Phishing is still the main route into UK business systems. The tactic is unchanged. The packaging has moved on. In 2026 the messages use AI-written copy, copied company branding and social pressure that a busy person can miss.
What phishing looks like today
Blatant prize and inheritance scams rarely reach a filtered inbox now. What arrives looks like ordinary work:
- A Microsoft 365 sign-in page that matches the real layout, served from a domain that is not Microsoft's
- A Teams message that appears to come from a director, asking for an urgent payment
- A note from "IT support" that sends the reader to a password-reset link
- A supplier invoice with bank details that have been quietly changed
- A shared-file alert that looks as if it came from SharePoint or Google Drive
Familiar name, short deadline. That is how the message gets through.
Why SMEs are targeted more than enterprises
Large companies usually keep a security team, inbound filtering and a staff awareness programme. Many SMEs don't. Criminal groups treat that gap as an opening.
The UK Government's Cyber Security Breaches Survey found that 50% of businesses reported a cyber attack or breach in the past year. Most of those incidents started with phishing.
How to protect your business
Email filtering
Microsoft Defender for Office 365, or a specialist product such as Mimecast, inspects every inbound message for harmful links, attachments and impersonation. Most of those messages never reach a person.
Multi-factor authentication (MFA)
A stolen password is not enough if the second factor is missing. MFA remains the control that most reliably stops a phished account from being used.
Security awareness training
Your team needs repeated practice, not a single slideshow. Simulated campaigns send realistic test messages. Anyone who clicks gets further training. The rest get a reminder that the threat is current.
DMARC, DKIM and SPF
These email authentication records stop attackers forging your domain when they write to clients and suppliers. If they're missing, someone else can send mail that looks as if it came from you.
Conditional access policies
You set who may sign in, from where, and on which devices. A Microsoft 365 attempt from an unknown device in another country can be refused on the spot.
Where automation belongs in the defence
Filtering and training still do most of the work. After a click, predictive monitoring watches for unusual sign-ins, new mailbox rules and credential use that doesn't match normal patterns. That shortens the window in which a stolen account can be exploited.
What to do if someone clicks a phishing link
- Change the password at once on the affected account
- Check MFA and end any active sessions
- Scan the device for malware
- Review mailbox rules, because attackers often add forwarding so they can read mail unnoticed
- Tell your IT provider, and report to Action Fraud if data was taken
A compromised account does more harm the longer it sits unnoticed. Act in minutes, not hours.
How Wanzo helps
Our cybersecurity service puts layered email security in place, enforces MFA across the organisation, runs phishing simulations and watches for compromised credentials. If an account is taken, the incident process starts without waiting for the next working day.
What to do next
If you want these controls on a monthly retainer rather than a one-off project, write to us. We'll review your email and identity setup and tell you what to fix first.