Phishing Protection for a Small Team
By CodexierPublished 7 min read
Phishing is not a technology problem with a technology fix; it is a people problem with three technical layers underneath. For a team of five to fifty, the realistic goal is not zero clicks but zero damage from a click. This guide covers how the attacks reach Swedish small companies, the fraud patterns to know, the layers that stop most of it, and what to do in the first hour after someone clicks.
How phishing reaches small firms
The mechanism is volume plus research. Bulk phishing sends the same fake login page to thousands of addresses and waits for the few who are busy. Targeted phishing reads your website and LinkedIn first: who is the CEO, who handles invoices, which suppliers you name, when the boss is travelling. A small company publishes all of that, so the attacker's email looks plausible because it was written from your own information.
Invoice and CEO fraud
The two patterns that actually cost Swedish small companies money rarely involve malware at all. Invoice fraud: an email, apparently from a real supplier, announces a new bankgiro number, and the next genuine invoice is paid to the criminal. CEO fraud: a message, apparently from the owner, asks finance to make an urgent payment or buy gift cards, with a reason not to call. Both work because they exploit a routine rather than a system.
| Pattern | What it looks like | The control that stops it |
|---|---|---|
| Changed payment details | Supplier 'moves bank', new bankgiro or IBAN, often just before a large invoice | Confirm every change by phone on the number you already have, never the one in the email |
| Urgent payment from the boss | Short message, travelling, cannot talk, needs it today, confidentiality requested | A standing rule that urgency never bypasses the phone check; the real boss will approve of the rule |
| Fake invoice for a service you never ordered | Directory listings, domain renewals, trademark 'registration' | Purchase orders or a known-supplier list; unknown senders wait |
| Credential harvest | 'Your mailbox is full', 'document shared with you', link to a login page | Two-factor on the account, and a password manager that refuses to fill on the wrong domain |
| Compromised supplier mailbox | A genuine thread continues with a changed attachment or account | Same phone rule; the sender's mailbox being real does not make the request real |
Bank transfers in Sweden are fast and hard to reverse. The phone call is cheap; the recovery is not.
Email filtering and warnings
Microsoft 365 and Google Workspace both include filtering that catches most bulk phishing when it is switched on and configured, which it often is not. Three settings matter most: a visible banner on mail from outside the organisation, link scanning that rewrites and checks URLs at click time, and impersonation protection that flags mail using your executives' names from foreign addresses. Publishing SPF, DKIM and DMARC on your own domain closes the other direction, so criminals cannot send as you to your customers; the setup is covered here.
- External-sender banner on every incoming message from outside your domain.
- Safe-links or equivalent URL checking at click time, not only at delivery.
- Impersonation protection for the names of the owner, finance and anyone who approves payments.
- Two-factor on every mailbox, with authenticator apps or hardware keys rather than SMS where possible.
- A password manager for the team; it will not fill your real password into a fake login page, which is a quiet but powerful control.
A simple reporting habit
The best sensor you have is the colleague who thinks something looks odd. The habit is: forward it, or use the report button, and carry on; no judgement, no forms. Someone (the owner, or whoever handles IT) glances at reports the same day and, if one is real, warns the rest of the team in a sentence. Over time the team learns what the attacks look like from real examples, which is more effective than any training slide.
Make it one click
Enable the built-in report button in Outlook or Gmail and tell everyone that is the whole process.
Reward the report
Say thank you in the team channel when someone catches one. People report more when reporting is visibly welcome.
Share the real ones
A screenshot of an actual attempt against your company teaches more than a generic awareness course.
What to do after a click
- Say so immediately. The person who clicked is the hero of this story if they speak up within minutes; the damage comes from silence.
- If a password was entered: change it now, sign out all sessions for that account, and check for new mail forwarding rules, which attackers add to hide their activity.
- If a payment was made: call the bank at once; fast action sometimes stops or recalls a transfer. Then report to the police.
- If a file was opened: disconnect the device from the network and have it checked before it is used again.
- Check whether personal data may have been exposed; if so, the 72-hour clock for notifying IMY may have started.
- Write down what happened and what was done, and adjust one control so the same click cannot cause the same damage.
When you do not need help: a team already on Microsoft 365 or Google Workspace with two-factor on and the phone rule agreed has most of this in place; the remaining steps are settings you can switch on with the vendor's guide. Buy help when you are not sure the settings are actually on, when your domain has already been spoofed, or when you want the mail, DNS and account hardening done and documented in one pass; that is what our performance and security optimisation package covers, priced on the pricing page, and a short call is enough to tell you which gaps you have.
- Performance & Security OptimizationMail filtering, DMARC, two-factor rollout and account hardening, done and documented in one pass.
- Monthly Maintenance PackageOngoing review of security settings, accounts and DNS as tools and people change.
- Book a free 15-minute callTell us your mail provider and how payments are approved; we point out the two or three controls that matter most for you.
Frequently asked questions
Is security awareness training worth it for a small team?
Short, real and repeated beats long and generic. Sharing actual attempts against your own company every few months, plus the one-click reporting habit, does more than an annual course. Simulated phishing campaigns can help larger teams but often breed resentment in small ones; the phone rule and two-factor deliver more protection per hour.
What should we do if a supplier's email account is hacked?
Treat any request from that thread as unverified: call the supplier on a known number, confirm the details, and tell them their mailbox may be compromised. Do not pay against changed details until confirmed by phone. Keep the emails as evidence in case the supplier or their bank needs them.
Can we get the money back after paying a fraudulent invoice?
Sometimes, if the bank is contacted within hours and the receiving account has not been emptied. Call the bank first, then report to the police, and inform your insurer if you have a policy covering fraud. The likelihood drops quickly with time, which is why the phone check before paying is worth far more than any recovery process.
Does two-factor stop all phishing?
No, but it stops the most common outcome, which is a stolen password being used to log in. Some attacks proxy the login in real time to capture the second factor as well; hardware keys and passkeys defeat those. For a small company, authenticator-app two-factor everywhere plus the payment phone rule covers the large majority of realistic attacks.
Not sure your mail and accounts are actually protected?
In fifteen minutes we go through your mail provider, two-factor status, domain records and payment routine, and tell you which two or three controls to fix first and what it would cost to have it done.
Book a free 15-minute call