Phishing: Recognition and Organisational Defence

Modern phishing is no longer given away by bad spelling. Which techniques work, what to teach staff, and which technical controls actually catch it.

Phishing is the most common initial intrusion vector, and that has not changed in years. What has changed is the quality. The old tells (broken language, a Nigerian prince, a suspicious sender) no longer work as a filter: messages are grammatically flawless, reference the organisation's real processes, and often arrive from a genuine colleague whose account was compromised earlier.

Why "watch for spelling mistakes" is not enough

Three things have fundamentally changed.

Text quality. Since generative language models, linguistic error as a signal has disappeared. Producing an organisation-specific phishing message takes minutes.

Contextual accuracy. Attackers assemble from public sources (company registers, LinkedIn, press releases, your website) who reports to whom, when reporting periods fall, who authorises payments. The message references these.

The authenticated sender. The most dangerous variant arrives from a genuinely compromised partner account, replying within an existing thread. Here the technical checks (SPF, DKIM, DMARC) all pass, because the message really did come from there.

The six most common patterns

Worth teaching by name, because people recognise a named pattern.

1. Urgent official notice. "Your account will be locked within 24 hours." The urgency exists to remove thinking time.

2. Executive instruction (CEO fraud). A request in the chief executive's name for an urgent transfer or data, typically adding "I am in a meeting, do not call". Finance and HR are the targets.

3. Invoice change. A notice in a real supplier's name about a changed bank account. The most expensive variant, because a single transfer costs millions.

4. Shared document. "X has shared a file with you." The link leads to a convincing sign-in page.

5. MFA fatigue. Not a message: the attacker already has the password and repeatedly sends push notifications until the user approves one to make it stop.

6. QR code (quishing). The code arrives as an image, so the mail filter cannot see the link inside, and the user opens it on a personal mobile with no corporate protection.

The single best question to teach: "am I being asked to do something urgently that involves money or access?" If yes, the answer is always the same: verify through a different channel. Not the phone number given in the message.

What to teach, and what not to

Do not teach people not to click. That is an impossible expectation and builds guilt, which suppresses reporting. Someone afraid of being scolded will not mention that they clicked, and precisely the information enabling the fastest response is lost.

Teach them to report. The goal is not zero clicks but fast reporting. A one-button "report suspicious message" in the mail client, and a culture where even false alarms are thanked.

Teach process, not tells. Four-eyes principle for payments, verifying bank account changes by phone on the number in the contract, never sharing passwords or MFA codes by email. Process protects even when the message is perfect.

Differentiate by role. Finance faces invoice fraud, HR faces data requests, IT faces privilege escalation, executives face targeted attacks. The same material for everyone is waste.

Technical controls that genuinely help

Training does not replace technology.

Control What it catches
Phishing-resistant MFA (FIDO2) Stolen passwords and real-time proxy attacks
DMARC with enforcement (p=reject) Forged messages sent in your own domain's name
External sender marking The executive instruction pattern, when the sender is external
Link rewriting and time-of-click checks Malicious links activated after delivery
Attachment detonation in a sandbox Documents infected with macros or scripts
Conditional access Sign-ins from unknown devices or unusual locations

DMARC deserves emphasis. Many organisations have it configured but only in monitoring mode (p=none), which blocks nothing. Moving to enforcement (p=quarantine, then p=reject) is a few weeks of work and eliminates anyone's ability to send mail in your company's name.

How to measure

Three indicators, with quarterly simulations.

Click rate. The most obvious, but misleading alone. On a well-timed, well-written campaign even the best organisations produce 5 to 10 percent.

Report rate. The more important one. How many report the suspicious message? This shows the organisation actively defends rather than merely passively avoiding mistakes. A healthy target: report rate higher than click rate.

Time to first report. If the first report arrives within five minutes, the security team can block the campaign before most people open it.

Simulation is useful only when it is not punitive. A click should trigger immediate, short, factual feedback, not a list sent to the manager.

The most common organisational failure

Phishing defence often lives on two separate islands: IT configures the filter, HR orders the annual e-learning, and the two never meet. Meanwhile the biggest exposure sits in a process gap: no four-eyes principle on payments, or nobody verifies bank account changes.

For invoice fraud, both technology and training are secondary. There, a single process rule (a change of bank account is accepted only after verification by phone on the number in the contract) is worth more than any filter.

If you want to assess where your organisation stands, our training service starts with a baseline measurement and tracks improvement with quarterly simulations. We covered strengthening authentication in our article on MFA types.

Back to Insights
Related content

Related content

Questions on this topic?

Our specialists are happy to discuss what this means in your organisation's environment.