Phishing Cyber Security and Invoice Fraud in Small Businesses
That is the sort of problem a small business needs its cyber security to address. For businesses in Northamptonshire, protecting email accounts and payment processes deserves as much attention as protecting the computers themselves.
Why phishing still needs your attention
The government’s Cyber Security Breaches Survey 2025/2026 found that 38% of UK businesses had identified phishing attacks in the previous 12 months. That includes fraudulent emails and attempts to send staff to fake websites; it does not mean every attempt succeeded.
A suspicious message might ask someone to open a shared document, sign in to Microsoft 365 or scan a QR code. Some impersonate a director requesting an urgent transfer. Others arrive through a genuine email account that has already been compromised, which makes the conversation harder to question.
Poor spelling can still be a warning sign. A well-written email can be dangerous too.
Make payment checks part of the routine
Any request to change a supplier’s bank details should trigger a separate check. Call a number already held in your records, rather than the number supplied in the email. The same rule should apply when the request appears to come from someone senior in your own business.
Give staff permission to pause a payment without feeling they are holding everything up. A clear process is easier to follow than an instruction to ‘be careful’, particularly when someone is covering the accounts role or working through a backlog.
If a payment has gone to the wrong account, contact your bank immediately and tell your IT support provider. Preserve the messages so they can be investigated.
Check the security behind the inbox
Multi-factor authentication adds an important check to a sign-in, but its protection depends on the method and configuration. Staff should never approve an unexpected authentication request. Where suitable, phishing-resistant sign-in methods can reduce the risk of someone being tricked into handing over access.
Email filtering, device protection and updates also need attention. So do accounts belonging to people who have left, unnecessary administrator access and rules that forward company emails elsewhere.
A short training session using realistic messages is more useful than expecting everyone to recognise every trick. Make reporting straightforward, and avoid blaming the person who raises the alarm.
How Ashby can help
At Ashby Computers, we provide cyber security, Microsoft 365 support and security awareness training for small and medium-sized businesses. We can help you review email protection and account access, identify settings that need attention and give your team practical guidance on suspicious messages.
For a business without its own IT department, having someone to contact when an email looks wrong can make a difficult decision much easier. Our Northamptonshire IT support team provides remote and onsite support, so security sits alongside the day-to-day help your staff need.
If you’re unsure how well your email accounts are protected, speak to Ashby about reviewing your current setup. Call 01604 790979 or email enquiries@ashbycomputers.co.uk.
Poor spelling can still be a warning sign. A well-written email can be dangerous too.