Sound familiar?
- A staff member entered their password into a fake Microsoft login page
- Customers have received invoices from your email address that you did not send
- Emails pretending to be your director are asking staff to buy gift cards
- You keep getting 'shared document' emails from addresses you do not recognise
- Your mailbox has rules you did not create
- Junk filtering misses obvious scams
Key facts
- Phishing affected 38% of UK businesses in the past year, according to the Cyber Security Breaches Survey 2025/2026
- The same survey found phishing was the most disruptive attack for 69% of businesses and charities that had a breach
- We configure Microsoft Defender for Office 365 or Exchange Online Protection anti-phishing and impersonation policies
- MFA, ideally app-based or passkeys, stops most stolen-password logins
- Suspicious emails can be forwarded to the NCSC at report@phishing.gov.uk
- One-off work: £45 an hour + VAT; ongoing cover: Complete plan £99 a month + VAT
Why phishing is the problem to fix first
The UK Government's Cyber Security Breaches Survey 2025/2026 found phishing affected 38% of businesses in the previous year, making it by far the most common attack type. Among businesses and charities that had a breach, 69% said phishing was the most disruptive one.
Modern phishing rarely looks like a badly spelled lottery win. It looks like a DocuSign request, a OneDrive share from a real supplier whose mailbox has been taken over, or a message from your director asking for a quick bank transfer. Some kits now proxy the real Microsoft login page and steal the session token as well as the password, which is why basic text-message MFA is no longer the whole answer.
How we cut phishing at the source
- Filtering: we review Exchange Online Protection or Defender for Office 365 policies: impersonation protection for your directors and domain, Safe Links and Safe Attachments where licensed, and quarantine notifications that staff actually understand.
- External sender tags: a clear "External" label on mail from outside the business makes fake internal requests easier to spot.
- Domain authentication: SPF, DKIM and DMARC on your own domain make it much harder for criminals to send email that looks like it came from you. See email security.
- Stronger sign-in: enforced MFA with the Microsoft Authenticator app, number matching, and where suitable passkeys or Conditional Access rules that block sign-ins from unmanaged devices. See password and MFA setup.
- Blocking forwarding: we disable automatic forwarding to external addresses, a favourite trick for quietly copying your mail.
Someone has clicked. What now?
Do not panic and do not delete the email. Call dijitul on 01623 650333 or 07425 323333. Here is what we do, usually remotely:
- Reset the user's password and revoke all active sessions in Microsoft Entra ID so any stolen session token stops working.
- Check the sign-in log for logins from unfamiliar countries or IP addresses.
- Remove any MFA methods the attacker registered and any inbox rules that hide or forward mail.
- Search the tenant for the same phishing email and pull it from every mailbox.
- Check whether the attacker sent mail from the account, and help you warn affected contacts.
- If a file was downloaded and run, isolate the device and scan it. See ransomware recovery if files are being encrypted.
If personal data may have been exposed, we help you assess whether it needs reporting to the ICO within 72 hours.
Invoice fraud and director impersonation
Business email compromise is where phishing turns into real money lost. An attacker reads a mailbox for weeks, then sends a perfectly timed message changing bank details on an invoice. The fix is part technical and part process:
- Agree a rule that any change of bank details is confirmed by phone, using a number you already hold, never one in the email.
- Turn on alerts for new inbox rules and unusual sign-ins.
- Protect finance staff mailboxes with stricter Conditional Access.
We can set up the technical side and give staff a short briefing as part of staff security training.
Google Workspace and other mail systems
Not everyone is on Microsoft 365. In Google Workspace we check the Gmail safety settings in the Admin console: protection against domain spoofing and employee name spoofing, warnings for unauthenticated senders, enhanced pre-delivery scanning for attachments, and the option to move suspicious messages to spam rather than just warning. We enforce 2-Step Verification for every user, and for admins we recommend security keys or passkeys.
If you still use POP or IMAP mail from a web host, filtering is usually much weaker, and moving to Microsoft 365 or Google Workspace is often the single biggest improvement. See Google Workspace support or email support.
Pricing
A phishing hardening session for a typical Microsoft 365 small business, covering policies, forwarding, external tags, DMARC and MFA, is charged at £45 an hour + VAT. Incident clean-ups are charged the same way. If you want this monitored and maintained, our Complete plan at £99 a month + VAT includes 3 hours of work each month and IT and Microsoft 365 helpdesk support, so staff can forward a suspicious email to us and ask before they click.
What it costs
Support plans from £25 a month + VAT, or £45 an hour + VAT for one-off fixes. Pick a plan if you want it looked after every month, or pay by the hour for a one-off job.
Essential
Keep it updated, backed up and watched.
- Website software updates (core, plugins, themes) applied and checked
- Daily backups
- Uptime monitoring
- Security monitoring
Business
Updates plus an hour of fixes every month.
- Everything in Essential
- 1 hour of fixes or changes every month
- Priority support
Complete
Website and your team's IT, covered.
- Everything in Business
- 3 hours of fixes or changes every month
- IT and Microsoft 365 helpdesk for your team
No plan? The first 30 minutes are the minimum charge, then we bill in 15-minute blocks.
Frequently asked questions
What should I do if I clicked a phishing link?
Do not enter anything else. If you typed a password, change it immediately from a trusted device and call your IT support. dijitul revokes active sessions, checks sign-in logs and mailbox rules, and removes the email from other inboxes. Act fast, because attackers often use stolen accounts within minutes.
Where do I report a phishing email in the UK?
Forward suspicious emails to the NCSC's Suspicious Email Reporting Service at report@phishing.gov.uk, and suspicious texts to 7726. If money or data was lost, report it to Report Fraud at reportfraud.police.uk. Tell your IT support too, so the email can be removed from colleagues' mailboxes.
Does MFA stop phishing?
MFA stops most attacks that rely on a stolen password, which is most of them. Some advanced phishing kits steal the session after you approve MFA, so dijitul also recommends number matching, Conditional Access rules and passkeys where your licences allow, plus revoking sessions quickly after any suspicious click.
Is Microsoft 365's built-in filtering enough?
Exchange Online Protection catches a lot, but default settings are not tuned for impersonation of your own directors or domain. dijitul reviews anti-phishing policies, enables impersonation protection where licensed, adds external sender tags and blocks auto-forwarding. Business Premium adds Defender for Office 365 with Safe Links and Safe Attachments.
How much does phishing protection cost?
dijitul charges £45 an hour + VAT for one-off hardening or clean-up, with a 30 minute minimum. Ongoing cover through the Complete plan is £99 a month + VAT, including 3 hours of work and helpdesk support for staff questions about suspicious emails.
Why are customers getting fake emails from my address?
Either your mailbox has been compromised, or criminals are spoofing your domain because it has no DMARC policy. dijitul checks sign-in logs to rule out a compromise, then publishes SPF, DKIM and DMARC so receiving servers can reject mail that pretends to come from you.
Related
Get it fixed
One-off fixes are £45 an hour + VAT. You'll know the likely cost before we start.