You can't eliminate phishing. You can make it dramatically less effective in 30 days, with measurable controls and a routine your team can actually live with.
Week 1 — Lock down identity
- Enforce MFA on every cloud account, including service accounts and ex-staff.
- Move admins to phishing-resistant MFA (passkeys or FIDO2 keys).
- Turn on Conditional Access: block legacy auth, enforce compliant devices.
- Audit and disable unused accounts, mailboxes and tokens.
Week 2 — Harden email
- Verify SPF, DKIM and DMARC are all configured.
- Move DMARC to p=quarantine, then p=reject, monitoring reports.
- Enable click-time URL protection and attachment sandboxing.
- Block lookalike domains and known-malicious senders at the gateway.
Week 3 — Train and simulate
- Roll out a short (10-minute) phishing module to every member of staff.
- Add a 'Report Phishing' button to every mailbox — make reporting one click.
- Run a baseline phishing simulation. Don't punish clicks; measure them.
- Brief managers on the results and the plan to improve.
Week 4 — Detect and respond
- Confirm EDR is on every endpoint and alerts go somewhere a human reads.
- Document a one-page incident plan for suspected compromise.
- Run a tabletop exercise: 'a finance user just typed their password into a fake page'.
- Schedule ongoing simulations and quarterly micro-training.
What good looks like at day 30
- 100% MFA coverage, phishing-resistant for admins.
- DMARC at p=reject with clean reports.
- Simulation click rate trending down month-on-month.
- Mean time to report a suspicious email under 5 minutes.
- EDR coverage at 100% with monitored alerts.
Next step
If you'd like a partner to run this plan with you — including the tooling and the 24/7 monitoring — book a free 30-minute review and we'll scope it to your business.

