Skip to content
../services/security

RISK · PHISHING

Phishing defence

The most dangerous message is the one that looks like your daily routine.

What it is

Phishing has little to do with the typo-ridden email of ten years ago. Today’s messages reuse your visual identity, name real colleagues and arrive at the moment when the requested action looks normal — a change of banking details at month end, an invoice during the payment window. Verizon’s annual breach report places the human element in the large majority of incidents. This is not about how clever your employees are, but about context and workload.

How a credible attempt unfolds

  1. 01

    Public research

    Org chart on your website, professional profiles, press releases: the attacker learns who approves payments and who deals with suppliers.

  2. 02

    A plausible pretext

    The message leans on a real event: an ongoing project, a known invoice, a publicly announced trip.

  3. 03

    Time pressure

    Urgency, requested confidentiality, the executive supposedly unavailable: everything is designed to prevent verification through another channel.

  4. 04

    The requested action

    A transfer, a change of banking details, or entering credentials on a page that mimics your usual tool.

The signals to recognise

These reflexes are learned in one session and stick if they are refreshed regularly.

  • An urgent request that implicitly forbids checking with someone else
  • A change of banking details received by email, however credible it looks
  • A sender address that is almost right, off by one letter or one domain
  • A login page reached through a link rather than through your usual bookmark
  • An unusual tone from someone you know well

The layers that genuinely reduce the risk

01

Two-factor authentication

A phished credential is no longer enough. This is the technical measure with the best effort-to-protection ratio.

02

Out-of-band verification procedure

Any change of banking details is confirmed by phone to a number already on file, never to the one given in the message.

03

Email authentication for your domain

SPF, DKIM and DMARC correctly configured stop anyone from spoofing your own domain to fool your customers.

04

Regular simulation campaigns

Training works, but it fades. A quarterly rhythm keeps the reflex alive.

05

A no-consequence reporting channel

A button to flag a doubt, and a guarantee that an employee who clicked will not be sanctioned. That is what buys you hours.

If someone clicked

Reaction time matters more than the mistake. These steps must be known by everyone, not just IT.

  1. 01Immediately change the affected password and revoke active sessions
  2. 02Check whether automatic forwarding rules were created in the mailbox — a classic move after a compromise
  3. 03Alert finance if a payment could have been triggered, and the bank without delay
  4. 04Search the logs for logins from unusual locations
  5. 05Inform the colleagues targeted by the same campaign, without naming the person who clicked

Five questions to place yourself

They can be answered in one meeting, and the result is often instructive.

  • Do you know your real click rate on a simulated campaign?
  • Is MFA active on every employee’s mailbox?
  • Is there a written rule for changes of banking details?
  • Are your SPF, DKIM and DMARC records correctly configured?
  • Would an employee who clicked know what to do within five minutes?

What we put in place

Your employees are not the weak link, they are the last line.

We start with a measurement campaign that gives your real click rate, without naming anyone.

Measure our exposure