Cybersecurity Glossary

Phishing

A fraudulent message designed to make you hand over a password, approve a payment or open a malicious file.

What Phishing means

Phishing is an attempt to trick a person rather than break a system. The message imitates someone the recipient trusts, a bank, a supplier, a colleague, the chief executive, and asks for something that feels routine. Modern phishing is well written, correctly branded and often references real projects, because attackers research their targets first.

Why Phishing matters for small businesses and nonprofits

For a small business or a nonprofit, phishing is the single most common route to a breach. One clicked link on one laptop can lead to a drained account or an encrypted file server. The defence is not a smarter workforce in the abstract; it is a few specific habits plus technical controls that catch what people miss.

What to do about Phishing

Three steps to deal with Phishing

  • Turn on multi factor authentication everywhere, so a stolen password alone is not enough
  • Verify any payment or bank detail change by calling a known number, never by replying to the message
  • Give staff a one click report button and thank every report, including the false alarms

Not sure where you stand on this?

We review your current setup against the basics, tell you plainly what is covered and what is not, and give you a ranked list with effort and cost. No jargon and no scare tactics.