In short
Phishing is an attempt to obtain credentials, payments or data through a faked message. It poses as a bank, a supplier, an authority or your own management. It attacks a person under time pressure rather than a system — which is why antivirus software alone does not protect against it.
How you spot one — and how you no longer can
The old tells have stopped working. Spelling mistakes and clumsy greetings were signals while the messages were machine-translated; today they are clean, in the right register, and often in Swiss spelling.
Two patterns remain: urgency («today», «final notice») and a break in the normal process — a payment request outside the usual route, a change of bank details from a known supplier, a request from management that bypasses the phone.
The most expensive case for an SME
Not the click on a link, but the changed payment details. An email announces a supplier's new bank account, the next invoice is paid to it, and the error surfaces with the reminder — weeks later.
No software prevents this. A rule does: every change of payment details is confirmed through a second channel, using the number from the contract and not the one in the email.
What actually helps technically
Three things, in this order. First, two-factor authentication on every account: an intercepted password alone then opens nothing. Second, correctly configured mail authentication (SPF, DKIM, DMARC) so nobody can write under your own domain.
Third, a place to report it that works without blame. Someone who fears the conversation after a click does not report it — and ten minutes of damage becomes ten days.
How we handle it
We set the mail records, switch two-factor sign-in on across the board, and write down the payment-change rule so it still applies when things are urgent.
How we work: IT security and Microsoft 365 — that is where the settings live that catch most of the cases.
Related terms
A term in your quote that nobody explained?
In a strategy call we translate the offer in front of you — even when it did not come from us.