Email is how organisations communicate, approve payments and share documents, which is exactly why attackers target it. A single convincing message can deliver malware, steal a password or persuade a finance officer to change a beneficiary account. Technology reduces the volume, but attackers aim at people, so the defence has to combine technical controls, clear processes and a workforce that feels safe reporting doubts.
Know the threats
- Phishing: messages that imitate a trusted brand or colleague to harvest credentials or deliver a malicious link or attachment.
- Spear phishing: the same idea, tailored to a named person using public information about their role, projects and contacts.
- Business email compromise (BEC): fraud in which an attacker impersonates an executive or supplier, or takes over a real mailbox, to request urgent payments or changes to bank details. Often no malware is involved at all.
- Other channels: phone calls (vishing), text messages (smishing) and messaging apps follow the same playbook.
Authenticate your own domain: SPF, DKIM and DMARC
Three DNS-based standards make it much harder to spoof your organisation's name:
- SPF lists the servers allowed to send mail for your domain.
- DKIM adds a cryptographic signature so receivers can verify a message was not altered and came from an authorised sender.
- DMARC tells receiving servers what to do when SPF and DKIM checks fail, and sends you reports showing who is sending mail in your name.
Move DMARC gradually from monitoring (p=none) to quarantine and finally reject, after you have identified every legitimate sender such as marketing platforms, ticketing systems and printers. Reject is what actually stops spoofing of your domain. Also consider protection against look-alike domains and display-name impersonation, since DMARC cannot stop those.
Layer the technical controls
- Filtering for spam, malicious attachments and links, with sandboxing or link rewriting for high-risk content.
- Multi-factor authentication on every mailbox, preferably phishing-resistant for executives and finance staff, and blocking of legacy protocols that bypass it.
- Clear external-sender banners and alerts for new forwarding or inbox rules, which attackers use to hide their activity.
- Endpoint detection and response (EDR) to catch what arrives and executes, and a SIEM alert for impossible-travel or unusual sign-ins.
- Restrictions on macros from the internet and on risky attachment types.
Fix the payment process, not just the inbox
BEC succeeds where a single email can move money. Require out-of-band verification, by calling a known number rather than one in the message, for any change of bank details, and use dual approval for payments above a defined threshold. Banks and financial institutions should apply the same discipline to payment instructions, aligned with the SWIFT Customer Security Programme where it applies.
Awareness training and simulated phishing
Short, frequent, role-specific training works better than one annual presentation. Teach people to pause on urgency, unusual requests and unexpected attachments, and show real examples from your own sector. Simulated phishing is useful as a learning tool and a trend measure, but it should not be used to shame or punish staff. Track the reporting rate as well as the click rate: a rising number of people reporting suspicious messages is a sign of a healthy culture.
Build a reporting culture
Give staff one easy way to report, such as a report-phishing button, and acknowledge every report quickly. Have a defined response: pull the message from all mailboxes, block the sender and links, reset exposed credentials and check for mailbox rules. This follows the approach in NIST SP 800-61 for incident handling. The person who clicked and reports within minutes is your best detection control, so never make them regret speaking up.
How Wethaq ICT helps
Wethaq ICT reviews your email security configuration and DMARC readiness, designs a layered defence, runs awareness programmes and simulated campaigns suited to your teams, and monitors mail-related alerts through our SOC. When something does get through, our incident response team helps contain and investigate it quickly.
Let’s build a secure foundation for your digital future
It starts with a free consultation: we learn your challenges and goals, then propose a service package tailored to your needs and budget.

