Phishing remains one of the most effective ways to attack a small or midsize business.
The technology has changed. The goal has not.
Attackers still want employees to click a link, open an attachment, approve a login, change payment details, or share sensitive information. In 2026, those requests look more convincing than ever. Artificial intelligence helps criminals write polished messages. Lookalike domains make fake websites harder to spot. QR codes, text messages, voice calls, and collaboration platforms extend phishing beyond the inbox.
Your employees are still the frontline defense.
That does not mean you should blame them when a convincing message gets through. It means your security strategy must give them the training, tools, and support needed to make safe decisions under pressure.
The strongest approach combines practical awareness with layered technical defenses. Here is what that looks like for an SMB.
WHY EMPLOYEES REMAIN THE FRONTLINE
Most phishing attacks are designed to manipulate a person, not simply exploit a software flaw.
An attacker may impersonate:
- Your CEO requesting an urgent payment
- A vendor asking to update banking information
- Microsoft 365 or Google Workspace requesting a password reset
- A customer sending a shared document
- A payroll provider requesting employee details
- A help desk technician asking to re-enroll MFA
- A delivery company asking someone to scan a QR code
The message may come from a compromised legitimate account. It may pass basic email authentication checks. It may contain perfect grammar. It may arrive through email, text, Teams, Slack, LinkedIn, or a phone call.
That is why “look for spelling mistakes” is no longer enough.
Employees make the final decision at several important points:
- Should I open this attachment?
- Should I follow this link?
- Should I approve this login?
- Should I change this vendor’s payment information?
- Should I share this data?
- Should I report this message?
Technology can reduce the number of dangerous messages that reach your team. It cannot eliminate every judgment call.
Your people need to know what to do when something feels unusual. They also need permission to slow down. A culture that rewards speed at all costs can unintentionally help attackers. A culture that supports verification makes phishing much harder to complete.
PHISHING TRAINING MUST MATCH REAL WORK
Annual security training is better than no training. It is not enough by itself.
Employees do not retain a slide deck because it was assigned once. They build reliable habits through repetition, relevant examples, and quick feedback.
The Cybersecurity and Infrastructure Security Agency’s guidance for small businesses recommends teaching employees how to recognize and report phishing. Your program should go further by connecting those lessons to your actual workflows.
USE REALISTIC SCENARIOS
Training should reflect the messages your employees genuinely receive.
For example:
- Finance staff practice verifying vendor payment changes
- HR staff practice handling payroll and employee-record requests
- Executives practice identifying impersonation attempts
- Sales staff practice checking shared documents and customer links
- Operations staff practice responding to shipping or invoice scams
- Administrators practice resisting fake MFA reset requests
The goal is not to trick employees or embarrass them. The goal is to rehearse the correct response before a real attack creates pressure.
KEEP TRAINING SHORT AND FREQUENT
A practical SMB program can include:
- One formal training session each year
- Five- to ten-minute refreshers each month
- Targeted updates when a new threat affects your industry
- Periodic phishing simulations
- Immediate coaching after a simulated click
- A simple reporting process available in the email client
CISA also recommends using the strongest available multifactor authentication and recurring employee awareness efforts. You can review its MFA guidance for small and midsize businesses as a baseline.
MEASURE THE RIGHT BEHAVIORS
A low click rate is useful. It is not the only measure that matters.
Track whether employees:
- Report suspicious messages
- Verify financial requests through a separate channel
- Reject unexpected MFA prompts
- Avoid entering credentials through email links
- Contact the help desk quickly after a mistake
- Follow the established incident process
A strong reporting culture is a security control. Employees should never fear punishment for reporting a mistake. Early reporting gives your IT team time to reset credentials, remove malicious messages, and investigate unusual activity.

TECHNICAL DEFENSES SHOULD CATCH WHAT PEOPLE MISS
Training is essential. It is not a replacement for proper security engineering.
Your controls should assume that someone will eventually click. The objective is to block the message, prevent credential abuse, limit access, and detect suspicious activity quickly.
PROTECT YOUR EMAIL DOMAIN
Configure and monitor:
- SPF
- DKIM
- DMARC
- Secure email filtering
- Malicious link analysis
- Attachment scanning
- Impersonation protection
- A built-in phishing report button
SPF, DKIM, and DMARC help prevent criminals from spoofing your own domain. They do not prove that every authenticated message is safe. A legitimate account can be compromised, and attackers can use reputable platforms to deliver malicious content.
Email authentication is one layer. It is not a complete phishing strategy.
REQUIRE PHISHING-RESISTANT MFA
Multifactor authentication can stop a stolen password from becoming a compromised account. However, not all MFA methods provide the same level of protection.
Whenever possible, prioritize:
- Passkeys
- FIDO2 or WebAuthn security keys
- Device-bound authenticators
- Authenticator apps with number matching
These methods are more resistant to credential harvesting and MFA fatigue than SMS codes or simple “approve” push notifications.
Start with your highest-risk accounts:
- Administrators
- Executives
- Finance users
- Remote access users
- Email and cloud platform accounts
- Employees with access to sensitive customer data
The CISA phishing-resistant MFA fact sheet explains the concept and rollout considerations in plain language.
BLOCK LEGACY AUTHENTICATION
Older protocols can allow attackers to bypass modern security controls. Disable legacy authentication where your platforms support that option.
Also review:
- Conditional access policies
- Risk-based login controls
- Unusual geographic access
- Unmanaged device access
- External forwarding rules
- OAuth application permissions
- Privileged account activity
These controls make a stolen password less useful to an attacker.
PROTECT ENDPOINTS AND NETWORKS
If a malicious link downloads a file or launches a script, endpoint protection should detect the behavior.
Your security stack should include:
- Endpoint detection and response
- Updated operating systems and browsers
- Browser protection against known malicious sites
- DNS filtering
- Network segmentation where appropriate
- Centralized logging
- Backup and recovery controls
- Monitoring for unusual data transfers
This is where network management services and security operations work together. A network cannot be protected effectively if no one knows what devices are connected, which systems communicate, or what normal activity looks like.

CREATE SIMPLE VERIFICATION PROCESSES
Attackers succeed when employees must make high-impact decisions quickly.
Written procedures reduce that pressure.
Require a second verification channel for:
- Wire transfers
- Vendor banking changes
- New payees
- Payroll changes
- Password resets
- MFA re-enrollment
- New administrator accounts
- Requests for sensitive customer or employee data
Do not verify using the phone number or link provided in the suspicious message. Use a known number from your vendor record, an established internal contact, or a trusted portal.
A simple policy can say:
> No payment or account-security change is approved from email alone. Verify the request through a known channel and document the confirmation.
That single rule can prevent a costly business email compromise incident.
WHAT TO DO AFTER SOMEONE CLICKS
Assume that mistakes will happen. Prepare your response before an incident.
Employees should know to:
- Stop interacting with the message.
- Report it immediately.
- Tell the help desk exactly what they clicked or entered.
- Change the affected password from a trusted device if instructed.
- Approve no unexpected MFA prompts.
- Avoid deleting evidence until IT or your security provider confirms it is safe.
- Watch for follow-up calls or messages from the attacker.
Your IT team should then determine whether to:
- Revoke active sessions
- Reset credentials
- Review mailbox forwarding rules
- Remove malicious inbox messages
- Check endpoint activity
- Search for unauthorized access
- Notify affected parties when required
- Document the incident and improve controls

HOW FIVE 9 CAN HELP
A strong phishing program does not require you to build everything alone.
Five 9 provides cybersecurity consulting to help identify vulnerabilities, improve controls, support compliance requirements, and prepare incident response procedures. We can also support your broader small business IT support needs, including infrastructure, identity, cloud, and endpoint security.
Our process is practical:
- Assess your current security posture
- Identify the highest-impact gaps
- Prioritize improvements based on risk and budget
- Implement the right controls
- Test whether those controls work
- Train your internal team
- Document the solution
- Continue monitoring and adjusting as your business changes
The goal is not to create dependency. The goal is to solve the immediate problem while giving your team the knowledge to maintain the result.
A typical security assessment can be completed in approximately one to two weeks, depending on the number of systems, locations, and compliance requirements involved. Project work and ongoing support can be structured separately. We will explain the scope, timeline, and pricing after understanding your environment.
START WITH AN HONEST CONVERSATION
Phishing will continue to evolve. Your defense needs to evolve with it.
Start by asking:
- Can every employee report a suspicious message in under a minute?
- Are high-risk payment and account changes verified out of band?
- Is phishing-resistant MFA available for critical users?
- Can you disable a compromised account quickly?
- Do you know which devices and systems need monitoring?
- Have you tested your response process recently?
If you are unsure, that is useful information. You do not need to fix everything at once.
Contact Five 9 for a straightforward, no-pressure conversation about your current risks and next steps. We will tell you honestly where we can help, what should be prioritized, and when another approach may make more sense.
Your team is part of your security strategy. Give them the training, processes, and technical support to make that strategy work.
