Phishing isn't a hacking problem; it's a habits problem. Attackers don't break in, they log in, using a password someone typed into a fake page or a payment someone approved without checking. Which is good news, in a way: you can audit your exposure with five questions and a stopwatch. Otters check their riverbank daily. Here's your version.
1. Is MFA on for the accounts that matter? (1 minute)
Open your Microsoft 365 admin centre (or ask whoever runs it) and confirm multi-factor authentication is enforced for every account, starting with admins and anyone in finance. A password alone is not a lock; it's a doormat. If even one admin account has no MFA, stop reading and fix that first.
2. Could you spot your own lookalike domain? (1 minute)
Write your email domain on a piece of paper, then write it with one letter swapped, doubled or dropped. That's what attackers register before impersonating your boss. Now check yesterday's inbox: would anyone in your team have caught it at 4:55pm on a Friday? Be honest.
3. What happens when someone reports a suspicious email? (1 minute)
Ask the person nearest you: "If you got a dodgy email right now, what would you do with it?" If the answer is "delete it" or "not sure", you have no early-warning system, because the same email probably landed in ten other inboxes. There should be one obvious place to report it, and someone who actually looks.
4. How do you verify changed bank details? (1 minute)
Invoice fraud is the most expensive email attack in Australia, and it works by emailing your accounts team "new bank details" from a compromised or lookalike supplier account. The fix costs nothing: any change of payment details gets verified by phone, on a number you already had, before a cent moves. Confirm that rule exists and is actually followed.
5. Does your mailbox have a real backup? (1 minute)
Microsoft keeps your email running; it does not keep an independent backup of it for you. Deleted mailbox, ransomware in OneDrive, or a malicious insider, and retention policies alone may not save you. Ask one question: "If our email vanished today, where's the copy?" If nobody can point at a specific answer, that's your gap.
How did you score?
Five confident yeses: genuinely well done, you're ahead of most 20 to 200 person businesses we meet. Re-run this check each quarter, because staff change and attackers don't rest.
Three or four: normal, and fixable in a week. Do MFA first, the bank-details rule second. Both cost nothing but attention.
Two or fewer: you're relying on luck, and luck is not a security control. This is exactly the situation our minimum standard exists for: every Otterly customer gets advanced anti-phishing screening and independent mailbox backup automatically, with no way to opt out, plus 24/7 EDR watching every device for the day something slips through.
The human layer
Technology catches most phishing; your people catch the rest, but only if they've practised. Our optional cyber security training add-on ($8/user/mo) runs ongoing simulated phishing and bite-size training, so the first convincing fake your team sees is one we sent, not one that costs you money.
Want a second pair of eyes on any of the five? That's a ten-minute chat, not a sales pitch: give us a squeak.