Phishing basics
TL;DR
Phishing works on people, not software: a believable message, a reason to act, and a link or attachment. It’s consistently one of the most effective ways in. The defences are MFA, awareness, filtering, and making it easy to report.
Only ever run phishing exercises with explicit written authorisation and defined scope.
What it is
A message that pretends to be something trusted to get someone to do something — click a link, enter a password, open a file. It targets the human, which is why it sidesteps a lot of technical controls.
How it works
The pattern is always the same: a pretext (who it claims to be), a lure (why you should act now — urgency, authority, fear), and an action (the link or attachment). On a test it’s used to measure how an organisation responds, not to catch people out.
How to defend
- MFA, so a phished password alone isn’t enough.
- Regular, blame-free awareness training, and a one-click way to report suspicious mail.
- Email filtering, link protection, and alerting on the follow-up (unusual logins after a click).
Reference: MITRE ATT&CK T1566: Phishing.