Reducing the Risk of Phishing Attacks
- Jul 29
- 1 min read

One of the most common cyberattacks organizations and everyday people face is phishing. A phishing attack occurs when cybercriminals send fake emails, text messages, or websites that appear legitimate in order to trick users into revealing passwords, financial information, or other sensitive data. Because phishing targets people rather than technology, it remains one of the biggest cybersecurity threats to businesses.
As an Information Systems (IS) manager, reducing the risk of phishing requires a combination of technology, policies, and employee awareness. My advice to managers includes:
Regular Security Awareness Training. Employees should learn how to recognize suspicious emails, unexpected attachments, fake links, and urgent requests for sensitive information.
Conduct Phishing Simulations. Sending simulated phishing emails helps employees practice identifying scams and improves their ability to respond to real attacks.
Require Multi-Factor Authentication (MFA). Even if a password is stolen, MFA makes it much harder for attackers to gain access to company systems.
Email Security Tools. Modern email filters can detect and block many phishing attempts before they reach employees' inboxes.
Keep Systems Updated. Regular software updates and security patches reduce vulnerabilities that attackers may exploit after a successful phishing attempt. Technology alone cannot stop every attack, so organizations need employees and customers who understand the risks and know how to respond. Continuous training, phishing simulations, and strong authentication methods significantly reduce an organization's chances of becoming a victim.


Comments