How do you protect a team from phishing?
Technical controls stop most phishing before anyone sees it, and phishing-resistant MFA makes the rest survivable. Training matters, but it works as a reporting mechanism rather than a filter — the goal is a team that reports quickly, not a team that never clicks. Assume someone will click.
Phishing did not go away, it changed channel
Cisco Talos’ Q1 2026 incident response review found phishing back as the leading initial access vector, at over a third of engagements where entry could be determined.
The channel shifted, though. Mandiant’s M-Trends 2026 shows voice phishing at 11% of initial infections — now second overall — while email phishing fell to 6%. Verizon’s 2026 DBIR adds that mobile social engineering succeeds around 40% more often than traditional email phishing.
If your entire programme is an email gateway plus an annual e-learning module, you are defending the channel attackers are leaving.
Layer one: stop what you can technically stop
Authenticate your email properly
SPF, DKIM and DMARC at an enforcing policy stop attackers spoofing your own domain at other people and at your staff. Many organisations publish DMARC at “none” and never move to quarantine or reject, which produces reports but no protection.
Deploy phishing-resistant MFA
This is the control that changes outcomes. Push approvals and one-time codes can be relayed by a proxy in real time. FIDO2 keys and passkeys are cryptographically bound to the legitimate site, so a convincing replica gets nothing reusable. Prioritise administrators, finance and anyone who can change payment details.
Close the bypasses
Talos found MFA gaps contributing to 35% of engagements, including attackers registering their own device on a compromised account or using a mail client that sidesteps the check. Disable legacy authentication protocols and alert on new device registrations.
Layer two: make reporting fast and blameless
The single most useful metric is not click rate. It is time-to-report: how long between the first person receiving a malicious message and your security team knowing about it. A one-click report button in the mail client, and a culture where reporting a mistake is met with thanks rather than a lecture, moves that number more than any training module.
Punitive simulated-phishing programmes actively work against this. If clicking gets you named in a report, the rational response is to say nothing — which is precisely the behaviour that turns one click into an incident.
Layer three: verification rules for high-risk actions
Voice cloning means a familiar voice is no longer evidence of identity. Write down the rules before you need them:
- Bank detail changes require callback to a number already on file, never one supplied in the request.
- MFA resets and privilege grants require identity verification the caller cannot fake by knowing public facts.
- Urgency plus secrecy is treated as a warning sign, not a reason to skip the process.
Most voice phishing succeeds at the service desk, so these rules belong there first.
What to do in the first hour after a click
Reset the credential and revoke active sessions and refresh tokens — a password reset alone does not evict an attacker holding a live session. Check for new device registrations, new mailbox rules, and any forwarding that appeared. Then check what that account could reach, because the account is rarely the objective.
Where Rivo fits
Our cybersecurity services cover identity and access management, multi-factor rollout, email security and the incident response planning that makes the first hour routine. Talk to our engineers about hardening your identity layer.





