Free windows logo window illustration Business Continuity

How to Keep Your Business Running When Microsoft 365…

Summary: The tools that run your business, like Microsoft 365, your accounting app, or your booking system, are reliable most of the time, but they do go down. When one does, work can stop for hours, and you often can’t do anything but wait for the provider to fix it. A simple plan keeps your team working and your customers informed while you wait.

Most of your business probably runs in the cloud now. Email, files, accounting, bookings, payments, it’s all online. Then one day a service goes down, and nobody can send an email, open a file, or take a payment.

It doesn’t take a hacker for this to happen. In July 2024, a faulty software update from the security company CrowdStrike crashed millions of Windows computers around the world in a few hours. Microsoft estimated it hit 8.5 million devices, grounding flights and stopping work at banks and hospitals.

Outages happen, even to the big names

Microsoft 365 itself has had days where email or Teams stopped working for hours. Internet providers have bad days too, and when yours does, everything online goes with it. Any tool you depend on can go down.

So much of a small business runs on a handful of online services now, and if one goes down, the work that depends on it stops until it’s back. Being with a big, well-known provider doesn’t protect you from this.

What an outage does to a small business

When a key service goes down, your team can’t get to email or files, so work stops. If your payment or booking system is offline, you can’t take money or appointments. Customers try to reach you and can’t, and you can’t reach them either. Staff end up sitting around waiting.

You usually can’t fix it yourself. When a big provider has an outage, all you can do is wait for them to sort it out. The goal of a plan is to keep working, and keep customers informed, until they do.

What a simple plan covers

A good plan answers these questions:

  • Which tools are critical? List the handful of services that would stop the business if they’re down, like email, your payment system, or your booking tool. Ignore the ones you could live without for a day, and focus on the few that would halt the work.
  • How will people keep in touch? Have a backup way to reach staff and customers that doesn’t depend on the tool that’s down. That might be phone numbers, a group chat on a different app, or text messages.
  • What do you need reachable offline? Keep a copy of the essentials, like your customer contact list, key phone numbers, and important documents, somewhere you can open if the main system is down. A printout or a copy on a phone is enough.
  • Who’s in charge? Decide who makes the decisions during an outage and who keeps customers updated. When it’s clear in advance, people act instead of waiting to be told.
  • Where do you check, and who do you call? Know where to see whether it’s a wider outage, which is usually the provider’s status page, and who to call for help, which is usually your IT provider.

What to do the moment an outage hits

  1. Check whether it’s just you. Look at the provider’s status page, or ask whether anyone else is having the same problem. If it’s a wider outage, there’s nothing to fix on your end, so stop trying.
  2. Tell your team. Let people know what’s down and what to use instead, so nobody wastes an hour rebooting a laptop that was never the problem.
  3. Switch to your backup way to communicate. Move to the phone, text, or another app so the team can still coordinate.
  4. Tell customers if it affects them. If you can’t take bookings or payments, say so and tell them when to try again.
  5. Note when it started and what’s affected. A couple of lines is enough. It helps you follow up afterward and spot anything that needs fixing once things are back.

A few things that make outages hurt less

  • Keep key files available offline. With OneDrive or SharePoint, recent files can sync to the device so you can still open them when the service is down. Ask your IT provider to make sure this is set up.
  • Have a backup way to get online. A mobile hotspot from a phone can get a few key people working again if your main internet drops.
  • Know your status pages. Bookmark the status page for Microsoft 365 and your other main tools. It’s the fastest way to tell whether the problem is them or you.
  • Keep contacts off the cloud. Have your important phone numbers and contacts somewhere that doesn’t need the internet, like a printout or your phone’s own contact list.
  • Ask your IT provider about alerts. Many can set up a warning that tells you about an outage before your customers do.

Keep your plan on one page

Keep this to a single page, somewhere you can reach without your main systems, whether that’s printed or in a separate app. Write down your critical tools, your backup way to communicate, where the essentials live, who’s in charge, and who to call. Review it once or twice a year so the names and numbers stay current.

Frequently asked questions

Isn’t the cloud always available?

No. Cloud services are reliable, but they still have outages, and even the biggest providers go down sometimes. The CrowdStrike outage in 2024 took millions of computers offline in a few hours. It’s safer to assume an outage will happen eventually and have a plan for it.

What should a continuity plan include?

The basics: which tools are critical, a backup way to reach staff and customers, where to find essential information if the main system is down, who’s in charge during an outage, and who to call for help. One page is enough for most small businesses.

What if the internet itself goes down, not just one app?

Plan for that too. A mobile hotspot from a phone can get key people back online, and a phone call still works when your systems don’t. Keep important numbers and contacts somewhere that doesn’t need the internet.

How can my team keep working if Microsoft 365 is down?

It depends on the work, but options include using files already saved on a synced device, switching to phone or text to stay in touch, and handling anything urgent on paper until service returns.

How long do outages usually last?

There’s no set answer. Some are fixed in minutes, others take most of a day. That’s the reason to plan around them, since you can’t count on a quick fix and you can’t speed it up from your end.

Whose job is this?

Yours, with help from your IT provider. They can tell you which of your tools are most at risk, set up things like synced files and a status-page alert, and help you write a simple plan.

Sources and further reading

If you’re not sure which of your tools would hurt most if they went down, or you’d like help putting a simple plan together, your IT provider can work through it with you. And if you don’t have an IT provider, feel free to reach out to us and we’ll help you sort it.

—

Featured Image Credit

This Article has been Republished with Permission from The Technology Press.

Free Cloud Network photo and picture Cloud

OneDrive or SharePoint? Where Your Business Files Should Live

Summary: If your business uses Microsoft 365, you have both OneDrive and SharePoint, and files usually end up scattered across them with no clear rule. OneDrive is for your own work, and SharePoint is for files the team shares. Getting this right makes files easier to find, safer when someone leaves, and easier to recover if something goes wrong.

If your business runs on Microsoft 365, you’ve got two places to store files: OneDrive and SharePoint. Most people are never told the difference, so files end up wherever is easiest, spread across OneDrive, SharePoint, Teams, and the desktop.

That’s how you end up with the everyday headaches: a file nobody can find, a document only one person can open, and a scramble to recover someone’s work after they leave. The rule for where things should go is simple once you know what each one is for.

What each one is for

OneDrive is your own space. Think of it as the cloud version of the My Documents folder on your computer: your work files, private to you unless you choose to share them. It’s the right place for drafts and anything only you need.

SharePoint is the team’s space. It’s built for files with shared ownership, the documents your team, department, or the whole business works on together. Microsoft’s own advice is straightforward: if you’re working on something by yourself, save it to OneDrive; if you’re working as a team, save it where the team works.

Where Teams fits in

Microsoft Teams confuses this for a lot of people, because it looks like a third place to keep files. In reality, when you upload a file to a Teams channel, it’s stored in that team’s SharePoint site. The Files tab in Teams is just a view into SharePoint.

So if your team works in Teams, your shared files are already in SharePoint, whether you realized it or not. That’s a good thing. It means the files have shared ownership and don’t belong to one person’s account.

So where should your files live?

Here’s the rule that keeps things simple:

  • If it’s your own draft or something only you need, keep it in OneDrive.
  • If the team needs it, more than one person works on it, or it’s a client or project file, put it in SharePoint (or the Teams channel for that work, which is the same thing).
  • Don’t leave important shared files sitting only on someone’s desktop or only in their personal OneDrive.

Sharing files the right way

Where a file lives also changes how you share it.

When you share a file from your OneDrive, you’re sending people into your personal space, usually with a link tied to your account. That works, but the link depends on you. If you leave, or the file moves, those links can stop working, and whoever relied on them is stuck.

In SharePoint or a Teams channel, the right people already have access, because the files belong to the team rather than to you. You can point a colleague to the folder and they’re in, with no one-off links to manage.

It’s also worth sharing a link instead of emailing a copy. When everyone opens the same file in OneDrive or SharePoint, they’re all looking at the current version, and you avoid ending up with five slightly different copies attached to five different emails.

Why this matters

Putting files in the right place saves you real trouble later.

Take what happens when someone leaves. Their personal OneDrive isn’t shared by default, so any important work kept only there can be hard to reach. Microsoft holds a deleted user’s OneDrive for 30 days by default and gives their manager access, but that turns into a rush against the clock. Files kept in SharePoint stay with the team no matter who comes or goes.

It also makes files easier to find. When the team’s documents live in one shared SharePoint library, people know where to look, instead of hunting through inboxes and personal drives.

And it helps you recover from mistakes. Both OneDrive and SharePoint keep older versions of your files and a recycle bin, so if a document gets overwritten or ransomware scrambles your files, you can roll back to a clean copy instead of starting over.

How to get it right

  • Put shared work in SharePoint or Teams. Anything the team works on together belongs in a shared library. Keep it out of one person’s OneDrive.
  • Keep OneDrive for your own files. Drafts and personal work are fine there. Just don’t let it become the only home for something the team needs.
  • Get files off local desktops. A file saved only on a laptop isn’t backed up, isn’t shared, and is gone if the laptop is lost. Move important files into OneDrive or SharePoint. You can still work from your computer the way you always have: the OneDrive app keeps a copy on the device for offline use and saves your changes to the cloud automatically.
  • Agree where things go. A simple, shared rule, like “client files live in the client’s SharePoint folder,” saves endless confusion later.
  • Use version history when you need it. If a file gets changed or deleted by mistake, you or your IT provider can restore an earlier version rather than redoing the work.

Frequently asked questions

What’s the difference between OneDrive and SharePoint in one line?

OneDrive is for your own work files. SharePoint is for files your team shares.

Where do files in a Teams channel get stored?

In SharePoint. Every team has a SharePoint site behind it, and the Files tab in a channel is a view into that site. Uploading a file to Teams is the same as putting it in SharePoint.

Should I keep work files on my computer’s desktop?

Try not to, for anything important. A file only on your desktop isn’t shared or backed up, and it’s gone if the device is lost or breaks. Save it to OneDrive or SharePoint instead, where it’s protected and reachable.

What happens to files in someone’s OneDrive when they leave?

By default, Microsoft keeps a deleted user’s OneDrive for 30 days and gives their manager access, and that window can be extended if it’s set up in advance. It’s recoverable, but it’s far easier if shared work was in SharePoint to begin with.

Can I get back a file that was deleted or changed by mistake?

Usually, yes. OneDrive and SharePoint both keep a recycle bin and older versions of files, so you can restore a deleted file or roll back to an earlier version. Your IT provider can help if you can’t find it.

Sources and further reading

If your files are scattered and you’re not sure what should sit where, your IT provider can set up a simple structure in SharePoint and move things into the right place, so files are easy to find and safe when people come and go. And if you don’t have an IT provider, feel free to reach out to us and we’ll help you sort it.

—

Featured Image Credit

This Article has been Republished with Permission from The Technology Press.

Free web design user interface website illustration Cybersecurity

Is Your Business Website a Security Risk?

Summary: Most small-business websites run on WordPress, and the biggest risk is usually old plugins that nobody has updated. Attackers scan the web for these known weak spots and use the sites they find to spread malware, post spam, or steal what visitors type into forms. Keeping the site and its plugins updated, and knowing who is responsible for that, prevents most of it.

Your website is one of those things you set up once and then stop thinking about. It sits there doing its job, so there’s no reason to touch it. That’s exactly why a neglected website is one of the common ways a small business gets hacked.

Most small-business sites run on WordPress, which powers more than 40% of all websites, according to W3Techs. WordPress itself is solid. The risk is usually the plugins and themes added to it, which often don’t get updated for years.

How a neglected website gets hacked

Attackers don’t usually pick your business by name. They run automated tools that scan huge numbers of websites looking for known weak spots, like a plugin with a security hole that hasn’t been fixed. When the tool finds one, it breaks in. It’s all automatic, and it isn’t aimed at you personally.

That’s why old plugins are the problem. When a plugin maker finds a security flaw, they release an update to fix it. Until you install that update, the hole stays open, and the automated scanners know exactly what to look for. Security researchers who track WordPress flaws find that the large majority are in plugins and themes, not in WordPress itself.

What a hacked website is used for

A hacked website rarely announces itself. Instead of shutting your site down, attackers usually keep it running and use it for their own purposes:

  • Serving malware. Your site gets changed so that visitors are infected or pushed to a page that tries to install something.
  • Spam and scam pages. Attackers add hidden pages selling fake goods or pushing scams, riding on your site’s good standing with search engines.
  • Stealing form data. If your site has a contact or checkout form, a hacked site can copy what people type into it, including personal or payment details.
  • Redirects. Visitors who click your link get sent somewhere else, often a scam or malware site.

The damage lands on you even though the attacker was after your visitors. Search engines flag hacked sites with warnings and drop them down the rankings, and browsers may block them, so customers see a red “this site may be dangerous” screen instead of your homepage.

Is your website at risk?

It depends on how your site is built.

If you use a hosted website builder like Wix, Squarespace, or Shopify, most of the security and updates are handled for you behind the scenes, so your risk is lower.

If you have a self-hosted WordPress site, usually set up by a web designer or agency on your own hosting, then keeping WordPress, the plugins, and the themes updated is someone’s job. The question is whose. On a lot of small-business sites, the honest answer is that nobody has touched it since it launched.

You can usually tell your site is at risk if you don’t know who maintains it, it hasn’t been updated in a year or more, or it’s running plugins from a developer who has since disappeared.

How to keep your website safe

  • Keep everything updated. WordPress, plugins, and themes all need updating when new versions come out. Many sites can be set to update automatically.
  • Remove plugins you don’t use. Every extra plugin is another thing that can go wrong. If you’re not using it, delete it.
  • Stick to well-known plugins. Use ones that are popular, well-reviewed, and updated recently. Avoid anything that hasn’t been touched in years.
  • Watch for abandoned plugins. Sometimes a plugin stops being updated, or gets removed from the plugin store because of a security problem. When that happens it stops getting fixes, so check now and then that the plugins on your site are still supported, and replace any that aren’t.
  • Lock down the admin login. Use a strong, unique password for the website’s admin account, and turn on multi-factor authentication if your setup supports it.
  • Add a security plugin or web firewall. A reputable one can block common attacks and warn you when something changes. Your web host or IT provider can recommend one.
  • Keep backups. If the worst happens, a recent backup lets you restore the site instead of rebuilding it from scratch.
  • Know who’s responsible. Decide who looks after updates and security, whether that’s your web designer, your IT provider, or your hosting company, and make sure it’s clearly somebody’s job.

What to do if your site is hacked

If your site does get hacked, moving quickly limits the damage:

  • Get help straight away. Cleaning a hacked site properly is a job for your web host, IT provider, or a website security service. Most hosts have dealt with this many times and can help.
  • Take the site offline. Putting up a simple “down for maintenance” page stops visitors from being harmed while it’s cleaned up.
  • Change the passwords. From a device you know is clean, change the passwords for your hosting account and the website’s admin login, and turn on multi-factor authentication.
  • Restore a clean backup. If you have a backup from before the hack, restoring it is often the fastest fix. If you don’t, the site will need to be cleaned by hand.
  • Update and tidy up before it goes back live. Update WordPress, the plugins, and the themes, and remove anything you don’t recognize or no longer use, so the same hole doesn’t get used again.
  • Tell anyone whose data was affected. If the site handled customer details or payments, check whether any of that was exposed, and let those people know if it was.

Frequently asked questions

How do I know if my website has been hacked?

Common signs are a warning from Google or your browser, a drop in search traffic, pages or pop-ups you didn’t add, or your web host getting in touch about a problem. If you’re not sure, your IT provider or web host can check.

Do I need to update my website if it works fine?

Yes. A site can look completely normal to you while an out-of-date plugin leaves a door open for attackers. Updates close those holes, which is why they matter even when nothing looks wrong.

I use Wix or Squarespace. Am I at risk?

Much less so. Hosted builders handle the updates and most of the security for you. You should still use a strong admin password and MFA, but you’re not responsible for patching plugins the way a self-hosted WordPress site is.

Who should maintain my website?

Someone should own it clearly: your web designer or agency, your IT provider, or your hosting company, depending on your setup. The important thing is that someone is actually doing the updates.

What is a security plugin or web firewall?

It’s a tool that sits on your website, blocks common attacks, watches for changes, and can alert you to problems. On WordPress, a reputable security plugin is a common, low-cost way to add that protection.

Sources and further reading

If you’re not sure whether your website is being kept up to date, or who’s responsible for it, that’s worth sorting out before something goes wrong. Your IT provider or web host can check where things stand and take over the upkeep. And if you don’t have an IT provider, feel free to reach out to us and we’ll help you sort it.

—

Featured Image Credit

This Article has been Republished with Permission from The Technology Press.

Free seo search engine optimization google illustration Cybersecurity

Why You Should Scroll Past the First Result on…

Summary: Scammers buy ads on Google and other search engines using the names of trusted brands and software, so their fake site shows up at the very top, above the real one. Click it and you can land on a fake page that steals your login or installs malware. You can avoid nearly all of it by skipping the sponsored results and going to the real website yourself.

When you search Google for a program to download or a website to log into, the first thing you see is usually an ad. It sits at the top, marked “Sponsored,” and most people click it without a second thought, because the top result is normally what you wanted.

Scammers count on that. They buy ads on the names of trusted companies and popular software, so their fake site appears right at the top, above the real one, and you click it thinking it’s the official page.

How the scam works

The trick is called malvertising, short for malicious advertising. A scammer buys a search ad for a term people trust, like the name of your bank, a Microsoft login, or a common program such as a PDF reader or a video player. The ad looks normal, with the real brand name and a web address that looks right.

When someone clicks it, they land on a page built to look exactly like the real one. Sometimes that page asks you to log in and hands your username and password straight to the scammer. Other times it offers the software you were after, and the download installs malware instead of the real program.

Why these ads are so easy to fall for

These ads are convincing. They sit above the real result, so they’re the first thing you see. They use the real company’s name and a web address that looks right. And they show up on a search you started yourself, so they don’t feel as suspicious as a random email or text would.

Attackers have also gotten good at hiding from the checks meant to stop them. They show a clean, harmless page to the ad reviewers and the real, malicious page to everyone else, so the ad can pass review and still do damage.

How common is this?

Very. In its 2025 Ads Safety Report, Google said it blocked or removed more than 8.3 billion ads that broke its rules, suspended 24.9 million advertiser accounts, and took down 602 million ads tied to scams. Google also noted that criminals are now using AI to make fake ads faster.

Security researchers have found scam search ads pretending to be well-known programs like VLC, 7-Zip, and CCleaner, and even Google’s own apps, with downloads that installed password-stealing malware. These show up on the everyday searches your team runs.

What this means for your business

For a business, the risk comes up in two everyday situations: downloading software, and logging in.

When someone downloads software, they search for a tool, click the top ad, and install something that steals the passwords and logins saved in their browser.

When someone logs in, they search for “Microsoft 365 login” or their bank, click the ad rather than the official link, and type their username and password straight into a fake page.

In both cases, the problem is info-stealing malware. Once it’s on a machine, it can steal saved passwords, browser cookies, and session tokens, which can get an attacker into accounts even when multi-factor authentication is switched on.

How to protect your team

  • Scroll past the sponsored results. The ads sit at the top, marked “Sponsored” or “Ad.” The real website is usually just below, in the normal results.
  • Don’t download software from an ad. Type the maker’s web address yourself, or search and use the normal result, then download from the official site.
  • Bookmark the sites you log into. For your bank, Microsoft 365, and other important accounts, use a saved bookmark instead of searching each time.
  • Keep devices and browsers updated. Turn on automatic updates so a bad download is less likely to work.
  • Tell your team this is a thing. Most people have no idea the top result can be a trap, and once they know, they stop clicking it.

Frequently asked questions

Aren’t ads at the top of Google checked and safe?

Google reviews ads and removes billions that break its rules, but scammers still slip through by showing reviewers a clean page and everyone else the malicious one. A “Sponsored” label doesn’t mean the site is safe.

What is malvertising?

Malvertising is short for malicious advertising: scammers buy online ads, often on trusted brand names, to send people to fake sites that steal logins or install malware.

How do I download software safely?

Go to the maker’s official website by typing the address yourself, or search and use the normal (non-ad) result. Don’t download from a sponsored ad, and don’t trust a download that arrives through one.

What should I do if someone clicked a scam ad?

If they only visited the page, close it and don’t enter anything. If they typed a password, change it and turn on MFA. If they downloaded and ran a file, disconnect the device and have your IT provider check it for info-stealing malware.

Does an ad blocker help?

It can. A reputable ad blocker hides many sponsored results, which takes the fake links off the page before anyone can click them. It isn’t a complete fix, so keep the habits above too.

Sources and further reading

If you’d like to give your team a plain rundown of what a scam ad looks like, or tighten how software gets installed on your computers, your IT provider can help with both. And if you don’t have an IT provider, feel free to reach out to us and we’ll help you sort it.

—

Featured Image Credit

This Article has been Republished with Permission from The Technology Press.

Free scam phishing fraud illustration Cybersecurity

How to Spot a Scam Email Now That They…

Summary: Scammers now use AI to write their phishing emails, so the spelling and grammar mistakes that used to give them away are gone. The UK’s National Cyber Security Centre and the FBI both warn that AI makes these messages cleaner, more personal, and harder to spot. The way to catch them now is to look at what an email is asking you to do, because the writing no longer gives anything away.

For years, the advice for spotting a scam email was simple: look for bad spelling and clumsy grammar. A real bank or supplier writes properly, the thinking went, so a message full of mistakes was probably fake. It was easy to teach, and for a long time it worked.

It doesn’t anymore. Scammers now use AI to write their emails, and AI writes cleanly. The typos and awkward phrasing that used to give phishing away are gone, and the messages landing in your team’s inbox read as well as anything from a real company. Worse, they can be written to sound like they came from someone you already know.

Why the old advice stopped working

The spelling-and-grammar tell worked because a lot of scammers were writing in a language that wasn’t their own, and the mistakes showed. AI took that away.

The UK’s National Cyber Security Centre says generative AI can now create convincing phishing lures “without the translation, spelling and grammatical mistakes that often reveal phishing.” The FBI says the same: criminals use AI to limit the grammar and spelling errors that used to mark a message as fake, so it reads as believable. That means the one thing most people were trained to look for no longer tells you much.

Why these emails are so convincing now

  • The writing is clean. A scam email reads like a normal business email, because a machine wrote it in seconds, in whatever tone the attacker asked for.
  • It’s personal. Attackers can feed public details about your company into an AI tool, pulled from your website, your team’s LinkedIn profiles, or a press release, and get a message tailored to you: the right names, the right job titles, and a believable reason to be in touch.
  • There’s more of it. AI makes each message faster to produce, so attackers send far more. The FBI’s Internet Crime Complaint Center added a section on AI to its annual report for the first time, tied to more than 22,000 complaints and nearly $893 million in reported losses.

These days, the scam email isn’t the obvious one anymore. Instead of “Dear customer, your account is suspended,” someone in your finance team gets a message that looks like it’s from a supplier they really deal with, mentions a real project, and asks to update the bank details for the next invoice. It reads exactly like a real supplier email. The only thing wrong is that the supplier never sent it.

Your spam filter won’t catch them all

It’s tempting to assume your email security will handle this. It catches a lot, and you should keep it switched on. But a well-written, personalized email that asks a normal-sounding question doesn’t always look dangerous to a filter, especially when it carries no obvious bad link or attachment. Both the NCSC and the FBI expect AI to push more of these messages through, which is why the last line of defense is a person who knows what to check.

It’s not just email anymore

AI has done the same thing to phone calls and texts. The FBI warns that criminals can clone a voice from a short audio clip, enough to leave a voicemail that sounds like your boss or a family member asking for an urgent payment. The same thing that makes AI emails so convincing makes AI phone scams convincing too. The defense is the same: if a call or voicemail asks for money or logins, hang up and call the person back on a number you already have.

Here are the signs you should still pay attention to

If you can’t trust how an email is written, look at what it’s asking you to do. That’s where the real warning signs are, and AI hasn’t changed them:

  • It asks for money, gift cards, or a payment to a new account.
  • It asks for a login, a verification code, or personal details.
  • It creates pressure: a deadline, a threat, or a “do this now.”
  • It asks you to change the bank details for an invoice or a supplier.
  • It comes with a link or attachment you weren’t expecting.
  • The display name looks right, but the actual email address doesn’t match it.

Every one of these is about what the email is asking for. So the rule to teach your team is simple: when a message is about money, logins, or how you pay someone, slow down before you act.

How to protect your team

  • Check money and login requests another way. If an email asks you to pay a new account or change a supplier’s bank details, call the person on a number you already have. Don’t reply to the email or use a number it gives you.
  • Stop telling staff to watch for bad spelling. Tell them to look at what the email is asking for, and to slow down when it’s about money or logins.
  • Make one rule for payment changes: confirm every change to bank details by phone, even when it’s urgent.
  • Turn on phishing-resistant MFA or passkeys, so a stolen password is harder to use even if someone gets tricked.
  • Make it easy to report a suspicious email and make sure nobody feels silly for checking.
  • Remind the team now and then that scam emails look perfect these days. A quick five-minute chat beats a poster nobody reads.

Frequently asked questions

Can you still spot a phishing email by bad spelling and grammar?

Not reliably. Attackers use AI to write clean, correct emails now, so a message with perfect spelling can still be a scam. Judge it by what it asks you to do.

What are the warning signs that still work?

The request itself: paying money, changing bank details, sharing a login or code, or being pushed to act urgently. Those signs don’t depend on how the email reads.

Is AI-generated phishing really more effective?

Yes. The NCSC and the FBI have both warned that AI makes phishing more convincing and more personal, and the FBI has tied AI to tens of thousands of fraud complaints and hundreds of millions in losses. Cleaner, tailored messages get opened and clicked more often.

Will my spam filter stop AI phishing?

It will catch a lot, and you should keep it on. But a well-written, personalized email with no obvious bad link can still look legitimate to a filter, so don’t rely on it alone. A trained person is the backstop.

What should staff do if they aren’t sure about a message?

Slow down and check through a channel they trust, like calling a known number or asking the person directly. And report it, even if it turns out to be genuine.

Sources and further reading

•  NCSC: The near-term impact of AI on the cyber threat — the UK cyber agency on AI producing phishing lures without the usual spelling and grammar mistakes.

•  FBI IC3: Criminals Use Generative AI to Facilitate Financial Fraud — how criminals use AI-generated text and cloned voices, and how it removes the usual signs of fraud.

If you’d like help teaching your team what to watch for, or turning on phishing-resistant logins so a fooled password doesn’t turn into a break-in, your IT provider can set both up. And if you don’t have an IT provider, feel free to reach out to us and we’ll help you sort it.

—

Featured Image Credit

This Article has been Republished with Permission from The Technology Press.

TSD Managed Services
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.