
Security
The attack that comes through email: how to actually prepare
Most business security incidents start with a message, not a technical flaw. Three defences work: making a stolen password useless with a second factor, breaking urgency with a written verification rule on payments, and training people with simulations instead of courses.
The image we carry of a cyber attack — a hooded genius forcing a system — is advertising. In reality, in a company, the most common entry point is an email: no technical flaw, no software breached. Someone opened something that looked normal.
And it does look normal today. Badly written messages with suspicious attachments still exist, but they are not what will hurt you. The ones that work continue a real conversation: they reply to an actual exchange of yours, quote an order that exists, arrive from the address of a supplier you know — because that supplier was breached before you.
The three attacks we actually see
- Credential theft. A page identical to your email login asks you to sign in again because "the session expired". From there the attacker reads everything and, above all, waits: stolen emails are what make the next move credible.
- Payment fraud. A supplier tells you their bank details have changed, inside an ongoing conversation, in a normal tone and with a consistent attachment. It is the single attack that costs small companies most, and it requires no technical skill to run.
- Data lockup. An attachment or link launches software that encrypts files and demands a ransom. Here the damage doesn't depend on how good the attacker was: it depends on how reachable your backups are.
The message that gets you doesn't look like an attack. It looks like Monday morning.What we repeat in training sessions
What works, in order of effectiveness
1. Second factor, everywhere. Email, business system, bank, admin panels, remote access. It makes a stolen password almost useless and it is the single measure with the best cost-to-effect ratio: it costs nothing and stops most credential theft.
An honest caveat: not all second factors are equal. A code by SMS is better than nothing but can be bypassed; a dedicated app is sturdier; a physical key or a passkey is the best defence available today, because it cannot be handed to a fake site.
2. A written payment procedure. Against bank-detail fraud no technology beats a simple rule: every change of bank details is verified by calling the number we already had on file, never the one written in the email. Add a second signature above a certain amount. Five lines worth more than any product.
3. Simulations, not courses. The annual course is forgotten in two weeks. What works is periodically sending fake attack emails: whoever falls for one finds out in a safe context and gets thirty seconds of explanation at the moment they are most receptive. It must be done without humiliating anyone — the goal is readiness, not a leaderboard — otherwise all you achieve is that people stop reporting.
The most important thing: make reporting easy
In every company, sooner or later, someone clicks. It is not a possibility: it is a statistical certainty, and it applies to careful people too. What separates an incident from a disaster is how much time passes between the click and the report.
If whoever slips fears a telling-off, they wait. They wait to be sure, they wait until the afternoon, maybe they never say it. Meanwhile the attacker is inside. That is why the rule we ask companies to state out loud is: whoever reports immediately is never told off, ever. It costs nothing and reduces damage more than any tool.
The first hour
You need a sheet, pinned up or shared, with five lines. Written beforehand, because nobody improvises well in the middle of an incident.
- Change the password of the account involved and close all active sessions, from another device.
- Tell the right person: a name and a number, not "IT".
- Isolate the affected computer from the network without switching it off — switching off destroys useful traces.
- Check outgoing payments and mail forwarding rules: attackers create one to keep reading your email even after losing access.
- Note times and facts as they happen. The bank, the insurer and — if you are subject to notification duties — the authority will need them, on tight deadlines.
What doesn't help
- Buying yet another product before putting second factor everywhere. Wrong order, and expensive.
- Banning everything. Overly tight rules get worked around, and the workarounds are worse than the original risk.
- Counting on being small. Email attacks don't select victims: they harvest them. Being unknown is not a defence.
If you must pick one thing to do this week: second factor on everyone's email, and the written rule on bank detail changes. Together they cover the two attacks that do the most damage to small companies.