Short answer

Phishing is a type of social engineering attack in which criminals send messages that appear to come from a trusted source to trick people into revealing credentials, opening malicious files or making payments. It is one of the most common ways attackers get into a company.

Common forms of phishing

Spear phishing targets a specific person using details about their role or company. Whaling targets executives. Smishing and vishing use SMS and phone calls. Business email compromise (BEC) impersonates a supplier or executive to redirect a payment.

Warning signs

Typical signs include urgency or pressure, an unexpected request for payment or credentials, a sender address that does not match the organisation, links that point to a different domain and attachments nobody was expecting.

How companies reduce the risk

Protection combines technology and people: email filtering, multifactor authentication so stolen passwords are not enough, awareness training and phishing simulations that show who clicks and, just as important, who reports. A clear and easy way to report suspicious messages is one of the most effective measures.

Where it shows up in compliance

Awareness training is required by ISO 27001 (Annex A 6.3), the ENS and NIS2, and phishing simulations are a common way to show it is effective.

Related terms

Keep reading on this topic

Turning employees into an active line of defence: awareness training, phishing simulation, device and identity hygiene, and SaaS access control.

Go to the topic hub