IT glossary
Phishing
Phishing is a message, usually email, sometimes a text or a call, made to look like it comes from someone you trust, so you hand over a password or money.
The messages are mostly ordinary. A shared document that needs a login. A supplier updating their bank details. A request from a director, sent while they are visibly travelling, asking for something quickly and quietly. The convincing ones are convincing because they arrive in the middle of a real workflow, at a moment when the request is exactly what you would expect.
Why it matters to you
This is the most common starting point for security incidents in small and mid-sized organizations, and it is worth understanding for a practical reason: the defences that help are cheap and specific. Multi-factor authentication makes a stolen password much less useful. A rule that bank-detail changes are confirmed by a phone call to a known number stops the payment-redirect version entirely. Both cost almost nothing.
Nobody falls for phishing because they are careless
They fall for it because they were busy, the message was well made, and it appeared in a legitimate thread. Treating it as a failure of attention leads to the worst possible outcome, which is a culture where someone realises at 4pm that they typed their password into the wrong page and then says nothing until Monday.
Those few hours are usually the difference between a reset password and a real problem. So the useful measure of security awareness training is not how many people clicked. It is how quickly people report, and whether the person who reports is thanked rather than named. If your training programme produces shame, it is producing silence.
What actually helps
- MFA on every account, especially administrators and finance
- A payment verification rule that does not depend on email
- A one-click way to report a suspicious message, and a visible response when someone uses it
- Simulated phishing used to find gaps, not to score individuals
- A stated no-blame position, said out loud by someone senior
The misconception worth correcting
That you can spot phishing by looking for bad spelling and odd addresses. Some of it still looks like that. Plenty of it is sent from a genuine, compromised mailbox at a company you actually work with, and reads perfectly. Verification through a second channel is the habit that holds up; visual inspection is not.