
Email still tops the attack list
Messaging apps have come and gone, but attackers never really let go of email. It reaches every desk. It reaches every phone. It lands in front of people who are busy, distracted, and halfway out the door. That's the whole appeal. One convincing message can be enough to hand over an account, wave through a fake invoice, or give ransomware its first toehold.
The numbers back this up. In its most recent Annual Cyber Threat Report, the Australian Cyber Security Centre found email compromise to be the single most reported threat facing Australian businesses. Roughly one in three business cybercrime reports now starts with an email. For a small firm in New South Wales, reading a message with a sceptical eye has quietly become a basic job skill. It's not something you can file under "IT's problem" anymore. The good news is that it's a skill you can build, and steady Cyber Security Awareness Training is what turns that healthy scepticism into a habit the whole team shares.
Today's phish looks nothing like yesterday's
Remember the misspelt "Nigerian prince" email? That era is over. The crews running these scams harvest LinkedIn for names and job titles, clone real branding right down to the footer, and pick their moment for quarter-end, when everyone is already stretched. AI writing tools have sanded off the clumsy grammar that used to give the game away. What lands now reads like a perfectly ordinary marketing email.
The economics have shifted too. Phishing-as-a-service kits sell for less than a takeaway coffee, and they do the whole job for the buyer, from registering a lookalike domain to reporting back on who opened the message and when.
Spam filters still block a huge amount, no question. But smaller outfits carry more of the risk, simply because nobody is watching the inbox around the clock. Picture an overworked bookkeeper reading email on the train home. That person is far more likely to tap "Pay now" than a corporate finance team with three sets of eyes on every payment.
Red flags staff can spot quickly
Technology buys you time. A person still makes the final call on whether to click. So it's worth drilling the team on a few reliable tells.
Look hard at the sender's address. One swapped character does a lot of damage. An "rn" reads as "m" at a glance. An extra "s" hides in plain sight. Teach people to hover over the address on a laptop, or long-press it on a phone, before they trust it.
Notice when the tone is off. Your supplier has signed off with "Regards" for six years, then suddenly it's "Cheers, mate" and a rushed favour. That prickle of "this doesn't sound like them" is often the sharpest alarm you have.
Treat surprise attachments and share links with suspicion. The partners you deal with use the tools you already agreed on. When something arrives outside that pattern, a thirty-second phone call settles it.
Check the branding closely. A logo that's slightly soft around the edges. A brand colour half a shade out. A missing ABN, or a phone number with an overseas prefix. Individually minor. Together, telling.
Push back on manufactured urgency. "Pay this in the next hour or the account is frozen" exists to stop people thinking. Real organisations give you time, and a second way to check.
None of these clues is proof on its own. Line up two or three, though, and most people will pause. That pause is the point.
Building a human firewall
Short and frequent beats the yearly marathon
Nobody retains a half-day security seminar. They retain the five-minute lesson that drops into a quiet moment between meetings. Build those lessons from the business's own quarantine folder, real bait aimed at real colleagues, and close with a two-question quiz. It sticks because last week it nearly caught someone down the hall.
Simulations build genuine confidence
Staged phishing lets staff practise with nothing actually at stake. Start soft. Raise the difficulty as people get sharper. Post the anonymised results, and make a bit of noise when the click rate drops. One rule keeps the whole thing working: a mis-click is a lesson, never a naming-and-shaming. The day it becomes the second thing, people go quiet, and quiet is exactly what you can't afford.
Make cross-checking the norm
You want a workplace where phoning a colleague to sanity-check an odd request counts as diligence, not paranoia. That starts at the top. When a manager visibly rings to confirm a change of bank details before paying it, everyone below them feels safe doing the same. Keep at it and "stop and check" becomes a reflex.
Keep devices patched and locked down
Awareness closes a lot of gaps. People are still people, though, and someone will eventually click. The job then is to make that click cost as little as possible. Keep operating systems patched. Switch on multi-factor authentication. Give staff only the access they actually need. If you run Microsoft 365, our guide to locking down Microsoft 365 with MFA covers one of the highest-value changes a small business can make. A patched laptop, running as a standard user rather than an administrator, makes life hard for ransomware even after the bait is taken.
What to do the moment a suspect email lands
Spotting the thing is half the battle. What you do in the next few minutes decides the rest.
Reporting in one click
Add a "Report Phishing" button to Outlook or Gmail. One tap lifts the message, headers and all, and sends it straight to IT or your managed provider. Staff skip the awkward forwarding dance, and your security people get clean data to tune the filters with.
Isolate fast
If someone does get caught, minutes matter. Pull the network cable. Drop the Wi-Fi. Trigger a remote containment script if you have one ready. The gap between a quick response and a slow one is often the gap between one sick laptop and malware quietly working its way across the network.
Reviews with no blame attached
Bring the team together for ten minutes afterwards, and keep the conversation on the email, not the person. What made it so convincing? The colleague who clicked already feels rotten, and pointing fingers only trains everyone else to stay silent next time. Maybe the fix is a tighter check when you onboard a new supplier. Maybe your website lists a few too many staff names and direct lines. Whatever you learn, feed it back into both the training and the technical settings.
The budget maths: training versus cleanup
Put a number on cleaning up after ransomware, or chasing a payment that went to a criminal's account, and it dwarfs what a decent awareness program costs. Local providers charge a few dollars per user a month, about the price of the office's Friday coffee run, and they keep the scenarios lined up with Australian regulations and the scams doing the rounds here right now.
Trouble Free Computing Solutions folds that training into its Cyber Security Awareness Training stack. The same remote-monitoring platform that keeps your servers patched also tracks quiz scores, so it all sits in one dashboard. Less admin. No dramas.
It also pays to keep government advice close. The Australian Cyber Security Centre publishes plain-language alerts you can forward straight to your team, which saves you writing the warning from scratch.
Everyday vigilance beats tech on its own
Phishing isn't going to stand still, and neither should you. The small businesses that stay ahead are the ones pairing switched-on people with hardened systems. Bite-sized training builds the reflexes. A quick call-back to verify frustrates the con artist. Patches and multi-factor logins keep the damage small on the day someone slips. Weave that habit into the ordinary working day, and even a beautifully written scam starts to fall flat.

