Cyber-Safe Certification: Why You Should Get It for Your Small Business
Phishing isn’t new, but it’s evolving. With generative AI, fraudulent emails are much more convincing, mimic the tone of your business partners, and target each employee with precision. Understanding this evolution is the first step in protecting your business. Here’s what’s changing and, most importantly, how to defend yourself.
Why AI Makes Phishing More Dangerous
For a long time, a phishing email could be spotted by its clumsy mistakes: spelling errors, awkward phrasing, and a poorly rendered logo. These red flags made it easy to spot and filter out. Generative AI has eliminated these flaws.
Today, an attacker can produce a perfectly crafted message in just a few minutes, in the language of your region, modeled after the style of a supplier or colleague. They can analyze your professional posts to personalize their approach: your job title, your projects, and your manager’s name. The message becomes credible because it sounds like you.
AI also expands the attack surface beyond email. Voice deepfakes can mimic an executive’s voice using just a few audio clips. Video deepfakes can simulate a person on a video call. Identity theft has reached a new level: it’s no longer just a fake sender, it’s a familiar voice or face urging you to act quickly.
New Forms to Watch Out For
- Spear phishing: a targeted attack on a specific individual, using real information (organizational chart, ongoing projects) to appear legitimate.
- CEO fraud: a fake executive, via email or phone call, requests an urgent and confidential wire transfer. AI now makes it possible to imitate their voice.
- Smishing: the same principle via text message, often involving a link to click or a package to claim, which plays on a sense of urgency and mobile habits.
What these attacks have in common: they don’t primarily target your systems, they target you as individuals. A large proportion of cybersecurity incidents stem from human error: one too many clicks, or misplaced trust. This is precisely where defense comes into play.
Warning signs to watch for
- A sense of urgency or pressure: you must act immediately, without telling anyone.
- An unusual request: a money transfer, a change to bank account information, or a request to send login credentials.
- Imposed confidentiality: you’re asked not to verify the request with a colleague.
- A slightly altered sender’s address, or a link whose URL doesn’t match the displayed text.
- An unusual communication channel: a manager suddenly contacting you via text message or private messaging.
The right response is simple: when in doubt, don’t click, don’t pay, and verify through another known channel.
Protecting Yourself Technically
- Email filtering: solutions that block a large portion of malicious messages and dangerous links before they reach you. Useful, but never foolproof: a well-written message sent from a legitimate domain will get through.
- Domain authentication (SPF, DKIM, DMARC): by default, nothing prevents a stranger from sending an email that displays your address as the sender. These three settings, configured on your domain name, close that loophole, ensuring your genuine messages are delivered more reliably.
- Multifactor authentication (MFA): enable it everywhere, no questions asked. But it’s no longer enough on its own: a fake login page can relay your code directly to the real service and hijack your session. For sensitive access (executive, finance, administrators), aim for phishing-resistant MFA using FIDO2 keys or passkeys.
- Monitoring and detection: monitor access and abnormal behavior, and allow connections only from devices known to the company. A stolen session then becomes unusable elsewhere.
- Updates and access management: limit permissions to what is strictly necessary and keep systems up to date to close unnecessary doors.
These building blocks form a foundation, not a shield. None of them makes phishing impossible: they reduce the attack surface and buy you time to respond. And since the most effective attacks target the person before the machine, the decisive battle is fought elsewhere.
Protecting the Human Element: The Decisive Factor
This is our belief: the best protection against phishing is a trained and vigilant team. Technology filters; people decide.
- Regular awareness training: short, practical formats, such as e-learning, that explain attack mechanisms and best practices, rather than technical jargon.
- Phishing simulations: send fake training emails to gauge actual responses and turn every mistake into a learning opportunity, without making anyone feel guilty.
- A culture of skepticism: instill the idea that it’s always legitimate to double-check, ask a question, or take your time. No one should feel at fault for wanting to verify a request.
This is the approach we take with our clients in French-speaking Switzerland: providing the technical tools and, at the same time, building teams’ skills so they can become the first line of defense.
FAQ
How can you spot an AI-generated phishing email?
Don’t just look for spelling mistakes: check the facts. The exact sender’s address (even a single character change is enough), the actual destination of a link (hover over it without clicking), and the plausibility of the request: a supplier suddenly changing its bank details, an unusual emergency, or an unexpected attachment. If in doubt, don’t reply to the message: contact the sender through a channel you already know.
How can you verify a suspicious voice or video (deepfake)?
Throw the caller off their script: ask a question that only the real person would know the answer to, or an unexpected question unrelated to the request. Warning signs include a slight delay in responses, a refusal to change the subject, or constant pressure to act quickly. The most effective defense is to call the person back using a channel you’re already familiar with, their usual number or internal messaging, never the number that just called. You can also establish rules in advance: a prearranged code word, or two-person verification for any sensitive request.
How can you thwart a CEO fraud scheme?
No urgent or confidential transfer request should be approved based solely on a phone call or email, even if it includes the CEO’s voice or signature. Protection is organizational: a systematic double-check on all payments exceeding a defined threshold, and an absolute rule requiring verification through a second channel. A company that implements these two rules significantly increases its level of security, regardless of the quality of the deepfake.
Conclusion
AI-enhanced phishing cannot be combated with a single tool, but rather with a two-pronged defense: technology that filters and humans who make the final decision. We support companies and institutions in French-speaking Switzerland on both fronts. Discover our cybersecurity services. Want to assess your exposure to phishing and raise awareness among your teams? Let’s talk.
Tags :
9/29/26, 10:00 AM