Security

Protect your business from phishing

Phishing is still the most common way into a company, because it targets people and not only systems. The right answer is not a single product but several layers that catch what the other layers miss — and a partner who owns the setup.

Published 18 July 2026 7 min readBy Webits

In short

  • Phishing targets people, and small and mid-sized businesses are attractive targets precisely because the defence is often thinner.
  • A hosted spam filter, SPF/DKIM/DMARC, MFA and updates form the technical foundation that stops most of it before the inbox.
  • The human part is about knowing the warning signs and having a simple routine for reporting suspicious mail.
  • When someone clicks, speed and a prepared plan decide how large the damage becomes.

What is phishing — and why are you a target?

Phishing is an attempt to trick an employee into handing over information, clicking a malicious link or approving an action the attacker cannot perform themselves. The classic example is an email pretending to be from the bank, Microsoft or a colleague, asking for a login or a quick payment. It works because it exploits trust, busyness and recognisable senders — not technical holes.

The targeted variants are the most dangerous. Spear-phishing is tailored to one person with real names and details. CEO fraud impersonates the director and asks finance for an urgent payment. Business email compromise goes further and takes over a genuine mailbox, so the message really does come from a trusted address. What they share is that they look credible and create time pressure.

Many believe only large companies are of interest, but the opposite is often true. Small and mid-sized businesses have real money and access, yet more rarely have dedicated IT security, fixed payment procedures and ongoing training. That makes you an easier target with a reasonable payoff for the attacker — and therefore a deliberately chosen target, not a random one.

The technical layers of defence

The first layer is to stop as much as possible before it reaches the inbox. A hosted spam filter sits in front of your mail and screens out most spam, fraud and malicious attachments, while still letting genuine mail through. Because it runs as a service, the rules are updated continuously without you having to maintain anything yourself.

The next layer is about making sure your own domain cannot be abused. SPF, DKIM and DMARC are three settings in your DNS that together tell the rest of the world which servers may send mail on behalf of your domain, and what should happen to the rest. Set up correctly, they make it markedly harder for an attacker to impersonate you towards your customers and partners.

The third layer protects the account itself. Multi-factor authentication (MFA) means a stolen password is not enough — a code or an approval from a device the attacker does not have is also required. Combined with regular updates of operating systems, browsers and applications, you close the gaps that otherwise make a single click far more dangerous than it needs to be.

The human layer: habits and routines

No technology catches everything, which is why employees are the last and most important layer. The purpose of training is not to frighten people, but to make it a habit to pause for a moment when a mail asks for something unusual. A short, recurring refresher works better than a single long session, because the methods change and recognition needs to be kept fresh.

The warning signs tend to repeat, and they are worth knowing in advance. Most suspicious mails give themselves away through one or more of the items listed below — especially the combination of time pressure and a request for money or a login.

Just as important as recognition is a simple routine for reacting. Everyone should know where to report a suspicious mail, and that it is never embarrassing to ask. A culture where forwarding a doubtful mail to IT or a colleague is entirely normal catches far more than a policy no one remembers.

  • Unexpected time pressure or threats that something will be closed or blocked now.
  • A sender address that looks like, but does not quite match, the one you know.
  • Links that point somewhere other than the text suggests, or unexpected attachments.
  • Requests for passwords, payments or changed account numbers outside the normal process.
  • A tone or wording that is slightly off from what the sender usually uses.

When it happens: how to respond

Even with good layers in place, someone will eventually click or hand over a password. What matters is what happens in the minutes and hours afterwards. Quick, calm action limits the damage, while hesitation — often out of fear of having done something wrong — gives the attacker the time needed to move further into the systems.

The steps below are a simple plan worth agreeing in advance, so no one has to work out the order in the middle of a stressful situation. The purpose is to cut off access, understand the scope and inform the right people — in that order.

After the response, it is worth using the incident to learn. What got through, why did it work, and which layer could have caught it? A short, blame-free review makes the defence better next time and shows employees that reacting quickly is worthwhile.

  • Change the password immediately and sign the affected account out of all devices.
  • Contact your IT lead or partner, so access and activity can be checked.
  • Look for created mail rules, forwarding or changed account numbers.
  • Warn colleagues, customers or partners if they may have been messaged from the account.
  • Was a payment made? Contact the bank as fast as possible — timing is often decisive.

How Webits helps

What works against phishing is not a single product but several layers working together, and a partner who takes responsibility for them actually being set up correctly. That is exactly the role we fill: we build the foundation, keep an eye on it and are there if something slips through.

In concrete terms we offer a hosted spam filter that stops most of it before the inbox, and we help with the technical foundation: SPF, DKIM and DMARC on your domain, MFA on the accounts and a sensible plan for updates. We can also help with the routines and training that turn employees into a strong last layer rather than the weakest one.

If you want a layered defence in place without having to assemble the pieces yourself, get in touch. We look at your current setup, point out the gaps that matter most and lay out a simple plan to close them — so your IT just works, even when someone tries to trick their way in.

Next steps

Use our guide to choosing the right process, or read about how Webits works with IT automation and system integrations. A concrete assessment starts with your current workflow, not with a particular tool.

Related

Ofte stillede spørgsmål

Det vigtigste at vide

Korte svar på de spørgsmål, vi oftest møder før et samarbejde.

Are small businesses really a target for phishing?

Yes. Small and mid-sized businesses have real money and access, but often a thinner defence, which makes them a deliberately chosen target — not a random one.

Is a spam filter enough to stop phishing?

A hosted spam filter stops most of it before the inbox, but no technology catches everything. It works best together with SPF/DKIM/DMARC, MFA, updates and alert employees.

What do we do if an employee has clicked or handed over a password?

Change the password immediately, sign the account out of all devices and contact your IT partner so access and activity can be checked. Quick, calm action limits the damage most.

Do you have a specific process?

Get it assessed

Tell us about the workflow, the systems and the manual steps. We'll help scope a safe first version.

Contact Webits

Ready to make IT something you never have to think about?

Tell us about your challenge — we'll get back to you with a concrete proposal for a solution.