Phishing & Email SecurityCommercial

How to stop phishing in your business: a 30-day plan

Practical steps combining email controls, MFA, training and simulations — week by week.

10 February 2026 7 min read
How to stop phishing in your business: a 30-day plan — Phishing & Email Security illustration

You can't eliminate phishing. You can make it dramatically less effective in 30 days, with measurable controls and a routine your team can actually live with.

Week 1 — Lock down identity

  • Enforce MFA on every cloud account, including service accounts and ex-staff.
  • Move admins to phishing-resistant MFA (passkeys or FIDO2 keys).
  • Turn on Conditional Access: block legacy auth, enforce compliant devices.
  • Audit and disable unused accounts, mailboxes and tokens.

Week 2 — Harden email

  • Verify SPF, DKIM and DMARC are all configured.
  • Move DMARC to p=quarantine, then p=reject, monitoring reports.
  • Enable click-time URL protection and attachment sandboxing.
  • Block lookalike domains and known-malicious senders at the gateway.

Week 3 — Train and simulate

  • Roll out a short (10-minute) phishing module to every member of staff.
  • Add a 'Report Phishing' button to every mailbox — make reporting one click.
  • Run a baseline phishing simulation. Don't punish clicks; measure them.
  • Brief managers on the results and the plan to improve.

Week 4 — Detect and respond

  • Confirm EDR is on every endpoint and alerts go somewhere a human reads.
  • Document a one-page incident plan for suspected compromise.
  • Run a tabletop exercise: 'a finance user just typed their password into a fake page'.
  • Schedule ongoing simulations and quarterly micro-training.

What good looks like at day 30

  • 100% MFA coverage, phishing-resistant for admins.
  • DMARC at p=reject with clean reports.
  • Simulation click rate trending down month-on-month.
  • Mean time to report a suspicious email under 5 minutes.
  • EDR coverage at 100% with monitored alerts.

Next step

If you'd like a partner to run this plan with you — including the tooling and the 24/7 monitoring — book a free 30-minute review and we'll scope it to your business.

Related services

Free cyber security review

Get a plain-English view of where your business stands.

30 minutes with a UK specialist. No obligation, no sales pitch.

Book my free cyber security review