Phishing

A member of your finance team gets an email from a regular supplier. Bank details have changed. The invoice gets paid.

A few days later, the real supplier calls asking where their money is.

“gulp”

This is the phishing risk small businesses now face. 

AI has made attacks cleaner, more personal, and harder to dismiss as obviously dodgy. The old advice about spelling mistakes and suspicious links still matters, but it’s not enough on its own. 

This article explains what’s changed in phishing protection, why staff training alone won’t protect you, and what practical controls actually work.

Why phishing is harder to spot now

Phishing emails used to announce themselves. Broken English, poor formatting, generic greetings, links that obviously didn’t match the company.

That’s changed. AI lets scammers produce cleaner, more targeted attacks — and the results look like ordinary business admin.

Scammers also personalise at speed, pulling details from LinkedIn, Companies House, social media, or previous data breaches to make messages feel relevant. Voice cloning adds another layer, creating calls or messages that sound like someone familiar.

The real issue is that these attacks look routine. Which means SMEs need to stop thinking about phishing as “spotting a dodgy email” and start thinking about it as “removing weak points in our processes.”

Pro Tip: If a voice message or call creates pressure to act fast (payment, passwords, bank details) treat that urgency as a red flag, not a reason to rush. Legitimate requests can wait five minutes for a call-back verification.

Why staff awareness alone isn’t enough

Training your team to spot phishing is still useful, of course, but it has a limit.

If an email is well-written, sent at the right time, and based on a real relationship, it won’t trigger alarm bells. If a voice message sounds like your boss, staff feel uncomfortable questioning it. If an urgent request arrives late Friday, the pressure to act can override good judgment.

The National Cyber Security Centre’s advice is clear: use several controls together rather than relying on one line of defence. (And we’ve covered the foundations of that approach in part one of this series.)

For SMEs, that means your staff should never be the only thing standing between a convincing scam and your bank account.

Instead of expecting people to make perfect decisions under pressure, give them a process to follow. That makes it easier to say “I need to verify this before we pay,” even if the request appears to come from a director or supplier.

Pro Tip: Write the process down and keep it somewhere visible: a shared doc, a pinned Teams message, a laminated sheet by the printer. When people are under pressure, they reach for the checklist, not their memory banks.

The controls that work

You don’t need complicated security; you need consistent security.

Pro Tip: Set MFA as a non-negotiable on Microsoft 365 first. It’s where most SME phishing attacks land, and it’s free to enable. The Microsoft 365 admin centre lets you enforce it across all users in under 30 minutes.

The verification process your team should follow

Make this simple so people follow it when they’re busy.

  1. Pause if the request involves money, login details, bank details, or confidential data — especially if it includes pressure: “Can you do this today?” or “This needs paying before close of business.”
  2. Check whether the request makes sense. Is there an invoice due? Were you expecting a bank detail change? Does it fit how your business normally handles things?
  3. Verify through a trusted route. Use a phone number from your accounting system, the supplier’s official website, a contact in your CRM, or a direct conversation. Don’t reply to the same email, click links in the message, or call the number that contacted you.
  4. Get second approval for high-risk actions. Payments, bank details, payroll data, customer information — one person doesn’t decide alone.
  5. Report anything that looks wrong. Keep it internal: “We’ve received a fake invoice from [supplier]. Don’t click links or process bank changes. Send anything similar to [contact].”

Simple. Repeatable. Doesn’t slow the business down.

Where to start 

Three questions are worth asking right now:

If any answer is unclear, it’s worth a conversation.

Operum Tech helps SMEs implement practical phishing protection before an attempt results in fraud or data loss. We can review where MFA is missing, tighten Microsoft 365 security, design payment approval processes, and train staff with realistic scenarios they’ll actually see.

Get in touch if you’d like us to take a look at your current setup.

Sign up below to join the Operum newsletter