What Is Phishing?
Phishing is a deceptive communication designed to persuade a recipient to perform an unsafe action.
The attacker may want the user to:
- Enter a password into a fraudulent website
- Download malware
- Open a dangerous attachment
- Reveal financial information
- Share a verification code
- Approve an unauthorised payment
- Change supplier-bank information
- Give the attacker access to company systems
Phishing messages are becoming more convincing and may include company names, employee information, familiar branding or realistic-looking login pages.
CISA recommends employee training as an important protection because a workforce that recognises and reports suspicious messages can prevent attacks before they cause wider harm.
What Is Business Email Compromise?
Business email compromise, commonly called BEC, is a targeted form of email fraud.
Instead of sending the same general message to thousands of people, the attacker may research the organisation and imitate a particular executive, supplier, lawyer, manager or employee.
Common examples include:
Executive impersonation
A message appears to come from a senior executive requesting an urgent and confidential payment.
Supplier-bank-detail fraud
An attacker impersonates a supplier and claims that future payments must be sent to a different account.
Invoice manipulation
A legitimate invoice is intercepted or recreated with fraudulent bank details.
Payroll fraud
A message appears to come from an employee asking human resources to change salary-payment information.
Account compromise
An attacker accesses a genuine mailbox and studies previous conversations before sending fraudulent instructions.
Microsoft distinguishes BEC from broad phishing because BEC is usually personalised and designed to exploit established business trust and authority.
1. Protect User and Administrator Accounts
A stolen password can give an attacker access to email, files, contacts, calendars and previous business conversations.
Organisations should therefore implement controls such as:
- Multifactor authentication
- Individual user accounts
- Strong protection for administrator accounts
- Separate administrator and normal working accounts
- Immediate removal of former employees
- Regular access reviews
- Detection of suspicious sign-ins
- Secure password-reset procedures
Multifactor authentication requires an additional verification method during sign-in, reducing dependence on the password alone.
Administrator accounts require particular attention because they hold elevated privileges and are valuable targets for attackers.
2. Authenticate Your Organisation’s Email Domain
Attackers may send fraudulent messages that appear to come from an organisation’s domain.
Email authentication helps receiving systems determine whether messages were sent through authorised sources.
Three important technologies work together:
SPF
Identifies the servers and services authorised to send email for the organisation’s domain.
DKIM
Adds a digital signature that helps verify that a message is associated with the sending domain and has not been improperly modified.
DMARC
Uses SPF and DKIM results to validate the visible sending domain and define how failed messages should be handled.
Microsoft recommends using SPF, DKIM and DMARC together because relying on only one of these technologies provides incomplete protection against spoofing and phishing.
Configuration must be planned carefully. Organisations should identify every legitimate system that sends email on their behalf, including Microsoft 365, marketing platforms, business applications and external services.
3. Configure Anti-Phishing and Anti-Spoofing Policies
Microsoft 365 cloud mailboxes include built-in protections against common spam, malware, phishing and spoofing threats. Microsoft Defender for Office 365 adds more advanced protections, depending on the plan and configuration.
Anti-phishing policies can help:
- Identify spoofed senders
- Display first-contact safety warnings
- Apply stronger protection to selected users
- Detect impersonation attempts
- Protect senior executives and finance employees
- Apply different actions to suspicious messages
- Quarantine or redirect identified threats
Microsoft Defender for Office 365 adds impersonation protection and adjustable phishing thresholds beyond the anti-spoofing capabilities available to all cloud mailboxes.
Policies should be tested and reviewed to reduce both missed threats and unnecessary blocking of legitimate communication.
4. Protect Users from Malicious Links
A phishing email may contain a link that looks legitimate but opens a fraudulent login page.
The page may copy Microsoft, a bank, a courier company or another trusted service.
Safe Links in Microsoft Defender for Office 365 can check supported links when users click them in email, Microsoft Teams and supported Microsoft Office applications. If a destination is identified as malicious, the user can be shown a warning instead of being taken directly to the site.
Link protection should be combined with employee guidance:
- Do not trust a message only because it contains a familiar logo.
- Check the full sender address.
- Hover over links before opening them.
- Avoid entering passwords after following an unexpected link.
- Open important services through known bookmarks or official applications.
- Report suspicious messages to the technical team.
5. Check Dangerous Attachments Before Delivery
Malicious attachments may contain:
- Malware
- Ransomware
- Credential-stealing tools
- Harmful macros
- Fraudulent forms
- Scripts designed to compromise devices
Safe Attachments in Microsoft Defender for Office 365 provides an additional protection layer by opening eligible attachments inside a virtual environment and analysing their behaviour before delivery.
This protection complements—rather than replaces—employee caution and endpoint security.
Employees should be suspicious of unexpected:
- Invoices
- Payment confirmations
- Password-protected archives
- Macro-enabled Office files
- Delivery notices
- Job-application attachments
- Scanned-document messages
- Files requesting that security settings be disabled
6. Verify Payment and Bank-Detail Changes Outside Email
Technology cannot determine the business legitimacy of every payment request.
Organisations should establish a separate verification process for high-risk instructions.
For example:
- Do not approve new bank details based only on an email.
- Contact the supplier through a previously verified telephone number.
- Require approval from more than one authorised employee.
- Confirm unusual or urgent executive instructions separately.
- Compare the request with previous contracts and payment records.
- Record the verification and approval process.
- Immediately report inconsistencies.
Employees should never verify a suspicious message using the telephone number or contact details contained inside that same message.
Microsoft similarly advises users to independently locate and contact an organisation when verifying suspicious company emails rather than relying on links or contact information supplied in the message.
7. Protect High-Risk Employees
Some users require stronger protection because their roles make them attractive targets.
These may include:
- Chief executives
- Finance directors
- Accountants
- Procurement officers
- Human-resources employees
- System administrators
- Executive assistants
- Employees authorised to approve payments
- Employees managing confidential information
Security measures may include:
- Stronger anti-phishing policies
- Impersonation protection
- Priority-account monitoring
- Phishing-resistant authentication for privileged accounts
- Additional training
- Restricted mailbox forwarding
- Regular review of access and mailbox rules
Microsoft Defender for Office 365 supports specialised protection for priority users and impersonation scenarios, depending on licensing and policy configuration.
8. Train Employees with Realistic Scenarios
General cybersecurity awareness is valuable, but email training should reflect how the organisation actually works.
Training examples should include:
- Fake supplier-bank changes
- Fraudulent quotation requests
- Executive payment instructions
- Password-reset phishing
- Fake Microsoft 365 login pages
- Payroll changes
- Malicious document-sharing links
- Fraudulent meeting invitations
- Fake customer complaints
- Requests for verification codes
Employees should know:
- How to report a suspicious message
- Who to call about payment instructions
- What to do after clicking a suspicious link
- What to do after entering credentials
- How quickly the incident must be reported
- Why deleting the message alone is not enough
Microsoft Defender for Office 365 Plan 2 can add attack-simulation training, investigation and automated-response capabilities for organisations requiring more advanced programmes.
9. Monitor and Respond to Suspicious Activity
The organisation should define who reviews:
- Phishing reports
- Quarantined messages
- Suspicious sign-ins
- Mailbox-forwarding changes
- New inbox rules
- Administrator activity
- Malware detections
- Impersonation alerts
- Unusual message volumes
- Messages sent from compromised accounts
If an employee reports a suspected compromise, the response may include:
- Blocking or resetting the affected account
- Revoking active sign-in sessions
- Reviewing multifactor-authentication methods
- Checking mailbox rules and forwarding
- Searching for related messages
- Removing malicious email from other mailboxes
- Reviewing payment or data exposure
- Preserving evidence
- Informing authorised management
- Improving controls after the incident
TZ-CERT coordinates cybersecurity-incident response nationally in Tanzania and operates within the Tanzania Communications Regulatory Authority.
How Junubia Host Supports Email Security
Junubia Host can help organisations through a structured email-security process.
Email-security assessment
We review users, licences, administrator accounts, email flows, authentication and existing policies.
Account-protection review
We assess multifactor authentication, administrator access and employee onboarding and offboarding.
Email-authentication configuration
We support planning and configuration for SPF, DKIM and DMARC according to the organisation’s sending environment.
Microsoft 365 threat-policy configuration
We help review anti-phishing, anti-spam, anti-malware, Safe Links and Safe Attachments capabilities available under the organisation’s licences.
Executive and finance-user protection
We help identify high-risk accounts and suitable impersonation or priority-account controls.
Employee-awareness guidance
We prepare practical training focused on phishing, payment fraud, suspicious links and account compromise.
Incident-response preparation
We help establish reporting, escalation and response steps for suspected email incidents.
Ongoing review
Email-security controls should be reviewed as users, suppliers, applications, licences and threats change.


