October is Cybersecurity Awareness Month, which makes it a good moment to talk about the single most common way small businesses get compromised. It is not sophisticated hacking. It is an email that convinces somebody to click.
The trouble is that most phishing advice is a decade out of date. “Look for spelling mistakes” and “watch for bad grammar” were useful when scam emails were written by people who did not speak the language. Today they are written by software that writes perfectly. The typos are gone. You need better tests.
Four Tests That Still Work
1. Read the actual sending address, not the display name
The name shown on an email is decoration. Anyone can put “Microsoft Support” or your own boss’s name there. Tap or click the sender name to reveal the real address behind it.
Then read it right to left. The important part of a web address is the bit immediately before the first single slash. microsoft.com.security-alert.co is not Microsoft; it is a site called security-alert.co. Scammers rely on you reading left to right, seeing a familiar name first, and stopping there.
2. Hover before you click
On a computer, resting your cursor over a link shows its true destination in the corner of the window. On a phone, press and hold. If the visible text says one thing and the destination says another, that is your answer. Be especially wary of links that go to a document-sharing or form-building service you do not use; those are popular because the domain itself looks legitimate.
3. Notice when you are being rushed
Nearly every scam creates artificial time pressure: your account will be closed today, the invoice is overdue, the payment must go out before end of business, your mailbox is full and messages are being deleted. Urgency exists to stop you thinking. Real organizations, including every bank we have ever dealt with, are perfectly willing to let you call them back.
4. Verify through a channel you chose
This is the one habit that defeats essentially all of it. If a message asks you to do something consequential, do not use the phone number, link, or reply address in the message. Look the company up yourself, or call the person on the number you already have for them.
The Two That Target Businesses Specifically
The fake boss request. An email appearing to come from the owner or a senior manager, often saying they are in a meeting and cannot talk, asking someone to buy gift cards, change payroll details, or wire a payment urgently. The tell is always the combination of authority, urgency, and a request to move money in an unusual way. Any business handling payments should have a standing rule: payment detail changes get verified by a phone call, every time, no exceptions for the boss.
The invoice that is almost right. Attackers who get into an email account often sit quietly and read for weeks, then send a real-looking invoice at the exact moment one is expected, with the bank details changed. This is why the phone call rule matters more than any software.
Reduce How Much Reaches You in the First Place
Human vigilance is the last line, not the first. Two technical measures do a lot of the work before anyone has to make a judgment call:
- Email authentication on your own domain. Correctly configured SPF, DKIM, and DMARC records make it dramatically harder for anyone to send mail that appears to come from your business. We wrote about how these work here.
- Multi-factor authentication everywhere. When someone does eventually give up a password, and statistically someone will, MFA is what keeps that mistake from becoming a breach.
If Someone Already Clicked
Speed matters more than blame. Change the password on that account immediately and sign out all other sessions. Turn on MFA if it was not already. Check the account’s forwarding rules and filters, because a very common move after a break-in is to quietly forward or auto-delete incoming mail so the real owner never sees the replies. Then tell whoever handles your IT, even if you are not sure anything happened.
Nobody should be embarrassed about this. These messages are convincing by design, and the people who fall for them are usually the ones who were busy and trying to be helpful.
If you would like us to review your email security or run through this with your staff, contact us.

