Cybersecurity spend keeps rising with better email filtering, stronger detection and more automation promising better protection. Yet phishing still works because while technology can reduce exposure, it can’t remove human judgment.
Phishing has evolved with the obvious, error-filled emails being replaced by messages that look and sound legitimate. Attackers now mimic tone, branding, and context and reference real suppliers, projects, and processes to feel familiar and credible. They also pick their moment by sending their communications during busy periods such as at the end of the day or when key people are unavailable. The aim isn’t just to deceive, it’s to create enough urgency to skip the checks.
Phishing isn’t just an awareness issue; it’s a behavioural risk to which even experienced professionals are vulnerable. People are trained to respond quickly, be helpful and keep work moving and attackers exploit exactly that.
When phishing succeeds the consequences can be immediate: credential theft, unauthorised access, data exposure or fraudulent payments. In professional services it can also compromise client confidentiality and cause regulatory scrutiny and reputational damage. Technology helps but technology alone isn’t enough. The best defence combines awareness with repeatable verification habits.
A few habits reduce risk fast:
-
Treat unexpected requests for credentials, payments or sensitive data as high risk
-
Don’t trust the display name or address; both can be easily spoofed using low cost tools
-
Slow down when a message feels urgent, unusual or does not follow your established processes
-
Verify via a second channel using known contact details (and not those in the email!)
- Report suspicious emails quickly so others can be warned
Simple actions create big impact if they’re consistent.
Most incidents happen not because controls are missing but because they’re bypassed in the moment.
Phishing isn’t going away any time soon. As protection toolsets improve attacks will evolve to find the weak spot. The organisations that manage this best aren’t always those with the fanciest products; they’re the ones that make safe behaviour easy and routine.
Phishing is a reminder of a simple truth: the weakest link is often not the system, but how it’s used.

David Baskerville
07769 946883
Do this today:
Pick one verification rule (e.g. “payments always confirmed by phone”) and make it non-negotiable.
Other articles in the 'Keep It Real' series
Keep It Real 5: Backups – The Last Line of Defence (Often Untested)
Most organisations say they have backups. Few can say, confidently, that they’ll work when the worst happens and they are needed. Backups are treated as a background safety net but in ransomware attacks, system failure or data loss they’re not a nice-to-have; they’re...
Keep It Real 4: Access Control. Who Actually Has Access to What?
Most organisations assume access is under control: logins exist, permissions are assigned and systems sit behind authentication. On paper it looks tidy but in reality access piles up over time, with little visibility and less removal. “Access creep” is one of the most...
Keep It Real 3: Software Updates, The Patch You Didn’t Apply
We tend to picture cyber breaches as sophisticated attacks beating sophisticated defences. In reality many breaches exploit something simpler such as a known vulnerability with a fix that was never applied. Patching is one of the most basic and effective security...
Keep It Real 1: World Password Day – The Basics Still Matter
World Password Day is 7 May. The problem isn’t awareness; it’s execution. Phishing is growing in both volume and sophistication. Messages now mimic suppliers, colleagues and trusted services with convincing branding, tone and timing. Often, attackers aren’t “breaking...
Latest Articles
Selecting the right technology for your law firm
Choosing the right technology starts with understanding how your firm works, what it needs and whether the systems you already have could deliver more. David Baskerville recently contributed to a Today’s Conveyancer feature on how law firms can select the right...
AI in the Right Way – Webinar | Thu 1 October
AI is moving quickly. For law firms, the harder question is how to turn that pace of change into something practical, controlled and genuinely useful. On 1 October, Cathy Kirby and David Baskerville will be delivering a webinar exclusively for LawNet members, looking...
AI Watermarking Is Coming. What Happens When the Watermark Gets Washed Out?
The EU's new AI transparency rules have pushed a potentially misunderstood concept into the mainstream: watermarking AI-generated text. In this article, David Baskerville discusses the principles and legislative background to the use of AI Watermarks, and explains how...









