Common forms of phishing
Spear phishing targets a specific person using details about their role or company. Whaling targets executives. Smishing and vishing use SMS and phone calls. Business email compromise (BEC) impersonates a supplier or executive to redirect a payment.
Warning signs
Typical signs include urgency or pressure, an unexpected request for payment or credentials, a sender address that does not match the organisation, links that point to a different domain and attachments nobody was expecting.
How companies reduce the risk
Protection combines technology and people: email filtering, multifactor authentication so stolen passwords are not enough, awareness training and phishing simulations that show who clicks and, just as important, who reports. A clear and easy way to report suspicious messages is one of the most effective measures.
Where it shows up in compliance
Awareness training is required by ISO 27001 (Annex A 6.3), the ENS and NIS2, and phishing simulations are a common way to show it is effective.




