Phishing and impersonation protection in Scotland

Help people verify a request before they act

A convincing message may appear to come from a colleague, supplier or service your team uses every day. Stratiis helps Scottish businesses prepare staff to question unusual requests, verify them through a trusted route and report concerns quickly. We connect practical guidance with the technical controls and response plan behind it.

What are phishing and impersonation?

Phishing is an attempt to persuade someone to reveal information, approve access, open harmful content or take another unsafe action through a deceptive message or contact. Impersonation makes the request appear to come from a trusted person or organisation. It may arrive by email, text, phone, messaging app or a fake sign-in page. A familiar name or realistic branding is not proof that the request is genuine.

Why it matters

Give people a safe way to pause and check

Good preparation makes verification and early reporting part of ordinary work.

Clearer decisions

Staff know which requests need an independent check.

Faster reporting

Suspicious contact reaches the right team promptly.

Safer payments

Changes to bank details follow an agreed approval route.

Better learning

Reports reveal where guidance or controls need work.

Protection plan

What should a phishing and impersonation plan include?

Start with the requests your team receives and the decisions an attacker could try to influence.

Area Question to answer Useful output
Exposure Which teams handle payments, accounts, sensitive records or supplier changes? Role-based scenarios.
Verification How will staff confirm an unusual request using a known, separate route? Simple check and approval steps.
Accounts Which services need stronger sign-in and access controls? Reviewed MFA and permissions.
Messages How are suspicious emails and other contacts filtered or flagged? Agreed technical controls.
Reporting Where does a concern go, including after someone has clicked or replied? Easy reporting and triage route.
Response Who assesses account access, exposed information or a payment request? Named owners and escalation.
Learning How will examples, feedback and incidents improve the plan? Training and control review.

The checks should fit your organisation's approval process. They should still work when a request looks urgent or seems to come from a senior person.

Practical starting points

Which requests deserve a closer check?

No single clue proves a message is fraudulent. Focus on the action requested and verify important changes independently.

Supplier payment changes

Confirm new bank details through a contact method already held in your records, following the agreed approval process.

Unexpected sign-in pages

Open the service through a trusted bookmark or app instead of using a link in an unexpected message.

MFA approval prompts

Question an approval request you did not initiate and report repeated or unexplained prompts.

Executive requests

Check unusual instructions to send money, files or credentials, even when the name and tone appear familiar.

Shared files and QR codes

Consider whether the file or destination was expected and whether the sender can be verified separately.

Calls, texts and chat

Apply the same verification rules when a caller or message claims to be a colleague, supplier or support desk.

How support starts

Build a response people can follow under pressure

Use your real workflows to test the steps, including a case where someone has already acted.

1

Review

Identify exposed roles, common requests, current controls and reporting gaps.

2

Define

Agree independent checks, approval boundaries and response owners.

3

Practise

Use realistic examples to rehearse verification and prompt reporting.

4

Improve

Review reports and incidents, then update guidance and controls.

Awareness Training provides the wider programme for reinforcing safe decisions across your team.

People and safeguards

Make verification and escalation clear

People should be able to challenge an unusual request without having to judge it alone.

What Stratiis can help plan

Relevant phishing and impersonation scenarios.

Practical verification and reporting guidance.

Review of supporting email, identity and device controls.

A response route and measures for improvement.

What your team owns

Approval rules for payments, access and information sharing.

Trusted contact details for independent checks.

Business decisions when a request is disputed.

Prompt reporting and cooperation with the response team.

When a message is suspicious

What should staff do next?

A clear route matters more than expecting every person to diagnose the message.

Situation Safe next step Who needs to know?
Unusual request Pause and verify through a known number, app or existing contact route. The request owner or approver.
Suspicious link or attachment Avoid opening it and use the agreed reporting method. Your security or support contact.
Unexpected MFA prompt Do not approve it; report the prompt and check the account. Your security or support contact.
Already clicked or replied Report promptly, explain what happened and follow the incident instructions. Your response team.
Payment may have been made Escalate immediately and contact the bank through its official channel. The payment owner, response team and bank.

Staff should know that early reporting is welcome, including when they are unsure or have made a mistake. Your response team can assess the message, account and business impact.

Beyond training

Pair people’s decisions with protective controls

Technical and process controls reduce the chance that one deceptive request causes harm.

Email protection

Filter and investigate suspicious messages and review email security settings.

Account protection

Use MFA, sensible access and prompt review of unexpected activity.

Payment checks

Require independent verification for changes to bank details and unusual transfers.

Response readiness

Give reports a named owner and a way to contain a suspected compromise.

Monitoring and Response covers the wider investigation and escalation process.

Related Stratiis services

Connect phishing preparation to wider security work

Use the right mix of guidance, controls and support for the risks your business faces.

Common questions

Phishing and impersonation FAQs

Clear answers to the questions staff and business leaders often ask.

What is the difference between phishing and impersonation?

Phishing is a deceptive attempt to make someone take an unsafe action. Impersonation is a method used to make the request appear to come from a trusted person or organisation. The two often overlap.

How can staff check a suspicious request?

Use a contact number, app or address already trusted by the business. Do not rely on the details supplied in the message being checked, especially for payments, access or sensitive data.

Can a message from a familiar account still be unsafe?

Yes. An account can be compromised, and names or branding can be copied. Judge the requested action and confirm unusual instructions through a separate route.

What should someone do after clicking a phishing link?

Report it immediately through the organisation's agreed route, say what was opened or entered, and follow the response team's instructions. Early reporting helps the team assess any account or device risk.

What if a payment has already been sent?

Escalate immediately to the payment owner and response team, and contact the bank using its official details. Speed matters when a transfer may have been redirected.

Does MFA stop phishing?

MFA adds protection, but it does not remove every risk. Users still need to question unexpected approval prompts and report them promptly.

Should staff report a message when they are unsure?

Yes. A simple reporting route lets the right team assess it. Staff should not feel they must prove a message is malicious before reporting it.

How should businesses measure improvement?

Review reporting behaviour, response time, recurring scenarios, near misses and whether staff follow independent verification steps. Use findings to improve both guidance and controls.

Talk to Stratiis

Make suspicious requests easier to recognise and report

Tell us where an impersonated request could affect your business. We can help plan practical checks, staff guidance and the supporting response.

Contact Stratiis →