Blog/Phishing

Phishing Awareness for Small Teams Without IT Staff

No IT department? A simple phishing routine for small businesses, charities and clubs: key settings, a payment rule, a reporting habit and a one-page checklist.

CyberWatch AI2 October 2026 · 2 min read
A small team working together around a table

Small teams are targeted by phishing just like large companies, often more, because criminals expect fewer checks. The good news: the most effective protections are simple habits and settings you already have.

Five things to set up once

  1. Two-step verification on every email account, ideally with passkeys. See passkeys vs phishing.
  2. A password manager for the team, so passwords are unique and shared safely. See password managers as a phishing alarm.
  3. Separate admin accounts for the person who manages email and the website.
  4. Email authentication on your domain. See SPF, DKIM and DMARC.
  5. Automatic updates on every device and browser.

Two rules everyone follows

  • The payment rule: any new or changed bank details are confirmed by phone on a number you already had. No exceptions, even for the boss. See changed bank details fraud.
  • The report rule: anything suspicious goes to one named person, straight away, with no blame. See why reporting quickly matters.

A simple response checklist

If someone…Do this
Clicked a linkClose it, tell the named person, run a security scan.
Entered a passwordChange it, sign out all sessions, check forwarding rules.
Paid moneyCall the bank immediately, then report to police.
Opened an attachmentDisconnect the device and get help. See opened a phishing attachment.

Keep it fresh

Share one real phishing example at a team meeting each month and talk through the signs. Short and regular beats long and annual. For a fuller plan, see our small business security checklist.

No IT person to ask? Paste suspicious messages into CyberWatch AI Scan for a free check.

For more, see how to report phishing in our complete guide.

Frequently asked questions

What is the most important step for a small team?

Protect email accounts with strong two-step verification and agree a rule that any change of payment details is checked by phone.

Who should staff report phishing to?

Name one person, even if they are not technical. Their job is to receive reports, warn others and follow the response checklist.

Do we need to buy security tools?

Most protections are settings already included in your email and browser. Start there before buying anything.

Sources

  1. Small organisations guide to cyber security, UK National Cyber Security Centre
  2. Cybersecurity for Small Business, US Federal Trade Commission
  3. Cyber Essentials, US Cybersecurity and Infrastructure Security Agency
Share this article
LinkedIn WhatsApp X
For organizations

Your people get these messages at work too.

CyberWatch AI sends your staff realistic practice attacks, trains the gaps it finds, and shows management exactly where the organization stands.