How to recognise phishing and defend your business
How to recognise phishing: warning signs, real-world examples and countermeasures for SMEs from TN Solutions, ISO 27001 certified. Call 02 9517550.

In this article
Phishing gives itself away through a handful of recurring signs: a sender address that doesn't match the real domain, an urgent tone, links pointing somewhere other than where they claim, and unusual requests for credentials or payments. Defending against it takes multi-factor authentication, email filtering, staff training and written verification procedures for bank transfers and changes to payment details.
What phishing is, and why it targets your business too
Phishing is a fraud technique in which the attacker impersonates someone the victim trusts — a bank, a courier, Microsoft, a supplier, even a colleague — to trick them into handing over credentials, data or money. Email is the classic channel, but today it also arrives via SMS, phone calls, WhatsApp and even QR codes.
The point many business owners underestimate is that phishing doesn't exploit a technical flaw. It exploits a human one: haste, habit, trust. That's why no firewall stops it completely. In our experience as a System Integrator — we've been working with SMEs in the Milan area for more than 25 years — almost every incident we see starts exactly here: a click made in good faith at 5:45 on a Friday afternoon, between an urgent delivery and a phone call.
And the consequences rarely stop at a stolen password. A compromised credential is often the opening move of a much larger attack: access to company email, payment fraud, and eventually the encryption of your systems. If you want to understand what happens next, we've written a dedicated guide on how to protect your business from ransomware.
How to recognise phishing in practice
Here are the concrete signs to check before you click. No single one is conclusive on its own, but two or three together should set off alarm bells.
1. The sender doesn't add up
The display name is trivially easy to fake: "John Smith - Accounts" can hide any address at all. Always check the full email address, and read it carefully. Fraudsters use domains that are almost identical to the real thing: barclays-security.com instead of barclays.com, rnicrosoft.com with "rn" standing in for "m", or the correct domain with a different suffix (.net instead of .co.uk).
2. Urgency and threats
"Your account will be suspended within 24 hours", "overdue invoice — we will take legal action", "confirm now or lose access". Urgency is phishing's primary weapon: its job is to switch off your critical thinking. A genuine supplier or a genuine bank doesn't operate that way. Whenever a message pressures you to hurry, that's precisely the moment to slow down.
3. The link doesn't go where it says
Before clicking, hover over the link (without pressing) and read the real address shown at the bottom of your browser or email client. On a smartphone, press and hold the link to preview it. If the text says "gov.uk/hmrc" but the link points to an unknown domain, you have your answer. Be wary of URL shorteners (bit.ly and the like) in contexts where there's no reason for them to appear.
4. Unusual requests for credentials or data
No serious service asks you by email to "confirm your password" or enter card details to release a parcel. If you're still in doubt, don't use the link in the message: open your browser, type the service's address yourself and check from within your own account.
5. Unexpected attachments
Invoices you never asked for, "delivery documents" from couriers you have no shipments with, password-protected ZIP files (the password exists to slip past antivirus scanning), Office documents asking you to "enable macros" or enable editing. An unexpected attachment should be treated as suspicious until proven otherwise — even if the sender appears to be a colleague, because their account may already be compromised.
6. Errors and oddities in the text
Glaring grammar mistakes are increasingly rare — with generative AI, fraudsters now write flawless copy — but there are still useful tells: generic greetings ("Dear customer") from someone who should know your name, blurry logos, incomplete signatures, a tone that doesn't match the person. If your accountant suddenly writes to you in stiff, formal English they've never used before, be suspicious.
7. Payment requests or changes to bank details
This is the most expensive scenario for SMEs: the so-called BEC scam (Business Email Compromise). After quietly reading the correspondence of a compromised account for weeks, the attacker inserts themselves into a genuine exchange with a supplier and announces "new bank details". The transfer goes out; the money vanishes. Iron rule: every change of IBAN or account details must be verified by phone, calling the supplier on a number you already know — never the one given in the email.
Beyond email: the variants worth knowing
Phishing has switched channels more than once, and it pays to call things by their name:
- Spear phishing: a targeted attack on a specific individual, built with real information (the boss's name, live projects, actual suppliers). Far more convincing than mass phishing.
- Smishing: phishing by SMS. The classic "your parcel is being held" or "unusual activity on your account" messages with a link to tap.
- Vishing: phishing by phone. The fake bank operator or fake Microsoft technician who walks you through steps "to secure your account" while actually draining it or taking control of your PC.
- Quishing: fraudulent QR codes, printed on fake notices or embedded in emails precisely because spam filters struggle to analyse them.
- CEO fraud: a message that appears to come from the owner or managing director asks someone in accounts for an urgent, confidential transfer. It leans on hierarchy and secrecy to shut down any verification.
How to defend your business: countermeasures that work for SMEs
Recognising phishing is half the job. The other half is building defences that hold up on the day someone, inevitably, clicks.
Multi-factor authentication (MFA) everywhere
It's the single most effective measure: even if a password is stolen, without the second factor the attacker stays locked out. Enable it on email, VPN, business applications and cloud access — with no exceptions for "trusted users" or senior managers, who are in fact the favourite targets. One caveat: there are attacks that bypass MFA using proxy pages that steal the session, so MFA is no licence to ignore all the other warning signs.
Technical protection for your email
SPF, DKIM and DMARC, correctly configured on your domain, stop fraudsters sending email in your company's name and help other people's filters flag fakes. On top of these come advanced anti-phishing filters that analyse links and attachments before delivery. If you use Microsoft 365, much of this tooling is already included but needs configuring — we cover it in our Microsoft 365 guide for businesses.
Ongoing training, not a one-off course
Training works when it's recurring and practical: short sessions, real examples, and above all simulated phishing campaigns, in which test emails measure how many people click. Not to punish those who get it wrong, but to understand where reinforcement is needed. An employee who has already "taken the bait" in a simulation is far less likely to fall for the real thing.
Written procedures for payments
The defence against BEC fraud isn't technological, it's organisational: dual approval for transfers above a set threshold, mandatory phone verification for any change of bank details, and a ban on executing payments requested by email alone, however urgent they sound. Putting it in writing takes away the fraudster's main weapon: pressure.
A plan for when the click has already happened
Even with every defence in place, sooner or later it happens. What to do straight away:
- Change the password on the affected account (and anywhere it was reused) and revoke active sessions.
- Alert IT or your support provider — no embarrassment, no delay: the first few hours make all the difference.
- Isolate the PC if an attachment was opened or anything was installed.
- Check mailbox forwarding rules: attackers create them so they can keep reading your email even after the password changes.
- Monitor accounts and logins over the following days.
On endpoints and servers, EDR technology lets you see in real time what happens after the click and isolate the machine before the attack spreads. Bear in mind that for many companies in the supply chain these measures are no longer optional: the NIS2 directive explicitly requires them, as we explain in our article on what NIS2 changes for SMEs.
Put your company's defences to the test
Phishing can't be eliminated; it has to be managed — with the right technology, clear procedures and people trained to recognise it. TN Solutions supports SMEs across all of this: exposure assessment, email protection, MFA, simulated phishing campaigns and incident response, with the hands-on approach of an ISO 9001 and ISO 27001 certified System Integrator, working alongside businesses from Melzo (Milan) for more than 25 years.
Explore our IT security services for businesses or get in touch for a no-obligation assessment: we'll show you, with real data, how exposed your business is and where it makes sense to start. Call us on 02 9517550.
Frequently asked questions
How do I recognise a phishing email at a glance?
Check three things: the sender's real address (not the display name), where the link actually points (hover over it without clicking) and whether the message creates urgency or asks for credentials or payments. If even one of these doesn't add up, don't click — verify through a different channel.
I clicked a phishing link: what should I do?
If you entered credentials, change them immediately and enable MFA; if you opened an attachment, disconnect the PC from the network and contact whoever manages your IT. Also check your mailbox forwarding rules. Acting within the first few hours dramatically limits the damage.
Does antivirus protect against phishing?
Only partially. Antivirus can block a known malicious attachment, but it can't stop you typing your password into a fake page. You need dedicated email filtering, MFA and staff training: phishing targets the person, not the machine.
Does phishing affect small businesses too?
Yes — in fact they're the preferred target: valuable data, light defences, no in-house security team. Many attacks on SMEs also serve as a springboard to reach their larger customers further along the supply chain.
How much does it cost to protect an SME from phishing?
Less than a single incident. MFA and proper email configuration come at modest cost; training and simulated phishing run on affordable monthly plans. A transfer diverted by BEC fraud, by contrast, typically starts in the tens of thousands of euros — and is almost never recovered.
Technology partners
Want to discuss it with our team?
We analyse your infrastructure for free and propose the most suitable solution.







