Skip to main content

Threats and response

Phishing Protection

Phishing manipulates people into revealing access, approving a request or taking an unsafe action. Good protection assumes convincing messages will sometimes reach the inbox.

Plain-English guidance · Last reviewed 24 July 2026

On this page

The business case

Why it matters

Modern phishing may copy a real sign-in page, continue an existing conversation or use urgent payment and document requests. The message can arrive through email, text, social media or collaboration tools.

A blame-free reporting culture limits damage. Staff should know that promptly reporting a clicked link, entered password or approved prompt is more useful than trying to hide a mistake.

Know the exposure

Common risks

01

Credential theft

Fake sign-in pages capture passwords, codes or sessions and may immediately enrol another authentication method.

02

Payment and data fraud

An attacker impersonates a trusted person to change bank details, request files or bypass an ordinary approval.

03

Malicious files and applications

Attachments, QR codes and consent screens can install software or grant access without a traditional password prompt.

Investigate, do not ignore

Warning signs

  • Unexpected urgency, secrecy or pressure to bypass an established process
  • A sign-in page reached from a message when no sign-in was expected
  • Sender name and reply address do not match the claimed organisation
  • A familiar contact requests new bank details, gift cards, passwords or MFA approval
  • An application asks for broad mailbox, file or contact permissions

Reduce likelihood and impact

Practical steps

  1. 01

    Slow down sensitive decisions

    Verify payment, account and confidential-data requests through a known number or separate trusted channel.

  2. 02

    Use phishing-resistant sign-in

    Adopt suitable passkeys or security keys where supported, with MFA and password-manager domain matching elsewhere.

  3. 03

    Reduce message trust

    Use mail filtering and authentication, but teach staff that a familiar display name or real mailbox is not proof of a safe request.

  4. 04

    Create a one-step reporting route

    Make reporting suspicious messages and mistakes fast, visible and blame-free. Preserve the original message where practical.

  5. 05

    Respond to entered credentials

    From a trusted device, reset the affected credential, revoke sessions, inspect MFA methods and applications, and review connected accounts.

Defined website support

How AHANIX can help

AHANIX can strengthen sign-in and ownership for web-related accounts and help identify suspicious website or domain changes.

  • Review administrator access for the website, domain, DNS and hosting
  • Help enable MFA and replace reused credentials on web accounts
  • Check public website, DNS or form behaviour after a reported phishing event

Clear limits

What this cannot guarantee

  • Training, filters and MFA reduce risk but cannot guarantee that every phishing attempt will be detected or stopped.
  • AHANIX does not inspect employee devices or provide organisation-wide email monitoring, forensic investigation or emergency identity response.

Continue with existing resources

Relevant tools and guides

These links use existing AHANIX tools and guides for the next useful check or deeper explanation.

Common questions

Phishing protection questions

What should I do after entering a password on a suspicious page?

Report it immediately. From a trusted device, change the affected password, revoke sessions, check MFA and recovery methods, and review connected services. If the password was reused, replace it everywhere it appeared.

Can I tell a message is safe from the sender name?

No. Display names can be copied and real mailboxes can be compromised. Check the actual address, request context and destination, and verify sensitive actions separately.

Do phishing tests solve the problem?

Simulations can support learning when used constructively, but they do not replace safer authentication, mail controls, clear processes and rapid incident reporting.

A scoped next step

Close the web-account gaps phishing can exploit

AHANIX can review ownership, passwords and MFA for the accounts that control your website and domain.

Review web account access

Continue in the Security Centre