IT & SupportIT SupportMicrosoft 365Server SolutionsVirtualisationCyber SecurityCyber SecuritySavvy SecureEmail SolutionsAccess ControlCCTVConnectivity & CommsBusiness Phone SystemsProfessional CommunicationNetwork & WiFiMobile ConnectivityBroadband CheckerWeb & DigitalWeb DesignAll servicesCompanyLocationsKnowledge HubGuidesFAQsAboutContactGet a Quote
Cyber Security

How to spot a phishing email: a guide you can give your staff

Employee checking a suspicious email on a laptop

This is a practical staff guide for any small business that wants people to handle suspicious email safely. Phishing is not only a badly spelt message from a stranger. It can look like a supplier invoice, a Microsoft 365 sign-in page or an urgent instruction apparently sent by the boss. The aim is not to make staff frightened of email. It is to give them a short pause-and-check routine, plus permission to report a mistake quickly.

Use this five-second pause before you act

When an email asks you to sign in, pay money, open an attachment, share information or change details, stop for five seconds. Ask: was I expecting this, does the request make sense, and can I check it another way? If the message creates unusual urgency or tells you to keep it secret, that is a reason to slow down, not speed up.

Step 1: check who really sent it

Look beyond the display name. "Microsoft Support", "Accounts" or the director's name can be typed by anyone. Check the full sender address and look for a slightly wrong domain, extra words, odd spelling or an unrelated address. On a phone, tap the sender name to reveal the actual address. A familiar address is not a guarantee either, because a compromised account can send convincing messages.

Common sender warning signs

  • The display name says a supplier, but the email address belongs to a free webmail account.
  • The address is close to a real domain but has a swapped letter, extra hyphen or unfamiliar ending.
  • The message comes from a colleague but asks you to bypass the normal approval process.
  • The reply-to address is different from the address shown as the sender.

Step 2: recognise pressure, authority and a story that does not fit

Phishing often works by putting people under pressure. The email may threaten account closure, say a payment is overdue, claim a parcel is waiting, or demand an immediate response from a senior person. It may flatter you with a private task or warn you not to tell anyone. These are persuasion tricks, not proof that the message is important.

Step 3: inspect links and attachments safely

On a computer, hover over a link without clicking and read the address that appears. On a phone, press and hold if your mail app shows the destination. Check the main part of the web address, not just a familiar word somewhere in a long link. A message can display "Microsoft 365" but lead to a completely different site. If you need to sign in, open a new browser window and use your saved bookmark or type the known address yourself.

Step 4: know the scams UK SMEs see most often

Invoice fraud and business email compromise: a criminal pretends to be a supplier and asks for future payments to go to a new bank account. Sometimes they first send a harmless email to learn how your finance process works. Never change bank details from an email alone. Call a trusted number already on file, use a second person to verify the change and record the check.

Fake Microsoft 365 sign-in pages: an email says your mailbox is full, a document has been shared or your password is expiring. The link leads to a realistic copy of a sign-in page that steals your password. The safest habit is to open Microsoft 365 through your usual route, not through a surprise link. Multi-factor authentication reduces the damage if a password is stolen, but it does not make the email safe. Read what multi-factor authentication does so staff know why an unexpected prompt matters.

CEO impersonation: a message apparently from an owner or director asks a staff member to make a payment, purchase vouchers or send payroll details. It usually arrives when the senior person is away or busy. The answer is not guessing whether it "sounds like them". Follow the agreed payment and verification process every time, including for the boss.

Step 5: what to do if you clicked or entered details

Tell your manager or IT support straight away. Do not be embarrassed and do not spend an hour trying to fix it alone. Speed matters: support can reset a password, revoke active sessions, check mail rules, block a malicious link and look for other affected accounts. If you entered a password, change it using the genuine sign-in page and approve no unexpected multi-factor prompts.

What staff should report

  • The suspicious email, using the company's reporting process or by forwarding it as instructed.
  • Whether they clicked a link, opened a file, signed in or shared any information.
  • The approximate time and the device used.
  • Any unexpected prompts, downloads or changes noticed afterwards.

Step 6: make reporting normal, not blameworthy

People report early when they expect help rather than blame. Thank staff for raising a concern, even if the email turns out to be genuine. Share short, anonymised examples of scams that reached the business so people can learn what they look like. A culture of hiding mistakes gives an attacker more time.

Pair staff training with technical controls: multi-factor authentication, spam filtering, regular updates, limited administrator rights and backups that have been tested. Cyber Essentials is a useful UK government-backed framework for basic protections; our Cyber Essentials guide for Greater Manchester businesses explains where it can fit. For day-to-day protection, see TSS's cyber security support.

What to do next

Give this guide to staff, agree one clear reporting route and run a short discussion using a recent example. Then check that multi-factor authentication is in place for email and that finance has a written bank-detail verification rule. TSS helps businesses in Bury, Greater Manchester and Lancashire improve practical defences; arrange a free, no-obligation chat if you would like help setting them up.

Want staff to spot scams sooner?

Book a free, no-obligation chat and we will help you build a clear reporting and protection routine.

Call us Get a quote