Cybersecurity

Why Phishing Keeps Getting Past Your Filter

Email filtering catches most of what it sees, and the messages that matter are built to not be seen. What actually reduces phishing risk is less about software and more about what happens after a suspicious email lands.

Every business we meet has an email filter, and every business we meet still gets phishing email. That is not a contradiction, and it is not necessarily a sign the filter is bad. It is how the economics of the attack work, and understanding that changes what you spend your effort on.

Filters are good at yesterday's attack

A filter works mostly by recognition: known bad senders, known bad links, patterns seen in millions of other mailboxes. Bulk phishing, the kind sent to everyone, gets caught at very high rates because by the time it reaches you it has already been seen elsewhere.

The messages that get through are the ones built not to be recognized. A new domain registered this week has no reputation to check. A message written for your company, mentioning a real vendor or a real project, matches no pattern. An attacker who has read a compromised mailbox first can reply inside an existing conversation, from a real account, at exactly the moment an invoice is expected.

No filter setting fixes that last one, because nothing about the message is technically wrong. The sender is real. The thread is real. Only the bank account number is new.

The question is what happens after delivery

Since some phishing will reach inboxes, the useful measure of your defenses is not whether that happens. It is what happens next.

  • Does the person who receives it recognize something is off?
  • Do they have a fast, blame-free way to report it?
  • Does the report reach somebody who can check whether nineteen colleagues got the same message?
  • If somebody clicked, does anything limit what the attacker gets?

That last point is where the technical work pays off. Multi-factor authentication means a stolen password is not enough on its own. Limited permissions mean one compromised account does not open everything. These are ordinary settings, not products, and a surprising number of businesses have them half applied.

Reporting is a culture question, not a training module

Annual security training has a place, but the businesses that handle phishing well have something simpler: staff who report odd messages without worrying about looking foolish, and somebody who actually responds to the reports.

The failure mode we see most is silence. Somebody clicks, realizes it a minute later, and says nothing because they are embarrassed. The attacker gets a week inside the mailbox instead of ten minutes. A team that hears thank you when they report, including when they report their own mistake, takes that week away from the attacker.

What to check this week

A short list, in the order we would do it:

  • Confirm multi-factor authentication is on for every mailbox, with no exceptions for executives. Attackers read org charts too, and the exceptions are the accounts they want most.
  • Ask how a member of staff would report a suspicious email today, and what would happen to the report. If the answer is a shrug, that is the gap.
  • Check the external sender warning is switched on, so a message from outside pretending to be your president is at least labeled.
  • Look at what your filter quarantined this month. It tells you what is being aimed at you.

None of this requires new spending. Most of it is configuration and habit.

Where we fit

Our cybersecurity services cover the technical half of this: the authentication setup, the mailbox rules attackers plant, the permissions that limit the damage of one bad click. The other half, the culture where reporting is fast and normal, we help build but cannot buy for you.

If you would like an honest read on where your email defenses actually stand, schedule a call. Bring a phishing email that made it through. There is nearly always one to hand.

  • Fast Track 50 Emerging Business Award, 2025
  • Top 3 Computer Support, Lake County, 2025
  • CyberCert SMB1001 Bronze
  • MSPAlliance member
  • Microsoft Partner
  • Dell Partner
  • Lenovo Partner
  • More than 20 years of experience
  • Managed services since 2010
  • Based in Northeast Ohio
  • Offices in Lake and Summit counties
  • Owner operated and independent
  • CMMC and HIPAA experience