Living guide · Cyber Security

Protecting Business Email From Phishing and Invoice Fraud

The email that costs a small business the most is not malware. It is a polite message asking finance to update a supplier's bank details. This guide covers the scenarios we see, the controls that stop them, the checks staff should make, and how we manage it for clients.

Last reviewed 10 September 2026 Published 10 September 2026 11 min read
Book a Discovery Call
This guide is for you if
  • Someone in your business has received, or nearly acted on, a fake payment request.
  • You want to know what Microsoft 365 already does about phishing and what it does not.
  • You need a short set of rules your finance team will actually follow.
In this guide
  1. 1. The scenarios
  2. 2. The controls
  3. 3. Staff checks
  4. 4. If it happens
  5. 5. How we help
  6. 6. FAQs
01

Four scenarios we see in real businesses

Phishing was involved in 85% of the breaches UK businesses identified last year (Cyber Security Breaches Survey 2025/26), and business email compromise cost victims .77 billion in 2024 according to the FBI. The mechanics are less dramatic than the numbers.

1. The supplier bank-detail change. An email arrives from a supplier you really use, on their real thread, saying they have changed banks. Either the supplier's mailbox has been compromised, or the domain is a lookalike. Finance updates the details. The next payment goes to the criminal.

2. The urgent request from the boss. "I am in a meeting, can you pay this invoice today, I will explain later." From a lookalike address, or from the director's real mailbox after a password was phished.

3. The credential harvest. A message "from Microsoft" or "from IT" with a link to a login page that looks right. The password goes to the attacker, who logs in, sets up a forwarding rule, and waits for an invoice to intercept.

4. The compromised customer. A customer's mailbox is taken over and used to send you a malicious attachment, from a real address you trust, on a real thread.

Scenarios 1 and 4 are why "we know our suppliers" is not a defence, and scenario 3 is why the fraud often starts weeks before anyone notices.

02

The controls that stop most of it

ControlWhat it stopsWhere it comes from
MFA enforced for everyone, legacy authentication blockedScenario 3: a stolen password is useless on its own.Every Microsoft 365 plan (security defaults); Conditional Access on Business Premium.
SPF, DKIM and DMARC at reject on your domainsCriminals sending as you to your customers and staff.DNS records; see the email security guide.
Impersonation protection listing your directors and key suppliersScenarios 1 and 2 from lookalike addresses and display names.Defender for Office 365 Plan 1, in Business Premium.
Safe Links and Safe AttachmentsMalicious links checked at click time; attachments detonated before delivery (scenario 4).Defender for Office 365 Plan 1.
Preset security policies (Standard or Strict)Microsoft's recommended anti-phishing, spam and malware thresholds instead of the defaults.Every plan for the basics; Defender for the advanced settings.
External email taggingA visible banner on mail from outside the business, so "from the MD" from outside stands out.Exchange Online setting.
Auto-forwarding blocked and inbox rules alertedThe attacker's first move after a compromise.Exchange Online and Defender alerts.
One-click reporting and someone who reviews the reportsFinds the campaign that got through, and removes it from everyone else's inbox.Report Message add-in; Defender for Office 365 for the clean-up.
MonitoringRisky sign-ins and new forwarding rules seen when they happen.Entra ID alerts, and a SOC if you want them read at night.

Not sure which of these applies to your business? Ask an engineer.

Book a Discovery Call
03

The checks for staff, especially finance

Technology stops most attempts. People stop the rest, and the rule set has to be short enough to survive a busy Friday.

  1. Bank-detail changes are verified by phone, on a number you already hold, not one in the email. No exceptions, including for the MD.
  2. Urgency is a signal, not a reason. Any payment request that says "today" or "do not tell anyone" is checked by a second person.
  3. Look at the address, not the name. Display names are free; the address behind them is what matters. Hover before you click; on a phone, press and hold.
  4. Never log in from a link in an email. Go to the app or type the address.
  5. Report, do not delete. The report button tells IT and protects colleagues who got the same message.
  6. If you did click, say so immediately. The cost of a compromise is set by how fast it is found, not by whether it happened.

Put these on one page, get the directors to sign it, and rehearse it once a year. Phishing simulations (included with Defender for Office 365 Plan 2 in the Defender Suite) make the rehearsal realistic.

04

If money has gone

Speed matters more than anything. Contact your bank immediately and ask them to recall the payment; banks can sometimes freeze funds if told within hours. Report to Action Fraud (England, Wales and Northern Ireland) or Police Scotland. Preserve the emails and headers. Then find out how it happened, because if a mailbox was compromised the attacker may still be in it; our compromised account guide covers that sequence.

05

How Black Sheep Support manages email protection

Email protection is part of our security baseline: the domain records at reject and monitored, Defender for Office 365 presets applied and tuned, impersonation lists maintained as your suppliers change, external tagging, forwarding blocked, reporting in place and reviewed, and alerts routed to monitoring. We also run the finance-team briefing and, for clients on the Defender Suite, phishing simulations. [TO CONFIRM: whether awareness training and simulations are a standard inclusion or an add-on.]

Start with the free domain security audit to see whether your own domain can be spoofed, then book a review of the inbound side.

Want a second opinion before you buy licences?

We will look at your tenant, tell you who would actually benefit, and what needs fixing first. An engineer, not a salesperson.

Book a Discovery Call
06

Frequently asked questions

Does Microsoft 365 protect against phishing?

Every plan includes basic anti-spam, anti-malware and spoof protection. The controls that stop targeted phishing and invoice fraud (impersonation protection, Safe Links, Safe Attachments) come with Defender for Office 365, included in Business Premium, and all of it needs configuring.

What is business email compromise?

Fraud carried out through email that appears to come from a trusted person or company: a supplier changing bank details, a director requesting a payment, or a compromised real mailbox used to redirect money. The FBI recorded .77 billion in losses from it in 2024.

How do we stop invoice fraud?

Verify every bank-detail change by phone on a known number; protect your own domain with DMARC; use impersonation protection for suppliers and directors; enforce MFA so a phished password cannot be used; and monitor for forwarding rules. All five together.

Should we train staff or rely on technology?

Both. Technology stops the volume; a short, rehearsed set of rules for finance stops the targeted attempt that gets through. Neither works alone.

What should we do if we paid a fraudulent invoice?

Call your bank immediately to attempt a recall, report to Action Fraud or Police Scotland, keep the emails, and check whether a mailbox was compromised. The faster the bank is told, the better the chance of recovery.

Are phishing simulations worth it?

For most businesses, yes, once the basics are in place. They make the rules real and show who needs a quiet word. They are included with Defender for Office 365 Plan 2 in the Defender Suite for Business Premium.

Book an email security review

We will check whether your domain can be spoofed, what your inbound protection is actually configured to do, and what your finance team's process would stop, and give you the fixes in order.

  • Your domain's SPF, DKIM and DMARC state.
  • What Defender and Exchange are and are not doing for you today.
  • The finance-team rules on one page.
  • What monitoring would add.
Book an email security review

Sources

Prices and product facts on this page were checked against the following Microsoft pages on the dates shown.

  1. 1.FBI Internet Crime Complaint Center: 2024 Internet Crime Report · accessed 10 September 2026
  2. 2.GOV.UK: Cyber Security Breaches Survey 2025/2026 · accessed 10 September 2026
  3. 3.Microsoft Learn: Why do I need Microsoft Defender for Office 365? (Plan 1 vs Plan 2) · accessed 10 September 2026

What has changed on this page

  • 10 September 2026Page published. Statistics from FBI IC3 2024 and the UK Cyber Security Breaches Survey 2025/26.

Related reading