No single control stops phishing. Email filters miss sophisticated attacks. Awareness training does not reach every employee. MFA can be bypassed. Each defence reduces risk, but none eliminates it. Building a phishing-resistant organisation means layering multiple controls so that the failure of any one does not result in compromise.

Why layered defence matters

Phishing is the most common initial access vector for cyber attacks. It is cheap to execute, difficult to prevent entirely, and scales to any number of targets. Attackers continuously adapt their techniques to bypass the latest defences — and they only need to succeed once.

A layered approach accepts this reality. Rather than relying on a single control, it creates multiple opportunities to detect and stop a phishing attack at different stages:

  1. Before the email arrives — email authentication and filtering.
  2. When the employee sees the email — awareness and recognition.
  3. If the employee clicks — technical controls on the endpoint and at the link.
  4. If the employee enters credentials — authentication controls that limit the impact.
  5. After the event — detection, response, and containment.

Each layer catches what the previous layer missed.

Layer 1: Email authentication and filtering

The first line of defence is preventing phishing emails from reaching inboxes.

Email authentication

SPF (Sender Policy Framework). Specifies which mail servers are authorised to send email on behalf of your domain. Receiving servers can check whether the sending server is permitted, and reject or flag emails that fail the check.

DKIM (DomainKeys Identified Mail). Adds a cryptographic signature to outgoing emails, allowing the receiving server to verify that the email has not been tampered with and was sent by an authorised source.

DMARC (Domain-based Message Authentication, Reporting, and Conformance). Builds on SPF and DKIM by specifying what should happen when an email fails authentication (none, quarantine, or reject) and providing reporting so the domain owner can monitor abuse.

Together, SPF, DKIM, and DMARC prevent attackers from sending emails that appear to come from your domain. They do not prevent all phishing — an attacker can still use a lookalike domain — but they remove one of the most effective spoofing techniques.

Email filtering

Modern email security platforms scan incoming emails for known malicious indicators: suspicious URLs, malicious attachments, anomalous sender behaviour, and content that matches phishing patterns. Advanced platforms use machine learning to detect novel threats.

No filter catches everything. The most sophisticated phishing emails — particularly spear-phishing and BEC — are designed specifically to evade automated detection. But filtering removes the bulk of commodity phishing and reduces the volume of threats that reach employees.

Layer 2: Awareness and recognition

Technical controls handle volume. Awareness handles the emails that get through.

Training that works

Effective awareness training is specific, relevant, and repeated. Annual compliance training that employees click through in twenty minutes does not materially reduce phishing risk.

Training that works:

  • Uses real examples relevant to the organisation and its sector.
  • Is delivered in short, frequent sessions rather than a single annual event.
  • Includes interactive elements — simulations, quizzes, real-time feedback.
  • Covers the full spectrum of phishing, from generic bulk campaigns to targeted spear-phishing and BEC.
  • Is role-specific for high-risk groups (finance, HR, IT, executives).

Simulated phishing

Regular phishing simulations reinforce training by giving employees practice at recognising phishing in their actual work environment. When an employee clicks a simulated phishing link, immediate feedback (“this was a simulated phishing email — here is what you should have noticed”) turns a mistake into a learning moment.

Reporting mechanisms

Employees need a simple, frictionless way to report suspected phishing. A “report phishing” button integrated into the email client is the gold standard. Reported emails should be reviewed by the security team, and reporters should receive feedback confirming that their report was received and acted on.

A high report rate is one of the strongest indicators of organisational resilience. Building that rate requires making reporting easy, visible, and valued.

If an employee clicks a link in a phishing email, technical controls on the endpoint and at the link provide additional opportunities to prevent compromise.

URL rewriting and time-of-click scanning. Email security platforms can rewrite URLs in incoming emails so that when the employee clicks, the request is routed through a scanning service that checks the destination in real time. This catches links that were benign at delivery but were activated after the email was sent.

Browser isolation. For high-risk users, browser isolation technology renders web content in a remote environment, preventing malicious content from reaching the user’s device even if they click a link.

Endpoint detection and response (EDR). If a phishing email delivers malware (via an attachment or a drive-by download), EDR on the endpoint can detect and block the malicious activity.

Application sandboxing. Email attachments can be opened in a sandboxed environment to detect malicious behaviour before the content reaches the user.

Layer 4: Authentication controls

If an employee submits credentials on a phishing page, authentication controls determine whether the attacker can use those credentials.

Multi-factor authentication (MFA). MFA is the single most effective control against credential phishing. Even if an attacker obtains a password, they cannot authenticate without the second factor. Phishing-resistant MFA methods — hardware security keys (FIDO2/WebAuthn) — are strongest because they bind the authentication to the legitimate site and cannot be replayed on a fake login page.

Conditional access policies. Policies that restrict authentication based on device, location, or risk score can block access even when valid credentials are presented from an untrusted context.

Password policies. While MFA is the primary defence, strong password policies reduce the risk of credential reuse — where a password leaked from one service is used to access another.

Layer 5: Detection and response

The final layer assumes that all previous layers have failed and the attacker has gained access. Detection and response capabilities determine how quickly the organisation identifies and contains the breach.

Monitoring for suspicious sign-ins. Alerting on sign-ins from unusual locations, devices, or at unusual times. Alert on impossible travel (sign-ins from two distant locations in quick succession).

Email analysis. When a phishing email is reported, the security team analyses it, identifies all recipients, quarantines unread copies, and resets credentials for anyone who clicked or submitted.

Incident response playbooks. Pre-defined response procedures for phishing incidents ensure that containment happens quickly and consistently, regardless of who is on duty.

Verification procedures for sensitive actions

Separate from the technical layers, process controls provide a critical defence against BEC and targeted spear-phishing.

Any request that involves:

  • Transferring funds.
  • Changing bank or payment details.
  • Sharing sensitive data externally.
  • Granting access or resetting credentials.

…should require verification through an independent channel. A phone call to a known number, confirmation from a second authorised person, or verification through an internal approval workflow. This single control prevents the majority of BEC losses.

Continuous improvement

Phishing resilience is not a destination — it is a process. The threat landscape evolves, employees turn over, and defences degrade without maintenance.

  • Regular phishing simulations maintain awareness and provide ongoing measurement.
  • Periodic technical reviews ensure that email authentication, filtering, and endpoint controls remain effective.
  • Post-incident reviews after real phishing attempts identify what worked and what did not.
  • Metrics tracking over time demonstrates improvement to leadership and identifies areas that need attention.

The organisations that are most resilient to phishing are those that treat it as an ongoing programme — not a one-off project.