How to Recognize a Phishing Email Before It's Too Late
Phishing is the entry point for the vast majority of successful cyber attacks against small and mid-sized businesses. Modern phishing emails are polished, personalized, and often reference real people and real projects. This article walks through the warning signs, common tactics, and a step-by-step response procedure your team can actually use.
The warning signs that still work
No single signal is proof, but a combination should trigger caution. Train your team to slow down when they see two or more of these.
- Sender address slightly wrong (m1crosoft.com, support@microsott.com)
- Display name matches a real person, but the underlying email address doesn't
- Urgency and pressure: 'you have 24 hours', 'account will be suspended'
- A link to review, approve, or sign in: hover to see the real URL before clicking
- Unusual request outside normal process: CEO asking for gift cards, vendor changing bank details
- Attachment you weren't expecting, especially .html, .htm, .zip, .iso, or Office files with macros
- Generic greeting when the sender should know your name
- Grammar, spelling, or formatting inconsistent with the real sender
Common phishing tactics we see against Sudbury businesses
Microsoft 365 login harvesting
An email pretending to be from Microsoft, IT, or a shared document notification asks you to sign in to view or approve something. The link goes to a fake Microsoft login page that captures your password and MFA code in real time.
Fake invoice / DocuSign / e-transfer
A document notification from a service you recognize (DocuSign, Adobe, QuickBooks) asking you to review an invoice. The link leads to a login harvest or malware.
CEO / owner impersonation
An email that looks like it's from the owner or a senior manager, sent to finance or an assistant, asking for a quick wire transfer, gift card purchase, or vendor payment. Usually 'urgent' and 'I'm in a meeting, can't call.'
Vendor banking change request
An email from a vendor (or compromised vendor mailbox) informing you they've changed banking details for future payments. Always verify by phone using a known number.
What to do when you spot a suspicious email
- Don't click the link, don't open the attachment, don't reply
- Report it to IT or use the 'Report Phishing' button if configured in Outlook
- If you already clicked and entered a password, reset the password immediately and tell IT
- If you already sent money, contact your bank first, then IT, then your cyber insurer
Not sure where your security gaps are?
Our free cybersecurity risk assessment scores your posture across MFA, backup, endpoint protection, and email security, then hands you a prioritized fix list.
Talk to a Security SpecialistPrevention beats detection
Individual vigilance matters, but layered controls stop far more attacks than training alone. Email filtering with impersonation detection, MFA on every account, and EDR on every endpoint together stop the vast majority of phishing consequences even when a click happens.
Frequently asked questions
How often should staff receive phishing training?
Short, ongoing training with periodic simulated phishing tests is far more effective than annual one-off sessions. Aim for monthly touchpoints, not annual.
Should we punish staff who fall for phishing tests?
No. Punitive programs cause underreporting, which is the opposite of what you want. Reward reporting, coach the individual privately, and treat repeated issues as a training conversation.
What if I already clicked?
Reset your password immediately (from a clean device), tell IT, and if you entered credentials, revoke Microsoft 365 sessions and enable MFA if it wasn't already. Speed matters.
Can AI stop phishing entirely?
AI-based email filtering catches much more than legacy filters, but no filter is perfect. Layered controls plus trained staff plus MFA is what actually works.
Joshua Arimoro
Joshua Arimoro is the Principal Consultant at Nickel City Tech Solutions, a managed IT and cybersecurity provider based in Lively, Ontario, serving businesses across Greater Sudbury and Northern Ontario. He works hands-on with Microsoft 365, server and network infrastructure, endpoint management, and backup and recovery for small and mid-sized organisations.
More about our teamRoll out phishing training and testing
Security awareness training and phishing simulations are part of every managed cybersecurity engagement.
Related services, locations, and resources
Related services
- Cybersecurity Services
Endpoint protection, MFA, email filtering, and M365 hardening.
- Managed IT Services
Proactive monitoring, patching, and predictable monthly support.
- Microsoft 365 Support
Exchange, Teams, SharePoint, OneDrive, and licensing.
- Backup & Disaster Recovery
Backup strategy, monitoring, and recovery testing.
Related service areas
Related resources
- Backing Up Primafact Case Files Properly
Case files in Primafact represent years of litigation work that can't be recreated. Here's what a proper ba…
- PCLaw Support for Ontario Law Firms: The IT Side of Running PCLaw
PCLaw handles billing, trust accounting, and time tracking for many Ontario firms. Here's what keeps it run…
- Protecting PCLaw Trust Accounting Data
Trust accounting data inside PCLaw deserves a distinct layer of protection. General infrastructure guidance…
- What Does a Sophos Firewall Actually Do for a Small Business?
A business-grade firewall does far more than block traffic at the edge. Here is what a device like a Sophos…
