Close Menu
  • News
  • Home
  • In Profile
  • Finance
  • Legal
  • Technology
  • Events
  • Features
  • Wellbeing & Mental Health
  • Marketing
  • HR & Recruitment
  • About
  • Advertise
  • Events Calendar
  • Business Wall
  • Subscribe
  • Contact
  • 0843 289 4634
X (Twitter) LinkedIn YouTube
Trending
  • Good Food Launches New SME Awards
  • New Scam Targets UK Small Businesses With Fake WhatsApp and Text Complaints
  • 1 in 10 bosses fear false allegations if they meet with junior staff
  • 2025 Marks Turning Point For Allergy Safety As Advocate Julianne Ponan MBE Helps Drive Change
  • Phoenixism: the legal and commercial dangers for directors
  • In Profile: Katie Smith on Innovation, Influence and the Future of OOH
  • Five Things Employers Need To Consider As Background Screening Shifts In 2026
  • What entrepreneurial leaders need most in the digital age 
X (Twitter) LinkedIn YouTube
SME Today
  • About
  • Advertise
  • Events Calendar
  • Business Wall
  • Subscribe
  • Contact
  • 0843 289 4634
  • News
  • Home
  • In Profile
  • Finance
  • Legal
  • Technology
  • Events
  • Features
  • Wellbeing
  • Marketing
  • HR & Recruitment
SME Today
  • About
  • Advertise
  • Events Calendar
  • Business Wall
  • Subscribe
  • Contact
  • 0843 289 4634
  • Twitter
  • LinkedIn
  • YouTube
  • RSS
You are at:Home»Features»Why phishing attacks are hard to combat and how SMEs can protect themselves
hacker man typing on laptop, hacking computer system

Why phishing attacks are hard to combat and how SMEs can protect themselves

0
Posted By sme-admin on June 7, 2022 Features, News, Technology

Rotem Shemesh, Lead Product Marketing Manager, Security Solutions at Datto, provides SMEs some guidance on how to protect against the numerous phishing attacks businesses face today.

Rotem Shemesh, Lead Product Marketing Manager, Security Solutions at DattoPhishing attacks remain the most common threat vector according to the UK Cyber Security Breaches Survey, published in March this year. Of the 39% of UK businesses that suffered a cyberattack in the last 12 months, 83% were due to a phishing attempt. This is not surprising, given how easy it is to deploy a phishing campaign; and while phishing is not new, it is often used as the first step in larger-scale cyberattacks to trick users into sharing confidential information. No organisation is immune to these attacks, but small and medium-sized enterprises (SMEs) are being targeted at an accelerated rate.

Sophisticated phishing can bypass security detection

Designed to create a sense of urgency or fear, phishing techniques have evolved over the years. They are increasingly sophisticated and more difficult to detect and defend against. Bad actors now operate on multiple channels to obtain user credentials from platforms such as WhatsApp, Slack, Twitter, LinkedIn, etc. Additionally, hackers are using techniques such as web session hijacking, email customisation, link masking, email thread hijacking, and are using nontraditional phishing mediums such as Voice over IP (VoIP), Short Message Service (SMS), and Instant Messaging (IM), which are making attacks more difficult to spot, as well as allowing them to bypass security systems.

Given the new techniques being used and the increased level of sophistication, circumventing detection hurdles is becoming easier – even for inexperienced hackers. In addition, today’s technology provides cybercriminals with the ability to automate email and webpage customisation, making it easy to launch highly tailored attacks even on small businesses.

One of the techniques hackers are using to gain access to sensitive information is spear phishing. The bad actor researches an intended target or small target group to obtain information they then include in a customised email to add credibility. Another more sophisticated phishing technique, called man-in-the-middle, relies on the interception of emails between two people. Once this is accomplished, the bad actor corresponds with the victims to acquire compromising information.

A more recent tactic involved a threat disguised as a communication hosted on a trusted domain, which enabled the attacker to remain below the detection radar. This attack leveraged Adobe InDesign’s hosting reputation to conceal a malicious link in an inframe. Sent via email, the goal of the bad actor was to obtain users’ credentials by having them click on a link to access a shared document. The link sent users to a fake webpage uploaded to indd.adobe.com, a legitimate URL. The masking technique – embedding an additional link in an iframe on the indd.adobe.com webpage – bypassed numerous email cybersecurity detection measures.

Fortunately, this attack was discovered before it had a chance to create severe damage, but this example depicts how serious and dangerous phishing attacks have become. As cybercriminals get smarter and bolder, SMEs must take the necessary steps to minimise the risk and impact of becoming a phishing victim.

Take an offensive approach to phishing

With phishing attacks more challenging to spot for the average user, SMEs need to build a strong cyber detection and prevention plan. While there’s no foolproof solution, SMEs need to be on high alert and take an offensive position by incorporating additional security measures.

All SMEs need to have the most up-to-date and advanced security solutions in place to protect email and other collaboration platforms against phishing threats. They need to adopt an assumed breach mentality and create a cyber resilience culture. This ongoing process consists of five functional components – identify, protect, detect, respond, and recover. It starts with an assumed breach mentality and ends with building a cyber resilience foundation.

It’s imperative to assess phishing risks and gaps by conducting phishing simulations frequently. Additionally, by deploying two-factor authentication, SMEs will be able to prevent cybercriminals that have compromised a user’s credentials from gaining access. For additional security, a combination of hardware-based multi-factor authentication (MFA) and biometrics –

instead of a password – should be used. If remote users need to access your network, make sure they connect over Virtual Private Networks (VPNs).

The SME’s IT department or their managed service provider (MSP) needs to keep abreast of current and new phishing strategies, as well as security policies and protection solutions. Also, cybersecurity frameworks such as the National Institute of Standards and Technology (NIST) Cybersecurity Framework and the Center for Internet Security (CIS) Controls should be leveraged to reduce risk, gain cyber maturity, and achieve desired security objectives.

Since end-users are key to spotting phishing attempts, conduct ongoing user training and education frequently. To determine if an email is authentic, the user needs to pay attention to the sender’s address – does it look legitimate? Are there grammar mistakes or odd language being used? If there’s a link, train users to hover the mouse over the link to see where it leads before clicking it. And finally, be sure that it’s easy for users to report a potential phishing attack quickly.

Given today’s ever-changing digital environment and malicious actors’ relentless aim of staying one step ahead of their targets, cyber security can no longer be an afterthought. SMEs need to be on the offensive and put security protection, processes, and training in place to minimise phishing risks.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

New Scam Targets UK Small Businesses With Fake WhatsApp and Text Complaints

1 in 10 bosses fear false allegations if they meet with junior staff

What entrepreneurial leaders need most in the digital age 

Comments are closed.

Follow SME Today on Linkedin and share all the topics you find interesting
ISO/IEC 27001 roadmap: A practical guide for UK SMEs
ISO/IEC 27001 roadmap: A practical guide for UK SMEs
Are you a Company Director?
Are you a Company Director - Verify your identity
Mastermind9
Events Calendar
    • Marketing
    January 26, 2026

    The State of Prospecting 2026: Trends shaping B2B sales & marketing outreach

    January 23, 2026

    DeqVision Expands to the UK to Help SMEs Get Leads and Sales

    • Finance
    January 30, 2026

    How to support employees facing financial stress and worry 

    January 29, 2026

    Rising Energy Costs: Practical Tips for UK Businesses

    • People
    October 13, 2025

    Dr. Karim Bahou appointed Head of Innovation at Sister, Manchester’s £1.7bn innovation district

    September 30, 2025

    Allergen Free For The Win: Ceo Of Inclusive Food Brand Announced As Best Business Woman

    • Health & Safety
    December 22, 2025

    Businesses Step Up Their Washroom Standards As Loo Of The Year Figures Reveal Big Changes

    September 18, 2025

    Lessons From Grenfell Are Still Being Learned

    • Events
    January 27, 2026

    Washroom Technician John Heritage Honoured At National Loo Of The Year Awards

    December 23, 2025

    SME Awards To Spotlight The Real Engine Of Uk Growth – Small Businesses 

    • Community
    December 29, 2025

    Care Sector Specialist Partners With Technology Platform To Tackle A Communication Crisis In Social Care

    November 24, 2025

    Cherishers Supports Those Spending Christmas Alone

    • Food & Drink
    February 3, 2026

    Good Food Launches New SME Awards

    February 2, 2026

    2025 Marks Turning Point For Allergy Safety As Advocate Julianne Ponan MBE Helps Drive Change

    • Books
    January 21, 2026

    The CEO Mirage: Exposing the hidden traps that take smart leaders down

    December 23, 2025

    Communication Expert Celebrates Book Launch At Oxford’s Saïd Business School

    The Newsletter

    Join our mailing list for the best SME stories, handpicked and delivered direct to your inbox every two weeks!

    Sign Up
    About

    SME Today is published by the same team who deliver The Great British Expos’. We have been organising various corporate events for the last 10 years, with a strong track record of producing well managed and attended business events across the UK.

    Join Our Mailing List

    Receive the latest news and updates from SMEToday.
    Read our Latest Newsletter:


    Sign Up
    X (Twitter) YouTube LinkedIn
    Categories
    • Books
    • Community & Charity
    • Education and Training
    • Environment
    • Events
    • Features
    • Finance
    • Food and Drink
    • Health & Safety
    • HR & Recruitment
    • In Profile
    • Legal
    • Marketing
    • News
    • People
    • Property & Development
    • Sponsored Content
    • Technology
    • Transport & Tourism
    • Wellbeing & Mental Health
    • ABOUT SME TODAY: THE GO TO RESOURCE FOR UK BUSINESSES
    • Editorial Submission Guidelines
    • Privacy
    • Contact
    Copyright © 2025 SME Today.
    • ABOUT SME TODAY: THE GO TO RESOURCE FOR UK BUSINESSES
    • Editorial Submission Guidelines
    • Privacy
    • Contact

    Type above and press Enter to search. Press Esc to cancel.