Cybersecurity Glossary

Spear Phishing

A phishing attack aimed at one named person, written with details that make it convincing.

What Spear Phishing means

Where ordinary phishing is sent in bulk, spear phishing targets an individual. The attacker reads your website, your press releases and your team's social profiles, then writes a message that mentions the right project, the right supplier and the right internal name. The technical trick is the same; the research is what makes it work.

Why Spear Phishing matters for small businesses and nonprofits

Finance staff, executive assistants and anyone who can move money or grant access are the usual targets. Because the message is plausible, the usual advice to look for spelling mistakes is useless. Process, not vigilance, is what stops this.

What to do about Spear Phishing

Three steps to deal with Spear Phishing

  • Require a second approver for any payment above a threshold you set
  • Publish less operational detail about who does what and who reports to whom
  • Practise the scenario with the people who would actually receive it

Not sure where you stand on this?

We review your current setup against the basics, tell you plainly what is covered and what is not, and give you a ranked list with effort and cost. No jargon and no scare tactics.