Help people verify a request before they act
A convincing message may appear to come from a colleague, supplier or service your team uses every day. Stratiis helps Scottish businesses prepare staff to question unusual requests, verify them through a trusted route and report concerns quickly. We connect practical guidance with the technical controls and response plan behind it.
What are phishing and impersonation?
Phishing is an attempt to persuade someone to reveal information, approve access, open harmful content or take another unsafe action through a deceptive message or contact. Impersonation makes the request appear to come from a trusted person or organisation. It may arrive by email, text, phone, messaging app or a fake sign-in page. A familiar name or realistic branding is not proof that the request is genuine.
Give people a safe way to pause and check
Good preparation makes verification and early reporting part of ordinary work.
Clearer decisions
Staff know which requests need an independent check.
Faster reporting
Suspicious contact reaches the right team promptly.
Safer payments
Changes to bank details follow an agreed approval route.
Better learning
Reports reveal where guidance or controls need work.
What should a phishing and impersonation plan include?
Start with the requests your team receives and the decisions an attacker could try to influence.
| Area | Question to answer | Useful output |
|---|---|---|
| Exposure | Which teams handle payments, accounts, sensitive records or supplier changes? | Role-based scenarios. |
| Verification | How will staff confirm an unusual request using a known, separate route? | Simple check and approval steps. |
| Accounts | Which services need stronger sign-in and access controls? | Reviewed MFA and permissions. |
| Messages | How are suspicious emails and other contacts filtered or flagged? | Agreed technical controls. |
| Reporting | Where does a concern go, including after someone has clicked or replied? | Easy reporting and triage route. |
| Response | Who assesses account access, exposed information or a payment request? | Named owners and escalation. |
| Learning | How will examples, feedback and incidents improve the plan? | Training and control review. |
The checks should fit your organisation's approval process. They should still work when a request looks urgent or seems to come from a senior person.
Which requests deserve a closer check?
No single clue proves a message is fraudulent. Focus on the action requested and verify important changes independently.
Supplier payment changes
Confirm new bank details through a contact method already held in your records, following the agreed approval process.
Unexpected sign-in pages
Open the service through a trusted bookmark or app instead of using a link in an unexpected message.
MFA approval prompts
Question an approval request you did not initiate and report repeated or unexplained prompts.
Executive requests
Check unusual instructions to send money, files or credentials, even when the name and tone appear familiar.
Shared files and QR codes
Consider whether the file or destination was expected and whether the sender can be verified separately.
Calls, texts and chat
Apply the same verification rules when a caller or message claims to be a colleague, supplier or support desk.
Build a response people can follow under pressure
Use your real workflows to test the steps, including a case where someone has already acted.
Review
Identify exposed roles, common requests, current controls and reporting gaps.
Define
Agree independent checks, approval boundaries and response owners.
Practise
Use realistic examples to rehearse verification and prompt reporting.
Improve
Review reports and incidents, then update guidance and controls.
Awareness Training provides the wider programme for reinforcing safe decisions across your team.
Make verification and escalation clear
People should be able to challenge an unusual request without having to judge it alone.
What Stratiis can help plan
Relevant phishing and impersonation scenarios.
Practical verification and reporting guidance.
Review of supporting email, identity and device controls.
A response route and measures for improvement.
What your team owns
Approval rules for payments, access and information sharing.
Trusted contact details for independent checks.
Business decisions when a request is disputed.
Prompt reporting and cooperation with the response team.
What should staff do next?
A clear route matters more than expecting every person to diagnose the message.
| Situation | Safe next step | Who needs to know? |
|---|---|---|
| Unusual request | Pause and verify through a known number, app or existing contact route. | The request owner or approver. |
| Suspicious link or attachment | Avoid opening it and use the agreed reporting method. | Your security or support contact. |
| Unexpected MFA prompt | Do not approve it; report the prompt and check the account. | Your security or support contact. |
| Already clicked or replied | Report promptly, explain what happened and follow the incident instructions. | Your response team. |
| Payment may have been made | Escalate immediately and contact the bank through its official channel. | The payment owner, response team and bank. |
Staff should know that early reporting is welcome, including when they are unsure or have made a mistake. Your response team can assess the message, account and business impact.
Pair people’s decisions with protective controls
Technical and process controls reduce the chance that one deceptive request causes harm.
Email protection
Filter and investigate suspicious messages and review email security settings.
Account protection
Use MFA, sensible access and prompt review of unexpected activity.
Payment checks
Require independent verification for changes to bank details and unusual transfers.
Response readiness
Give reports a named owner and a way to contain a suspected compromise.
Monitoring and Response covers the wider investigation and escalation process.
Connect phishing preparation to wider security work
Use the right mix of guidance, controls and support for the risks your business faces.
Phishing and impersonation FAQs
Clear answers to the questions staff and business leaders often ask.
What is the difference between phishing and impersonation?
Phishing is a deceptive attempt to make someone take an unsafe action. Impersonation is a method used to make the request appear to come from a trusted person or organisation. The two often overlap.
How can staff check a suspicious request?
Use a contact number, app or address already trusted by the business. Do not rely on the details supplied in the message being checked, especially for payments, access or sensitive data.
Can a message from a familiar account still be unsafe?
Yes. An account can be compromised, and names or branding can be copied. Judge the requested action and confirm unusual instructions through a separate route.
What should someone do after clicking a phishing link?
Report it immediately through the organisation's agreed route, say what was opened or entered, and follow the response team's instructions. Early reporting helps the team assess any account or device risk.
What if a payment has already been sent?
Escalate immediately to the payment owner and response team, and contact the bank using its official details. Speed matters when a transfer may have been redirected.
Does MFA stop phishing?
MFA adds protection, but it does not remove every risk. Users still need to question unexpected approval prompts and report them promptly.
Should staff report a message when they are unsure?
Yes. A simple reporting route lets the right team assess it. Staff should not feel they must prove a message is malicious before reporting it.
How should businesses measure improvement?
Review reporting behaviour, response time, recurring scenarios, near misses and whether staff follow independent verification steps. Use findings to improve both guidance and controls.
Make suspicious requests easier to recognise and report
Tell us where an impersonated request could affect your business. We can help plan practical checks, staff guidance and the supporting response.


