Phishing emails are responsible for the majority of business cyber incidents in New Zealand. CERT NZ consistently reports phishing as the top initial access vector across all sectors. The goal of a phishing email is simple: get someone to click a link, open an attachment, or hand over credentials. The consequences range from account compromise to full ransomware deployment.
The good news is that phishing is preventable. Not perfectly — no control is — but the combination of technical controls and staff awareness can stop the vast majority of phishing attempts before they cause harm.
Here are 10 practical steps any NZ business can take.
1. Enable Multi-Factor Authentication on All Business Accounts
MFA is the single most effective control against phishing. Even if an employee clicks a phishing link and enters their password on a fake login page, the attacker cannot access the account without the second factor. CERT NZ estimates MFA prevents over 99 percent of automated account takeover attacks.
Enable MFA on: Microsoft 365, Google Workspace, your banking platforms, payroll systems, accounting software, and any cloud service accessible from outside the office. Use authenticator apps (Google Authenticator, Microsoft Authenticator) rather than SMS where possible — SMS MFA is better than nothing but is vulnerable to SIM-swap attacks.
2. Configure Email Authentication Records
Three DNS records work together to prevent attackers from sending emails that appear to come from your domain:
- SPF (Sender Policy Framework) — specifies which mail servers are authorised to send email from your domain
- DKIM (DomainKeys Identified Mail) — adds a cryptographic signature to outgoing emails so recipients can verify they were not tampered with
- DMARC (Domain-based Message Authentication, Reporting and Conformance) — tells receiving mail servers what to do with emails that fail SPF and DKIM checks
Without these records, anyone can send email that appears to come from your domain. With them configured correctly and DMARC set to "reject", spoofed emails from your domain are blocked before they reach the recipient.
3. Use a Business Email Filtering Service
Consumer email services include basic spam filtering. Business email filtering services — Microsoft Defender for Office 365, Google Workspace's built-in filtering, Proofpoint, Mimecast — go further, scanning attachments for malware, checking links against threat intelligence databases, and using AI to detect phishing patterns that bypass simple keyword filtering.
For NZ SMEs using Microsoft 365 Business Premium, Microsoft Defender for Office 365 Plan 1 is included and should be configured with Safe Links and Safe Attachments policies enabled.
4. Block Automatic Execution of Macro-Enabled Office Files
Office documents with macros (.xlsm, .docm) are a common malware delivery mechanism. A phishing email attaches a macro-enabled spreadsheet, the employee opens it, enables macros when prompted, and malware executes. Microsoft 365 now blocks macros from internet-downloaded files by default in recent versions — verify this setting has not been overridden in your environment.
If your business does not legitimately use macro-enabled Office files, block them at the email gateway entirely.
5. Train Staff to Recognise Phishing
Technical controls stop a large proportion of phishing. They do not stop all of it — particularly targeted spear-phishing designed to bypass automated filters. Staff awareness is the last line of defence.
Effective phishing training covers: how to inspect the actual sender email address (not just the display name), how to hover over links to see the destination URL before clicking, what to do when an email creates urgency or pressure around financial transactions, and how to report suspicious emails internally.
Training that uses realistic simulated phishing — sending staff test phishing emails to measure and improve click rates — is significantly more effective than presentation-based training alone. See our post on phishing training for employees for what good phishing training looks like.
6. Implement a Clear Reporting Process
Staff who suspect a phishing email need to know what to do with it. If there is no clear, simple reporting process, they will do nothing, delete it, or worse — click it to confirm their suspicion. A reporting process should be: one action (forward to a specific address, click a report button in Outlook, message the IT contact) and fast enough that staff actually use it.
Microsoft 365 and Google Workspace both support report phishing buttons that submit the email for analysis. Enable them and tell staff how to use them.
7. Separate Financial Authorisation From Email
Business email compromise (BEC) attacks target finance staff with phishing emails impersonating executives or suppliers requesting urgent payment changes. The defence is a process control rather than a technical one: any payment instruction received by email should require verbal confirmation through a separately established phone number before execution.
This one process change prevents the most damaging category of phishing attack — fraudulent payment redirection — regardless of how convincing the email is.
8. Keep Software Patched and Updated
Phishing emails that deliver malware through document attachments or malicious links depend on exploiting vulnerabilities in the software that opens them. Browsers, Office applications, PDF readers, and operating systems that are fully patched close the majority of these attack vectors. Enable automatic updates for all endpoint software and track compliance.
9. Restrict What Staff Can Install
Staff who can install any software on their work devices can inadvertently install malware distributed through phishing. Application control — allowing only approved software to run — is the strongest version of this control. At minimum, ensure standard user accounts do not have local administrator rights, which limits the impact of any malware that does execute.
10. Review and Test Regularly
Phishing threats evolve. A training programme delivered once and a technical configuration set up two years ago degrade against current attack techniques. Schedule: quarterly phishing simulations to measure staff awareness, annual review of email filtering configurations, and a review of MFA coverage whenever new systems are adopted.
CERT NZ's annual reports provide a useful benchmark for current threat patterns and what NZ businesses are being targeted with.
Run phishing simulations and security awareness training for your staff with SecureAZ