Cybersecurity spend keeps rising with better email filtering, stronger detection and more automation promising better protection. Yet phishing still works because while technology can reduce exposure, it can’t remove human judgment.

Phishing has evolved with the obvious, error-filled emails being replaced by messages that look and sound legitimate. Attackers now mimic tone, branding, and context and reference real suppliers, projects, and processes to feel familiar and credible. They also pick their moment by sending their communications during busy periods such as at the end of the day or when key people are unavailable. The aim isn’t just to deceive, it’s to create enough urgency to skip the checks.

Phishing isn’t just an awareness issue; it’s a behavioural risk to which even experienced professionals are vulnerable. People are trained to respond quickly, be helpful and keep work moving and attackers exploit exactly that.

When phishing succeeds the consequences can be immediate: credential theft, unauthorised access, data exposure or fraudulent payments. In professional services it can also compromise client confidentiality and cause regulatory scrutiny and reputational damage. Technology helps but technology alone isn’t enough. The best defence combines awareness with repeatable verification habits.

 

A few habits reduce risk fast:

  • Treat unexpected requests for credentials, payments or sensitive data as high risk

  • Don’t trust the display name or address; both can be easily spoofed using low cost tools

  • Slow down when a message feels urgent, unusual or does not follow your established processes

  • Verify via a second channel using known contact details (and not those in the email!)

  • Report suspicious emails quickly so others can be warned

Simple actions create big impact if they’re consistent.

Most incidents happen not because controls are missing but because they’re bypassed in the moment.

Phishing isn’t going away any time soon. As protection toolsets improve attacks will evolve to find the weak spot. The organisations that manage this best aren’t always those with the fanciest products; they’re the ones that make safe behaviour easy and routine.

Phishing is a reminder of a simple truth: the weakest link is often not the system, but how it’s used.

    David Baskerville

    David Baskerville

    07769 946883

    Do this today:

    Pick one verification rule (e.g. “payments always confirmed by phone”) and make it non-negotiable.

    Other articles in the 'Keep It Real' series

    Keep It Real 5: Backups – The Last Line of Defence (Often Untested)

    Keep It Real 5: Backups – The Last Line of Defence (Often Untested)

    Most organisations say they have backups. Few can say, confidently, that they’ll work when the worst happens and they are needed. Backups are treated as a background safety net but in ransomware attacks, system failure or data loss they’re not a nice-to-have; they’re...

    Keep It Real 4: Access Control. Who Actually Has Access to What?

    Keep It Real 4: Access Control. Who Actually Has Access to What?

    Most organisations assume access is under control: logins exist, permissions are assigned and systems sit behind authentication. On paper it looks tidy but in reality access piles up over time, with little visibility and less removal. “Access creep” is one of the most...

    Keep It Real 3: Software Updates, The Patch You Didn’t Apply

    Keep It Real 3: Software Updates, The Patch You Didn’t Apply

    We tend to picture cyber breaches as sophisticated attacks beating sophisticated defences. In reality many breaches exploit something simpler such as a known vulnerability with a fix that was never applied. Patching is one of the most basic and effective security...

    Keep It Real 1: World Password Day – The Basics Still Matter

    Keep It Real 1: World Password Day – The Basics Still Matter

    World Password Day is 7 May. The problem isn’t awareness; it’s execution. Phishing is growing in both volume and sophistication. Messages now mimic suppliers, colleagues and trusted services with convincing branding, tone and timing. Often, attackers aren’t “breaking...

    Latest Articles

    Selecting the right technology for your law firm

    Selecting the right technology for your law firm

    Choosing the right technology starts with understanding how your firm works, what it needs and whether the systems you already have could deliver more. David Baskerville recently contributed to a Today’s Conveyancer feature on how law firms can select the right...

    AI in the Right Way – Webinar |  Thu 1 October

    AI in the Right Way – Webinar | Thu 1 October

    AI is moving quickly. For law firms, the harder question is how to turn that pace of change into something practical, controlled and genuinely useful. On 1 October, Cathy Kirby and David Baskerville will be delivering a webinar exclusively for LawNet members, looking...

    Talk to us today

    Get In Touch

    Discover more from Baskerville Drummond LLP

    Subscribe now to keep reading and get access to the full archive.

    Continue reading