Phishing is not an entry-level threat — it is the gateway
The latest warning from Panda Security that phishing remains the cyber threat small businesses should watch is important precisely because the tactic is so familiar. Many UK SME owners associate phishing with poorly written emails asking for bank details. That version still exists, but it is no longer the main concern.
Modern phishing frequently impersonates Microsoft 365, a bank, HMRC, a supplier, a delivery company, a company director or an outsourced accountant. It may arrive by email, text message, Teams, WhatsApp or a compromised supplier mailbox. Its purpose is usually simple: persuade one person to reveal credentials, approve a payment, open a malicious file or disclose customer information.
For a small business, one successful message can become a much larger event. Stolen email credentials can allow criminals to read correspondence, reset passwords elsewhere, impersonate staff to customers, redirect invoices, steal data or deploy ransomware. That is why phishing should not be treated only as an employee-awareness issue. It is a business continuity, fraud, data protection and insurance-readiness issue.
Why UK SMEs remain especially exposed
Small teams create concentrated risk
Larger organisations may have dedicated security teams, segregation of duties and round-the-clock monitoring. Many SMEs do not. The same person may manage sales, supplier relationships, payroll and online banking. They may also be the person who can approve urgent payments.
Attackers understand this. A fake message apparently sent by a managing director or a regular supplier can exploit normal working habits: speed, trust and limited time. A business does not need to be a high-profile target to be attacked. Automated phishing campaigns reach thousands of inboxes, while more targeted business email compromise attacks focus on firms with visible suppliers, property transactions, payroll activity or invoice payments.
Hybrid work expands the attack surface
Staff increasingly access business systems from home, customer sites and personal mobile devices. Cloud email and collaboration tools make this practical, but they also make a compromised account highly valuable. If a criminal captures a Microsoft 365 login, they may gain access to emails, contacts, shared files and internal messages without needing to breach an office network.
A convincing phishing email can also bypass the assumptions behind traditional security. Antivirus software may not stop a staff member entering valid credentials into a fraudulent login page. This is why identity protection, particularly multi-factor authentication (MFA), has become one of the most important controls for SMEs.
AI makes impersonation more credible
Phishing is becoming more polished. Criminals can use publicly available company information, copied branding and AI-assisted writing to create messages with fewer obvious spelling errors. They can identify directors, suppliers and staff through websites and social media. Voice-cloning and deepfake-style impersonation are additional reasons not to rely solely on someone recognising a suspicious tone.
The practical implication is clear: employees need a process for validating high-risk requests, not merely a list of warning signs.
What a phishing incident can cost beyond the stolen payment
A fraudulent transfer is often the most visible loss, but it may be only the first cost. If an attacker accesses an email account, the business may need specialist forensic support to establish what happened, contain the access and determine whether personal data was exposed. There may be legal advice, customer notification, regulatory considerations and significant management time.
For firms that hold customer contact details, financial information, health-related data or commercially sensitive documents, the consequences can be particularly serious. Under UK GDPR, a personal data breach may need to be assessed promptly and, where required, reported to the Information Commissioner’s Office within the applicable timeframe. The business must make a reasoned decision based on the risk to individuals; it should not assume that a restored inbox means the incident is over.
Operational disruption is another overlooked exposure. A compromised account can be used to send malware to customers, change payment instructions or lock staff out of critical systems. Even where no ransomware is deployed, rebuilding trust with customers and suppliers can take longer than the technical recovery.
Where cyber insurance fits — and where it does not
Cyber insurance can form part of an SME’s resilience plan, but it is not a substitute for security controls. A well-designed policy may provide access to incident-response specialists and cover certain costs associated with a cyber event, subject to its terms, conditions, exclusions, limits and excess.
Depending on the policy, relevant cover may include:
- incident response, forensic investigation and crisis-management support;
- legal and data-protection advice;
- notification and credit-monitoring costs where appropriate;
- business interruption losses following a covered cyber incident;
- cyber extortion response; and
- liability claims arising from a security or privacy failure.
However, payment diversion and social engineering fraud are areas where assumptions can be costly. Some cyber policies include cover for funds transfer fraud or social engineering, while others limit it, exclude it or require it to be added separately. Crime insurance, fidelity cover and cyber cover can overlap imperfectly. SMEs should ask specifically whether a policy responds if an employee authorises a transfer after receiving a fraudulent instruction that appears to come from a director or supplier.
It is equally important to understand the policy’s security requirements. Insurers commonly ask about MFA, backups, endpoint protection, patching, staff training and payment controls. Inaccurate answers can create problems at claim stage. A business should be able to evidence the controls it says it has, rather than treating the proposal form as a box-ticking exercise.
Practical steps SMEs should take this month
Make MFA non-negotiable
Enable MFA for email, cloud storage, remote access, accounting platforms and administrator accounts. Use phishing-resistant methods where feasible, such as authenticator apps, passkeys or hardware security keys, rather than relying exclusively on SMS codes. Prioritise email first: it is commonly the reset point for other accounts.
Create a payment-verification rule
Do not validate changed bank details or urgent payment requests by replying to the original email or using a telephone number supplied in it. Staff should call a known, independently verified contact number or use an established supplier contact. For higher-value payments, require a second approver and a separate verification step.
This control should apply even when the message appears to come from the owner or finance director. A genuine leader should welcome a process that protects the business.
Train for decisions, not quizzes
Annual awareness training alone is insufficient. Run short, regular exercises based on realistic situations: a Microsoft 365 password reset, a supplier bank-detail change, an HMRC message or an urgent request from a director. Staff must know how to report a suspicious message quickly and without embarrassment.
Measure reporting rates, not only click rates. Early reporting can enable IT providers to block a campaign before more staff engage with it.
Secure and monitor email
Use a reputable email-security service, configure domain protections such as SPF, DKIM and DMARC, and ensure logging is retained for a useful period. Restrict administrator privileges and review forwarding rules, delegated mailbox access and suspicious login activity. Criminals often create inbox rules to hide replies or divert payment-related messages after compromising an account.
Prepare the response before an incident
Document who contacts the bank, IT provider, insurer, legal adviser and key customers if a phishing incident occurs. Keep insurer and broker details accessible outside the affected email system. If money has been sent, contact the bank immediately; speed can affect the prospect of recovering funds. Preserve evidence, change credentials from a clean device and notify the insurer in line with the policy conditions before appointing external response providers where required.
Questions to ask before buying or renewing cyber insurance
Cyber insurance should be matched to how the business actually operates. Before renewal, SMEs should ask their broker or insurer:
- Does the policy cover social engineering and invoice-redirection fraud, and what sub-limit applies?
- Are losses from a compromised cloud email account covered, including forensic and legal costs?
- What MFA standard is required, and does it apply to all users or only remote and privileged access?
- Is business interruption cover triggered by cloud-service disruption or only by damage to the company’s own systems?
- Who provides the incident-response service, and is a 24-hour helpline available?
- Are there exclusions or conditions relevant to unpatched systems, outsourced IT or inadequate backups?
The objective is not to buy the longest list of policy features. It is to identify the losses most likely to threaten the firm’s cash flow and ensure that security controls, internal procedures and policy wording align.
FAQ
Does cyber insurance automatically cover a phishing payment scam?
No. Cover for authorised payments induced by phishing or impersonation varies considerably. Ask whether social engineering, funds transfer fraud or invoice manipulation is included, what limit applies and whether a separate crime policy is needed.
Is multi-factor authentication enough to stop phishing?
MFA substantially reduces the risk of account takeover, but it is not a complete solution. Attackers can still target payment approvals, exploit MFA fatigue, compromise sessions or persuade staff to disclose information. MFA should sit alongside payment verification, email security and staff reporting procedures.
What should a UK SME do in the first hour after a phishing incident?
Contact the bank immediately if a payment is involved, isolate affected access where appropriate, reset credentials from a known-clean device, preserve emails and logs, contact the IT provider and notify the cyber insurer or broker according to the policy. Assess whether personal data may have been accessed and obtain specialist advice promptly.
Will a cyber insurer require staff phishing training?
Requirements vary, but insurers increasingly expect demonstrable controls such as regular awareness training, MFA, backups and patch management. Training is valuable not just for obtaining cover: it can reduce the likelihood and scale of a loss.
Source: pandasecurity.com — Mon, 31 Aug 2026 07:11:36 GMT