How can our staff spot a phishing email?

Skip to main content

Last updated: 3 October 2026

Short answer: check the sender’s real address, be suspicious of urgency or threats, hover over links before clicking, and never enter a password from an email link. If in doubt, contact the sender using a number you already trust, and report it.

Want this sorted for you?Talk to our Burgess Hill team about cyber security services. Free, friendly and no obligation.
85%of UK businesses hit by a cyber attack said it involved phishing (Cyber Security Breaches Survey 2025)
43%of UK businesses had a breach or attack in the past 12 months
3 secsto check the sender before you click

What does a phishing email look like?

From: accounts@micros0ft-support.coURGENT: your account will be closed todayDear customer, we need you to confirmyour password immediately.Verify now1234Odd sender addressFear and urgencyVague greetingLink or login request

A typical phishing email: a lookalike sender, a threat, a vague greeting and a button that asks you to sign in.

What are the warning signs of phishing?

Warning sign What it looks like What to do
Lookalike sender An address that nearly matches a real brand, such as a zero instead of an o. Click the sender name to see the full address.
Urgency or threats “Account closed today”, “payment overdue”, “final warning”. Slow down. Real organisations rarely demand action in minutes.
Generic greeting “Dear customer” instead of your name. Treat it as a flag, but know that targeted attacks do use names.
Links and login requests A button that opens a sign-in page. Go to the website yourself, rather than using the link.
Unexpected attachment Invoices, voicemails or shared documents you did not expect. Confirm with the sender by phone before opening it.
Change of bank details A supplier or colleague asks you to pay a new account. Always verify by calling a number you already hold.

What should we do if someone clicks a phishing link?

  1. Do not panic and do not delete itTell your IT provider straight away, and keep the email as evidence.
  2. Change the passwordIf they typed one in, change it from a different, trusted device.
  3. Check MFA and sign-insReview recent sign-in activity and remove any unfamiliar devices.
  4. Look for forwarding rulesAttackers often add hidden rules to copy your email.
  5. Report itForward the email to report@phishing.gov.uk, the NCSC reporting service.
Make it a habit. A short “does this look right?” check before every click stops most phishing attacks, and multi-factor authentication limits the damage when someone is caught out.

How can ABCOM protect our business from phishing?

ABCOM helps businesses across Sussex reduce phishing risk with email security, multi-factor authentication, staff awareness training and monitoring through Microsoft 365. Take our free Cyber Essentials readiness quiz or book a free IT review.

Want this looked after for you?

ABCOM has supported Sussex businesses and charities since 1996 and is an NCSC Assured Service Provider – Cyber Advisor (Cyber Essentials). Talk to a real person about your IT.

Also read

How ABCOM can help

Talk to a real person at our Burgess Hill office. We are an NCSC Assured Service Provider and have supported Sussex businesses since 1996.

Scroll to Top
Free 3-minute quiz · No sign-up for your score

Is your team using AI you don’t know about?

Score your Shadow AI risk across policy, data, tools, people and detection, then get the three controls to fix first.

Take the Shadow AI Check10 questions · about 3 minutes