Building a Phishing Defence in Layers
No single tool stops all phishing. How to combine email security, strong sign-in, payment checks and a reporting culture so one miss does not become a breach.

Every defence against phishing has gaps. Filters miss new messages, people have busy days, and codes can be relayed. A layered defence accepts this and makes sure that when one layer misses, the next one catches it.
Layer 1: stop it arriving
- Email filtering with your provider's protections switched on. See what filters catch and miss.
- SPF, DKIM and DMARC on your own domain. See email authentication explained.
- Warning banners on external email.
Layer 2: make clicks harmless
- Browser protection and updates. See browser protections.
- Password managers that only autofill on real sites.
- Passkeys or security keys on email and admin accounts. See why some two-step verification can be phished.
Layer 3: make money hard to move
- Verify any change of bank details by phone on a known number. See changed bank details fraud.
- Two people approve large or unusual payments.
- No exceptions for urgency or seniority. See whaling.
Layer 4: people who report
- An easy report button and a no-blame culture. See report buttons.
- Short, regular practice. See phishing simulations.
Layer 5: respond fast
- A simple plan for when someone clicks or enters a password.
- Know how to reset passwords, end sessions and check forwarding rules.
Give staff a quick way to check. Anyone can paste a suspicious message into CyberWatch AI Scan for a free check.
For the full picture, see how to protect yourself from phishing.
Frequently asked questions
What is the single most important layer?
There is no single one, which is the point. If forced to choose, phishing-resistant sign-in and a payment verification rule prevent the most costly outcomes.
Can a small organization do this?
Yes. Most layers are settings and habits, not expensive products.
Where do people fit in?
People are the layer that reports what technology missed. Their job is not to be perfect but to speak up quickly.
Sources
- Phishing attacks: defending your organisation, UK National Cyber Security Centre
- Small organisations guide to cyber security, UK National Cyber Security Centre
- Implementing phishing-resistant MFA (fact sheet), US Cybersecurity and Infrastructure Security Agency


