Phishing
Phishing is an attack that uses fake emails and messages to trick people into taking an action.
Phishing is an attempt to trick people with fake messages into clicking, entering data, or making a payment. It is one of the most common entry points for attacks on organisations.
How it works
Attackers impersonate known senders like Microsoft, Swiss Post, a bank, or your own IT department. The message contains a link to a fake login page or an attachment with malware. Modern attacks also bypass MFA by forwarding the login to the real service in real time. Besides email, attackers use SMS, Teams messages, QR codes, and phone calls.
For example, an employee receives an email about a supposedly shared document. She enters her password and the MFA code. Minutes later, someone logs into her account from abroad and creates a forwarding rule. The SOC detects this combination, revokes the sessions, removes the forwarding rule and resets the account.
What to look out for
- Make reporting easy. A button in the email client and quick feedback increase the reporting rate.
- Use phishing-resistant MFA, for example, passkeys or FIDO2 keys.
- Monitor logins and new mailbox rules after a click has occurred.
- Train without shaming. Staff who fear punishment will not report a click.
Measuring and improving
Simulations show how many people click and how many report the email. The reporting rate is more important than the click rate. A high reporting rate means the SOC learns about an attack early, even if someone clicked.
Typical mistakes
Many programmes consist of annual training and one simulation. This is not enough because lures change constantly. Short, regular exercises work better. A second mistake is having no process after a report. This means reported emails remain in other inboxes.
How we implement it
We analyse reported phishing emails in the SOC and lock compromised accounts within the agreed mandate. We offer training as part of our 'Security Awareness' security service.