Protecting an organisation against phishing takes layers, because no single control stops every lure. Block spoofed mail with DMARC, filter malicious links and domains, move staff to phishing-resistant MFA, verify every payment change, train people to report fast, watch for lookalikes of your brand and keep a takedown and incident process ready. Each layer catches what the one before it missed.
This guide is for the people who run security, IT or risk at a company. If you are looking for personal habits, read our 10 tips to stay safe from phishing instead.
Why one control is never enough
Phishing is the most reported cybercrime there is. The FBI’s Internet Crime Complaint Center received 191,561 phishing and spoofing complaints in 2025, more than any other type, according to its 2025 Internet Crime Report. Business email compromise (BEC), where a fake executive or supplier asks for a payment, led to 24,768 complaints and about $3.05 billion in reported losses that year.
The attacks also change faster than any filter. The Anti-Phishing Working Group’s Phishing Activity Trends Report for Q2 2026 quotes Fortra, which saw the number of wire transfer BEC attempts rise 88% in a quarter and the average amount requested reach $61,732. Fortra also saw more “two-step” phishing, where the first email is a harmless business enquiry and the malicious link only arrives after someone replies. A filter can’t block a link that isn’t there yet, and a trained employee can’t spot a fake login that their password manager would have caught. So you stack controls.
The structure below follows the joint guidance from CISA, the NSA, the FBI and MS-ISAC, Phishing Guidance: Stopping the Attack Cycle at Phase One, with additions for brand abuse and Indian reporting rules.
Layer 1: Stop people sending mail as your domain
Publish SPF and DKIM for every domain that sends mail, then a DMARC record. Start DMARC at p=none to collect reports, fix the legitimate senders it reveals, and move to quarantine and then reject. CISA’s guidance asks organisations to set DMARC to reject for sent mail.
Note that a policy of none only meets the minimum. Google’s email sender guidelines have required SPF, DKIM and DMARC since February 1, 2024 for anyone sending more than 5,000 messages a day to Gmail accounts, but they accept a DMARC policy of none. That gets your mail delivered. It doesn’t stop anyone forging your domain.
Don’t forget domains that never send mail. Give them a DMARC reject policy and an SPF record that allows nothing, so they can’t be used either.
Layer 2: Filter links, attachments and domains
- Scan links and attachments at the email gateway, including links rewritten at click time.
- Block known malicious domains, URLs and IP addresses with denylists, as CISA recommends.
- Use a protective DNS resolver, which refuses to resolve known phishing and malware domains for every device on the network.
- Tag external mail, and flag display names that match your executives.
Layer 3: Make stolen passwords useless
Passwords will be phished. The question is whether a phished password is enough to get in. CISA describes FIDO and PKI based MFA as phishing resistant, and its guidance tells organisations to put administrators and privileged accounts on it first. Passkeys and hardware security keys are tied to the real website, so a lookalike page can’t use them. Where you still rely on push notifications, turn on number matching. SMS codes are better than nothing, but a real time phishing kit can relay them.
Single sign-on helps too. Fewer separate logins means fewer pages for staff to be tricked on, and one place to see failed and suspicious sign-ins.
Layer 4: Verify money and access requests out of band
BEC needs no malware and no link, so technical filters often miss it. Set two rules and don’t allow exceptions:
- Any change of bank details for a supplier, employee or customer is confirmed by calling a number you already hold, never one in the email.
- Password resets and MFA changes at the help desk need identity checks that a confident caller can’t talk around.
The second rule matters because some groups phone the help desk directly. CISA’s advisory on Scattered Spider describes calls to IT help desks posing as employees to get passwords reset and MFA moved to the attackers’ devices.
Layer 5: Train people to report, not just to spot
Training works best when it is frequent, short and tied to a reporting habit. Give staff a one-click report button, thank everyone who reports, and measure how fast the first report arrives after a simulated or real campaign. That number tells you how quickly your security team learns about an attack. We cover the employee side in more depth in 6 ways to protect employees from phishing.
Layer 6: Watch the outside, and take fakes down
Many phishing attacks against your customers never touch your network. They run on lookalike domains, fake apps, social media pages and paid ads that use your name. Monitor new domain registrations and app stores for your brand, and have a removal process ready: evidence, abuse reports to the registrar, host and proxy, and follow up until the page is offline. TIKAJ’s takedown service does this end to end, and TIKAJ and Hunto handle more than 100,000 takedowns a year for over 150 enterprise customers.
Layer 7: Be ready to respond and report
Write down what happens when someone clicks: who resets the account, who checks mailbox rules and sessions, who calls the bank. In India the clock matters for compliance as well. CERT-In’s Directions of April 28, 2022 require service providers, intermediaries, data centres, body corporates and government organisations to report listed cyber incidents, including phishing attacks, within six hours of noticing them.
FAQ
What is the single most effective control against phishing?
Phishing-resistant MFA, such as passkeys or hardware security keys. Most phishing aims to steal a login, and these methods refuse to sign in to a lookalike site, so even a convincing fake page gets nothing useful. It doesn’t stop payment fraud or malware attachments, though, which is why it sits inside a layered plan rather than replacing one.
Is an SMS OTP enough to stop phishing?
No. An SMS code stops attackers who only have a password, which still helps. But modern phishing kits act as a live relay between the victim and the real site: the victim types the code into the fake page and the kit passes it on within seconds. Codes can also be lost to SIM swaps. Use passkeys or an authenticator with number matching where you can.
Do companies in India have to report phishing incidents?
Yes, in most cases. CERT-In’s Directions of April 2022 list identity theft, spoofing and phishing attacks among the incidents that service providers, intermediaries, data centres, body corporates and government organisations must report to CERT-In within six hours of noticing them. Reports go to incident@cert-in.org.in. Sector regulators such as the RBI may add their own reporting rules on top.
