Require multifactor authentication for email, finance, administration and cloud services. Limit privileges, remove dormant accounts and monitor unexpected sign-ins or forwarding rules.
Authenticate the domainMaintain accurate SPF and DKIM records and deploy DMARC through a monitored path toward enforcement. This makes direct spoofing harder and provides visibility into systems sending as the organisation.
Verify sensitive requests separatelyChanges to bank details, urgent payments, password resets and confidential data requests should be confirmed using a trusted second channel. Do not rely on contact details supplied inside the suspicious message.
Teach observable behaviourTraining should focus on practical signals: unexpected urgency, altered domains, unusual file-sharing links and requests that bypass normal process. Make the reporting route obvious and avoid blaming people who report quickly.
Prepare a first-hour responseKnow how to reset credentials, revoke sessions, inspect mailbox rules, preserve evidence and notify affected parties. Viewertech can review mail configuration and help establish a proportionate incident procedure before an event occurs.
Talk to ViewertechFor practical guidance tailored to your organisation, contact the Viewertech team.
