Phishing & Email Security for Small Businesses (South Jersey + Remote): A Practical Guide
- Jonathan Alessandrini
- Aug 12
- 1 min read
Phishing is still the #1 way attackers get into small businesses — and email is usually the entry point. Whether you’re based in South Jersey or working with a remote team nationwide, these steps will help you reduce risk quickly.
What phishing looks like today
Fake invoice/payment requests (often ‘urgent’).
Password reset or ‘account locked’ emails that lead to a fake login page.
Vendor impersonation (spoofed email addresses, lookalike domains).
‘CEO fraud’ asking for gift cards, wire transfers, or payroll changes.
Step 1: Require MFA everywhere
Turn on multi-factor authentication for email (Microsoft 365/Google Workspace), remote access, and any admin accounts. MFA stops most takeovers even if a password is stolen.
Step 2: Add email protections (SPF/DKIM/DMARC)
These settings help prevent attackers from spoofing your domain and improve deliverability. If you’re not sure what’s configured, it’s worth a quick audit.
Step 3: Train staff with a simple verification rule
Any request to change payment details, payroll, or passwords must be verified out-of-band (call a known number, not the one in the email). This one habit prevents a huge percentage of losses.
Step 4: Reduce inbox risk
Disable legacy/basic authentication where possible.
Use least-privilege mailbox access and shared mailbox controls.
Keep devices patched and protected (EDR/AV).
Quick checklist
MFA enabled for all users
SPF/DKIM/DMARC configured
Staff verification rule in place
Backups tested quarterly
Need help?
Book a free consultation and we’ll review your email security setup and recommend the highest-impact fixes. We work on-site in South Jersey and remotely nationwide.




Comments