Two-factor authentication
A phished credential is no longer enough. This is the technical measure with the best effort-to-protection ratio.
RISK · PHISHING
The most dangerous message is the one that looks like your daily routine.
Phishing has little to do with the typo-ridden email of ten years ago. Today’s messages reuse your visual identity, name real colleagues and arrive at the moment when the requested action looks normal — a change of banking details at month end, an invoice during the payment window. Verizon’s annual breach report places the human element in the large majority of incidents. This is not about how clever your employees are, but about context and workload.
Org chart on your website, professional profiles, press releases: the attacker learns who approves payments and who deals with suppliers.
The message leans on a real event: an ongoing project, a known invoice, a publicly announced trip.
Urgency, requested confidentiality, the executive supposedly unavailable: everything is designed to prevent verification through another channel.
A transfer, a change of banking details, or entering credentials on a page that mimics your usual tool.
These reflexes are learned in one session and stick if they are refreshed regularly.
A phished credential is no longer enough. This is the technical measure with the best effort-to-protection ratio.
Any change of banking details is confirmed by phone to a number already on file, never to the one given in the message.
SPF, DKIM and DMARC correctly configured stop anyone from spoofing your own domain to fool your customers.
Training works, but it fades. A quarterly rhythm keeps the reflex alive.
A button to flag a doubt, and a guarantee that an employee who clicked will not be sanctioned. That is what buys you hours.
Reaction time matters more than the mistake. These steps must be known by everyone, not just IT.
They can be answered in one meeting, and the result is often instructive.
We start with a measurement campaign that gives your real click rate, without naming anyone.
Measure our exposure