The email does not look ridiculous.
The logo is right. The sender’s name is familiar. The request is plausible. Maybe a vendor says its payment instructions changed. A manager needs a document quickly. A client wants account information sent somewhere new. A service says the business needs to log in and fix a problem.
Nothing about the message screams scam.
That is exactly why a useful business security process cannot depend on somebody spotting a typo.
For a small business, the practical goal is not to turn every employee into a cybersecurity analyst. It is to make a few risky requests require verification before anyone acts.
What should a business verify before acting on an email request?
Verify any unexpected or changed request involving money, passwords, account access, sensitive information, payment instructions, or an unusual download by contacting the person or company through a channel you already trust—not through the contact information supplied in the message.
That last part matters.
If a questionable email says, “Call me at this new number to confirm,” using that number does not independently verify anything. Use the number already in your records, the vendor’s known portal, an established contact, or a public company website you navigate to yourself.
The National Institute of Standards and Technology’s small-business phishing guidance recommends exactly that kind of separate verification for urgent requests, including contacting a boss or vendor directly using known contact information rather than information in the message.
The old red flags still help. They are no longer a process.
Suspicious spelling, strange formatting, a mismatched address and awkward wording can still expose a bad message.
But “look for bad grammar” is a weak security policy in 2026.
NIST now specifically warns small businesses that artificial intelligence can be used to create increasingly convincing phishing messages. A fraudulent request can be grammatically clean, professionally written and tailored to a believable situation.
That changes the question employees should ask.
Instead of only asking, Does this email look fake?, ask: Would we verify this type of request even if the email were real?
That is a much stronger rule because it does not require the employee to correctly diagnose the scam first.
Protect the action, not just the inbox
Email filters matter. Spam detection matters. Authentication matters. Training matters.
None of them should be the only thing standing between a convincing message and a high-consequence action.
Imagine an office manager at a commercial landscaping company who regularly receives invoices from suppliers. One afternoon, a familiar supplier appears to send updated ACH instructions. The message fits the job. The invoice amount is ordinary. The signature looks normal.
The dangerous step is not receiving the email.
It is changing the payment destination based only on the email.
A simple company rule—all changes to vendor payment instructions are confirmed using the vendor contact already on file—moves the security control to the point where money can actually leave the business.
The same idea works elsewhere:
- A request for a password does not receive a password. The employee goes directly to the known account or asks the appropriate administrator.
- A request to send sensitive customer records to a new address gets independently confirmed.
- An unexpected shared document is verified before the employee signs in through its link.
- A manager’s unusual request for a payment, gift card, credential or confidential file gets confirmed outside the original message.
The Federal Trade Commission’s Cybersecurity for Small Business guidance recommends internal verification policies and gives wire-transfer requests received by email as a specific example of something employees should call to confirm.
Don’t make employees improvise the verification step
“If something seems suspicious, check with someone” sounds reasonable until the employee is busy, the request appears normal, and nobody knows exactly who “someone” is.
A better policy names the trigger and the response.
For example:
Changed payment instructions: do not use the new instructions until the change is confirmed with the vendor using the contact already stored in the accounting or vendor record.
Unexpected password or login request: do not use the message link. Open the service through the normal bookmark, app or known website and check the account there.
Sensitive information going somewhere new: verify the recipient and business reason through an established channel before sending it.
Unusual executive or manager request: confirm directly when the request involves money, credentials or confidential information—even when the message appears to come from the correct person.
That is not bureaucracy for its own sake. It gives the employee permission to slow down at exactly the moment a scammer wants speed.
Email authentication protects the business name too
There is another side to the problem: scammers do not only impersonate people to your business. They can impersonate your business to customers and vendors.
The FTC recommends email authentication technologies including SPF, DKIM and DMARC for businesses using their own domain for email. These technologies help receiving mail systems verify whether messages claiming to come from a domain are authorized.
You do not need to turn the staff meeting into a lesson on DNS records.
The useful business question is simpler: who manages our business email, and have the domain’s email-authentication protections been configured correctly?
This is also where yesterday’s ownership question becomes practical. If nobody knows who controls the domain or DNS, even a straightforward email-security improvement can become difficult. The Grassroots article on website ownership and digital access explains why the business should know who controls those underlying accounts without requiring the owner to personally administer them.
MFA matters most where a stolen password can do real damage
A phishing message may be trying to steal money directly. It may also be trying to steal a login.
Multi-factor authentication adds another barrier when a password is compromised. The FTC recommends MFA for sensitive information, and the Cybersecurity and Infrastructure Security Agency advises small and medium businesses to require MFA wherever possible, beginning with administrative accounts and people handling sensitive data.
If the platform offers stronger phishing-resistant methods, use them where the risk justifies it. At minimum, do not leave high-impact business accounts protected only by a reused or easily shared password.
The important accounts are not limited to banking. Business email itself can be a powerful recovery channel. So can domain registration, file storage, accounting, CRM, hosting, payroll and administrative access to other systems.
What if somebody already clicked?
This is where shame becomes expensive.
If an employee thinks they clicked a bad link, entered a password into the wrong page or sent information they should not have sent, the business needs to hear about it quickly.
A reporting process that makes people afraid to admit a mistake encourages delay.
The FTC advises businesses to give employees a way to report suspicious messages and, when credentials may have been compromised, to change compromised passwords promptly and follow the company’s response procedures. NIST likewise recommends teaching employees both how to spot phishing and how to report it when they think they have encountered or fallen for one.
The first question should be, “What happened?” Not, “How could you fall for that?”
You can improve the process after the immediate risk is contained.
Make the verification rule fit the business
A five-person consulting firm and a multi-location service company do not need identical procedures.
That is where generic security checklists often lose small businesses.
A small professional office may be able to confirm an unusual request by walking ten feet and asking. A property-management or HOA service operation may need a documented vendor-contact record because invoices and approvals move among several people. A clinic has additional sensitivity around patient information. A contractor with field staff may need a clear rule for what should never be approved from a text message while somebody is standing on a jobsite.
The control should match the way work actually happens.
Grassroots approaches digital systems the same way. Our Services & Solutions start with the business, the customer and what needs to happen before choosing the technology. Security procedures benefit from the same discipline. A rule people cannot realistically follow during the workday is likely to become a rule people route around.
A useful five-minute exercise
Ask the team to name the three email requests that could cause the most damage if they were fake.
Do not start with every possible cyber threat. Start with your actual business.
Maybe the answers are:
- changing where a vendor gets paid;
- sending a customer or employee file;
- resetting or sharing access to an important account.
For each one, decide how it gets independently verified and where the trusted contact information comes from.
Then write that down in plain English.
That small exercise will not solve cybersecurity. It does something more practical: it removes guesswork from three moments when a convincing message could otherwise turn into a business problem.
Where should a small business start?
Pick one high-consequence request that currently could be approved from an email alone.
Change the process so the request requires a second, trusted verification step.
Then move to the next one.
If your website, email, forms and business systems have grown over time and you are not sure where the weak handoffs or account dependencies are, schedule a Complimentary Discovery Call with Grassroots Consulting. We can start with how the business actually works, identify what matters, and help simplify the digital foundation around it.
Built in collaboration with ChatGPT.