A member of your finance team gets an email from a regular supplier. Bank details have changed. The invoice gets paid.
A few days later, the real supplier calls asking where their money is.
“gulp”
This is the phishing risk small businesses now face.
AI has made attacks cleaner, more personal, and harder to dismiss as obviously dodgy. The old advice about spelling mistakes and suspicious links still matters, but it’s not enough on its own.
This article explains what’s changed in phishing protection, why staff training alone won’t protect you, and what practical controls actually work.
Why phishing is harder to spot now
Phishing emails used to announce themselves. Broken English, poor formatting, generic greetings, links that obviously didn’t match the company.
That’s changed. AI lets scammers produce cleaner, more targeted attacks — and the results look like ordinary business admin.
- Fake invoices and supplier impersonation. Messages are tailored by role and reference real relationships. A finance assistant gets an invoice query that mentions a genuine supplier. An office manager gets a bank detail change that looks like routine admin. The payment request feels expected, so it gets processed.
- CEO fraud. AI can match the tone of a senior manager well enough that staff feel uncomfortable questioning it. In a small business where people know the owner personally, an urgent request from “the MD” is hard to push back on.
- Fake login prompts. A message that looks like a Microsoft 365, Teams, or Google Workspace invitation leads to a fake page. The staff member enters their password. The attacker gets access to email, files, contacts, and invoices.
Scammers also personalise at speed, pulling details from LinkedIn, Companies House, social media, or previous data breaches to make messages feel relevant. Voice cloning adds another layer, creating calls or messages that sound like someone familiar.
The real issue is that these attacks look routine. Which means SMEs need to stop thinking about phishing as “spotting a dodgy email” and start thinking about it as “removing weak points in our processes.”
Pro Tip: If a voice message or call creates pressure to act fast (payment, passwords, bank details) treat that urgency as a red flag, not a reason to rush. Legitimate requests can wait five minutes for a call-back verification.

Why staff awareness alone isn’t enough
Training your team to spot phishing is still useful, of course, but it has a limit.
If an email is well-written, sent at the right time, and based on a real relationship, it won’t trigger alarm bells. If a voice message sounds like your boss, staff feel uncomfortable questioning it. If an urgent request arrives late Friday, the pressure to act can override good judgment.
The National Cyber Security Centre’s advice is clear: use several controls together rather than relying on one line of defence. (And we’ve covered the foundations of that approach in part one of this series.)
For SMEs, that means your staff should never be the only thing standing between a convincing scam and your bank account.
Instead of expecting people to make perfect decisions under pressure, give them a process to follow. That makes it easier to say “I need to verify this before we pay,” even if the request appears to come from a director or supplier.
Pro Tip: Write the process down and keep it somewhere visible: a shared doc, a pinned Teams message, a laminated sheet by the printer. When people are under pressure, they reach for the checklist, not their memory banks.
The controls that work
You don’t need complicated security; you need consistent security.
- Multi-factor authentication (MFA) on Microsoft 365, email, accounting software, banking, CRM, and any system holding customer or financial data. A stolen password isn’t enough on its own. If someone enters their password into a fake login page, there’s another barrier.
- Clear payment approval rules. Any new payment, urgent payment, or change to payment details should be checked through a separate route before money leaves. Replying to the same email chain isn’t enough if that email account’s compromised.
- Never change supplier bank details by email alone. Verify using contact details already stored in your accounting system, CRM, or previous trusted correspondence. Don’t use the phone number or email in the change request.
- Call-back procedures using known numbers. If someone receives an urgent payment request or voice message, they verify by calling a number the business already has on file, not the number that just contacted them.
- Dual approval for high-risk actions. One person shouldn’t change supplier bank details, approve large payments, send payroll information, or create new admin users. Dual approval stops rushed decisions and protects the staff member from feeling they have to challenge authority alone.
- Simple reporting for suspicious emails. Staff need to know exactly who to contact. If reporting is awkward, people won’t do it (meaning the same scam reaches multiple people before anyone raises the alarm).
- Clear rules for out-of-hours requests. If a request involving money, bank details, or passwords arrives outside normal working hours, it must be verified before action. That rule gives staff permission to pause. In phishing prevention, that pause often stops the fraud.
Pro Tip: Set MFA as a non-negotiable on Microsoft 365 first. It’s where most SME phishing attacks land, and it’s free to enable. The Microsoft 365 admin centre lets you enforce it across all users in under 30 minutes.
The verification process your team should follow
Make this simple so people follow it when they’re busy.
- Pause if the request involves money, login details, bank details, or confidential data — especially if it includes pressure: “Can you do this today?” or “This needs paying before close of business.”
- Check whether the request makes sense. Is there an invoice due? Were you expecting a bank detail change? Does it fit how your business normally handles things?
- Verify through a trusted route. Use a phone number from your accounting system, the supplier’s official website, a contact in your CRM, or a direct conversation. Don’t reply to the same email, click links in the message, or call the number that contacted you.
- Get second approval for high-risk actions. Payments, bank details, payroll data, customer information — one person doesn’t decide alone.
- Report anything that looks wrong. Keep it internal: “We’ve received a fake invoice from [supplier]. Don’t click links or process bank changes. Send anything similar to [contact].”
Simple. Repeatable. Doesn’t slow the business down.
Where to start
Three questions are worth asking right now:
- Could someone access your email with only a stolen password?
- Could supplier bank details be changed based on an email?
- Would every staff member know what to do if they received a suspicious invoice or payment message?
If any answer is unclear, it’s worth a conversation.
Operum Tech helps SMEs implement practical phishing protection before an attempt results in fraud or data loss. We can review where MFA is missing, tighten Microsoft 365 security, design payment approval processes, and train staff with realistic scenarios they’ll actually see.
Get in touch if you’d like us to take a look at your current setup.
Sign up below to join the Operum newsletter