A large share of the security trouble that hits small businesses starts not with clever technical hacking but with a convincing email. A message arrives that looks legitimate - appearing to come from a bank, a supplier, a delivery company, a well-known service, or even a colleague - and it tries to talk the reader into doing something: clicking a link and entering a password on a fake page, opening an attachment, or sending money or information. This is phishing, and it works by deceiving a person rather than defeating a machine, which is why the best defence is not a piece of software but a reader who recognises the warning signs. Those signs are consistent and learnable, and knowing them turns the most common attack into one that mostly bounces off.
The signals repeat because the tactics do. A sense of urgency or threat is the classic one - your account will be closed, there is a problem that must be fixed immediately, act now or lose access - because pressure is designed to make people react before they think. An unexpected request is another: a message asking you to confirm a password, update payment details, or approve something you were not expecting deserves suspicion precisely because it was unprompted. Links whose visible text does not match where they actually lead, addresses that are subtly wrong, generic greetings where a real sender would know your name, and small oddities of wording are all common tells. Any one of them is a reason to pause; several together are close to a certainty.
The habit that defends against nearly all of it is simple: do not act on the email's own links or instructions, but reach the organisation independently. If a message says there is a problem with a bank account, a business should not click its link, but go to the bank the way they normally do - a saved address, the usual app, a known phone number - and check there. A genuine issue will still be reachable that way; a fake one evaporates, because the deception depended on you using the path the attacker supplied. The same holds for an unexpected request that appears to come from a colleague or supplier: confirm it through a channel you already trust before acting, especially where money or credentials are involved.
For a small business, the most effective step is to make sure everyone who reads email knows these signs, because an attacker only needs one person to click. A brief shared understanding - that urgent, unexpected messages asking you to click or confirm something are treated with suspicion, and that anything important is verified independently before acting - costs nothing and neutralises the route by which most breaches begin. It also helps to agree that reporting a suspicious message, or admitting to having clicked one, is welcomed rather than punished, since attacks caught and owned up to early are far less damaging than ones hidden out of embarrassment. Phishing succeeds by rushing an isolated person into a mistake; a workforce that knows the signs and checks independently is the plain, cheap answer to it.