Phishing Emails Everywhere? A Practical Email Security Guide for SMEs
Data Security 2026-10-05 CentralComputer Team

Phishing Emails Everywhere? A Practical Email Security Guide for SMEs

Phishing Emails Everywhere? A Practical Email Security Guide for SMEs

Phishing Emails Everywhere? A Practical Email Security Guide for SMEs

Last month, an accountant at a trading firm in Tsuen Wan received an email from her "boss" instructing her to wire HK$280,000 to a new account for an urgent deal. The sender address differed from the boss's real email by a single letter — she nearly transferred the money. Luckily the bank called to verify, exposing the scam. We see several of these "CEO fraud" cases every month; some companies aren't so lucky, and the money is gone for good.

Phishing has moved far beyond broken-English "you've won a prize" spam — today's lures are convincing enough to fool IT staff. Here's how to spot them and protect your business, especially SMEs without an enterprise security team.

How convincing is modern phishing?

  • CEO fraud — impersonating the boss or a supplier to request wire transfers, like the case above
  • Fake login pages — "Your Microsoft 365 password is expiring, click here to reset" leading to a pixel-perfect fake Microsoft site that harvests your credentials
  • Fake invoices / quotes — attachments (.html, .zip) that install malware and hijack the machine once opened
  • AI-written lures — flawless language, personalized with real company details scraped from LinkedIn

The 5-second verification routine

  1. Read the real sender address — not the display name, the part after @. boss@company-secure.com is not boss@company.com; watch for lookalike letters (rn vs m, 0 vs o)
  2. Hover links, don't click — hover (don't click) and check the real URL shown in the corner
  3. Ask why it's "urgent" — "Immediately!", "Today!", "Don't tell anyone!" are pressure tactics to stop you thinking. Real emergencies get a phone call
  4. Treat attachments with suspicion — .html, .zip, .iso, or macro-enabled Office files you weren't expecting: don't open
  5. Verify by phone when unsure — call a number you already know, never one from the email

6 email security settings every SME needs

  • Enable MFA — the single most important step. Even with a stolen password, attackers can't get in without the second factor. Free in Microsoft 365 and Google Workspace — turn it on
  • Set up SPF / DKIM / DMARC — the "ID cards" of email that stop others impersonating your domain. A one-time setup; get an IT provider to do it if unsure
  • Use separate admin accounts — don't read daily email with your highest-privilege account
  • Attachment sandboxing — Microsoft 365 Business Premium's Safe Attachments opens attachments in a virtual environment first
  • Back up mailboxes regularly — if ransomware encrypts your mailbox too, backups are your way back
  • Train staff — run a simulated phishing test every six months; retrain anyone who clicks. Cheapest and most effective control there is

Already clicked a suspicious link or entered your password?

  1. Change the password immediately — from a different, clean device
  2. Revoke all sessions — Microsoft 365 lets you revoke all sessions from the admin panel
  3. Check forwarding rules — attackers love adding secret forwarding rules to silently copy your mail. Delete any rule you don't recognize
  4. Tell IT / your company — don't hide it out of embarrassment; early warning saves everyone
  5. If malware is suspected, disconnect — unplug, kill WiFi, stop it spreading to other machines

Real case: one policy saved a company HK$460,000

Earlier this year, the purchasing department of a logistics firm in Kowloon Bay received a "supplier" email saying their bank account had changed, asking for the next HK$460,000 payment to go to the new account. The email was professional and even quoted the correct deal reference. Purchasing nearly transferred — but the company had one rule: any change to payment details must be verified by calling the supplier on a known number. One call revealed the supplier knew nothing about it. HK$460,000 saved — by a rule we suggested during an IT security review last year. It cost nothing.

Summary

Phishing defense isn't one magic product — it's habits plus settings: MFA on, SPF/DKIM/DMARC done, and a culture of "verify by phone when in doubt". SMEs with limited resources should spend time and money where it counts most.

Not sure your company's email setup is safe? WhatsApp CentralComputer for an email security check: MFA, SPF/DKIM/DMARC, backups — all reviewed in one go.

Related: Virus Removal & Security | SME Ransomware Protection | Blog

Found this article helpful?

Feel free to share it with your friends or colleagues.

Call Us