top of page
Search

Phishing & Email Security for Small Businesses (South Jersey + Remote): A Practical Guide

  • Jonathan Alessandrini
  • Aug 12
  • 1 min read

Phishing is still the #1 way attackers get into small businesses — and email is usually the entry point. Whether you’re based in South Jersey or working with a remote team nationwide, these steps will help you reduce risk quickly.

What phishing looks like today

  • Fake invoice/payment requests (often ‘urgent’).

  • Password reset or ‘account locked’ emails that lead to a fake login page.

  • Vendor impersonation (spoofed email addresses, lookalike domains).

  • ‘CEO fraud’ asking for gift cards, wire transfers, or payroll changes.

Step 1: Require MFA everywhere

Turn on multi-factor authentication for email (Microsoft 365/Google Workspace), remote access, and any admin accounts. MFA stops most takeovers even if a password is stolen.

Step 2: Add email protections (SPF/DKIM/DMARC)

These settings help prevent attackers from spoofing your domain and improve deliverability. If you’re not sure what’s configured, it’s worth a quick audit.

Step 3: Train staff with a simple verification rule

Any request to change payment details, payroll, or passwords must be verified out-of-band (call a known number, not the one in the email). This one habit prevents a huge percentage of losses.

Step 4: Reduce inbox risk

  • Disable legacy/basic authentication where possible.

  • Use least-privilege mailbox access and shared mailbox controls.

  • Keep devices patched and protected (EDR/AV).

Quick checklist

  • MFA enabled for all users

  • SPF/DKIM/DMARC configured

  • Staff verification rule in place

  • Backups tested quarterly

Need help?

Book a free consultation and we’ll review your email security setup and recommend the highest-impact fixes. We work on-site in South Jersey and remotely nationwide.

 
 
 

Comments


bottom of page