as a containment job rather than an email problem. The same reflexes you need after a ransomware incident apply here, on a smaller scale.
What this costs, honestly
Here is what the five controls cost in practice for a team of around 25 people. The striking thing is how much of it is configuration rather than purchase.
| Control | What it stops | Typical cost | Effort |
|---|---|---|---|
| Passkeys or security keys for admins and finance | Credential replay, attacker-in-the-middle, password spray | From USD 29 per key (Yubico Security Key NFC); passkeys are free on existing devices | A day, plus a recovery plan |
| DMARC at enforcement, SPF and DKIM | Exact-domain spoofing of your own brand | Included in your mail platform | A week of monitoring, then one change |
| Payment-change callback rule | Business email compromise and invoice fraud | Nothing | An afternoon to write and circulate |
| One-click report button and a named responder | Shortens the window between first click and containment | Included in Microsoft 365 and Google Workspace | An hour to deploy |
| Short, specific training on the current lures | Raises reporting, trims the residual click rate | Low, and often bundled with your mail security | Quarterly, 20 minutes |

Set against that, IBM’s 2026 figure of USD 4.99 million as the global average breach cost is not a number most small businesses will ever face in full. The useful way to read it is as a direction of travel: IBM reports the average has risen 12% in a year, and that detection and escalation plus lost business now make up 63% of the total. Both of those lines shrink when somebody reports the email on day one instead of day forty.
A thirty-day plan you can actually finish
Sequencing matters more than ambition. Run it like this and the hard part is done before anyone loses interest.
- Week one. List every account that can move money, change DNS or read the whole mail store. That list is usually shorter and stranger than people expect.
- Week two. Put passkeys or hardware keys on every account from that list, and register a spare key per person so a lost device is not a lockout.
- Week three. Deploy the report button, name the responder, and write the payment-change rule into the finance process.
- Week four. Move DMARC from monitoring to enforcement, switch off legacy authentication, and block external auto-forwarding.
- Then quarterly. Twenty minutes on what is circulating now, and a review of report rates rather than click rates.
If one of those weeks slips, let it slip. Weeks one and two carry most of the value, and a half-finished rollout that covers your finance team still removes the attack path that costs the most.
Frequently asked questions
Is SMS-based two-factor authentication better than nothing?
Yes, clearly better than nothing, and it is a reasonable stopgap while you roll out something stronger. But it is not phishing-resistant: a relay page captures the code in real time, and SIM swapping remains a live risk. Treat SMS as a floor you are moving off, not a destination, and prioritise your finance and admin accounts for passkeys first.
How often should we run phishing simulations?
Quarterly is plenty for most small teams, and monthly usually produces fatigue rather than learning. The DBIR’s median email click rate of 1.4% suggests there is little headroom left in that metric anyway. Track how many people report a suspicious message instead, and make sure every report gets a reply from a human.
Someone clicked and entered their password. What now?
Revoke active sessions first, then reset the password, then re-register the second factor. Check mailbox rules for new auto-forwards, check for newly registered MFA methods, and pull the message from every mailbox that received it. Only then start on the question of how it got through, because the attacker is working to a clock as well.
Do we need a separate email security product?
Often not at first. Microsoft 365 and Google Workspace both include impersonation protection, link checking and attachment handling that many businesses have never switched on. Configure what you already pay for, measure what still gets through, and buy against that evidence rather than a vendor’s threat slide.
Does any of this help against voice and text message scams?
Phishing-resistant sign-in and the payment-change callback rule both do, because neither depends on the message being an email. Managed or enrolled phones also give you some visibility, which unmanaged personal devices do not. The DBIR’s phone-based simulation data showing a 40% higher click rate is a good reason to cover this channel explicitly in your training.
We set up phishing-resistant sign-in, DMARC enforcement and reporting workflows remotely for clients worldwide as part of our cybersecurity services, including the recovery planning that stops a lost key becoming a lockout. Get in touch with Eudora Technology to talk about your project.



