Phishing is the most common way UK SMEs get breached. Not zero-days. Not state actors. A convincing email or message that gets one person to click, type a password, or approve an MFA prompt.
What phishing actually is
A phishing attack is any attempt to trick someone into doing something harmful — usually by impersonating a trusted brand, colleague or supplier. The goal is almost always one of three things:
- Steal credentials (usernames, passwords, MFA codes).
- Trick a payment (change bank details, approve an invoice).
- Install malware (a document, link or fake software update).
Why modern phishing slips past filters
2026's phishing rarely looks like the dodgy emails of a decade ago. Attackers now:
- Use legitimate services (Microsoft, DocuSign, Dropbox) to host the lure.
- Compromise a real supplier's mailbox and reply inside an existing thread.
- Generate clean, on-brand copy with AI — no spelling mistakes, correct tone.
- Send MFA-prompt-bombing or push-notification fatigue attacks.
The signals to train your team on
- Unexpected urgency — 'pay today', 'approve now', 'before close of business'.
- Any request to change bank details, even from a known supplier.
- A login page asking for credentials after clicking an email link.
- MFA prompts you didn't trigger.
- Attachments or links you weren't expecting, even from real contacts.
What actually reduces phishing risk
Awareness alone isn't enough. The combination that works:
- MFA on every account — ideally phishing-resistant (passkeys, FIDO2).
- Email authentication (SPF, DKIM, DMARC at p=reject).
- Modern email security that inspects URLs at click time, not just send time.
- Short, regular training plus realistic phishing simulations.
- A clear, blame-free reporting button so staff flag suspicious mail in seconds.
Next step
Book a free 30-minute review and we'll show you exactly which phishing controls you have today, which are missing, and which would have the biggest impact in your business.

