The Dispatch

Email Security for Small Businesses: The Top 5 Threats You Missed

Written by John Ohlwiler | 8/13/26, 5:15 PM

Your inbox is the most attacked surface in your business. Not your firewall. Not your servers. Your email.

Phishing and spoofing alone generated 191,561 complaints to the FBI in 2025 -- the single highest complaint category of any cybercrime that year.1

For small businesses, the stakes are personal. The average phishing breach costs an SMB $200,0002 -- enough to permanently alter the trajectory of a growing company. And unlike enterprise organizations with full security teams, most small businesses are running on default settings and good intentions.

Here are the five email threats most likely to hit you, and what to do about each one.

1. Phishing: The Threat Your Team Is Most Likely to Click

Phishing is the starting point for most cyberattacks on small businesses. An attacker sends a convincing email -- impersonating a vendor, your bank, Microsoft, or even a colleague -- designed to get someone to click a link or hand over credentials.

Three things have made this worse in recent years. First, AI has eliminated the grammar errors and awkward phrasing that used to make phishing easy to spot. An estimated 85.8% of phishing attacks are now AI-assisted, producing emails that read exactly like the real thing.3

Second, the speed at which people click. The median time between receiving a phishing email and clicking a link is under 60 seconds.4

Third, the scope. Small businesses with 1 to 249 employees have a baseline phishing click rate of 24.6% before any security training.4 That means roughly one in four of your employees will click on a convincing phishing test right now.

The fix is layered: email filtering that flags suspicious senders, phishing simulation training (employees with regular simulation training are 7x less likely to take the bait4), and a culture where people feel comfortable flagging suspicious messages before clicking.

2. Business Email Compromise: The Scam That Doesn't Need Malware

Business Email Compromise is the most financially devastating email threat businesses face. In 2025, BEC generated $3.04 billion in verified losses across 24,768 FBI complaints.5

What makes BEC different from phishing is that it often involves no malware at all. An attacker -- sometimes after monitoring your email for weeks -- impersonates an executive, a vendor, or a trusted partner and convinces someone to wire money, change payment account details, or share sensitive data.

86% of BEC losses move through wire transfer or ACH, making them fast and often unrecoverable.5 By the time the fraud is detected, the money is already gone.

Small businesses are prime targets because decision-making chains are shorter. The person who receives the fake "CEO email" is often the same person who processes the payment.

Defending against BEC requires process controls as much as technology: verbal verification for any payment change request, dual approval on wire transfers, and clear internal policies about how financial instructions can and cannot be communicated.

3. Email Spoofing: When Your Domain Becomes the Weapon

Email spoofing is when an attacker sends emails that appear to come from your domain -- your company address -- to trick your customers, vendors, or partners into taking action.

This is largely a configuration problem, and it is shockingly common. 68% of small and medium-sized businesses lack DMARC policies6 -- a foundational email authentication standard that tells receiving mail servers what to do with emails that fail to verify as legitimate.

Even among organizations with DMARC deployed, only 18.4% use a "reject" policy.6 The rest are monitoring the problem without stopping it.

DMARC works alongside two other technical standards: SPF (Sender Policy Framework), which specifies which mail servers can send on behalf of your domain, and DKIM (DomainKeys Identified Mail), which adds a cryptographic signature to verify message integrity. All three should be configured and checked regularly.

This is one of the few email security items that does not require ongoing behavioral change from your team. It is a technical fix -- configure it once, monitor it, and your domain becomes significantly harder to weaponize.

4. Malicious Links: Why "Don't Open Attachments" Is Not Enough Anymore

The classic email safety advice -- do not open attachments from unknown senders -- is no longer sufficient. Attackers have shifted their delivery method.

According to Proofpoint, malicious URLs are now used four times more often than attachments to deliver malware.7 And the links themselves have gotten harder to identify: shortened URLs, links embedded in QR codes, and redirect chains that pass through legitimate services before landing on malicious pages.

QR code phishing alone produced more than 4.2 million threats in just the first half of 2025 -- and most email security filters were not built to scan a QR code embedded in an image.7

The implication for your team: the "look before you click" advice now requires actually hovering over links, scrutinizing sender addresses, and treating any email that creates urgency around clicking a link as suspect -- regardless of who it appears to come from.

Advanced email security tools that sandbox links before they load, and that inspect URLs in real time rather than at delivery, are increasingly essential rather than optional.

5. Account Takeover: What Happens After You Click

Account takeover (ATO) is what follows a successful phishing attack. An attacker obtains valid credentials and logs into a legitimate email account -- usually quietly, without triggering any alerts.

Account compromise surged 389% year over year in 2025, making up 55% of all attacks observed in one major security study.8 Once inside, attackers can monitor communications, intercept payment threads, set up forwarding rules to receive copies of future emails, and launch BEC attacks from a trusted address -- all without your team knowing.

The insidious part is dwell time. Attackers often sit inside compromised accounts for weeks before doing anything visible, studying your patterns and waiting for the right moment.

Multi-factor authentication (MFA) is the single most effective control against account takeover. If an attacker has your password but cannot pass the second factor, they are locked out. Despite this, MFA adoption at small businesses significantly lags behind enterprise organizations.8

Beyond MFA: regularly audit mailbox rules for unexpected forwarding, review sign-in logs for logins from unfamiliar locations, and train your team to report anything that feels off -- even if they cannot articulate exactly why.

The Short List: What to Do This Quarter

You do not need to solve everything at once. Start with the controls that close the most risk with the least friction:

  • Enable MFA on every email account, starting with anyone who handles financial transactions or has admin access.

  • Check your DMARC, SPF, and DKIM configuration. If you do not know whether these are deployed, that is your answer.

  • Implement a verbal verification policy for any request to change payment details or wire funds, regardless of who the email appears to be from.

  • Run a phishing simulation. You cannot train against a threat your team does not recognize.

  • Review active inbox rules and sign-in logs for signs of unauthorized access.

Email security is not a product you install once. It is a posture you build over time -- the kind of work Sentry guides clients through as part of the Secure stage of our Technology Maturity Model.

If you are not sure where your business stands, start with an honest assessment of these five areas. The gaps are usually easier to find than you expect -- and significantly harder to ignore once you do.

Ready to take a closer look at your email security posture? Talk to the Sentry team.

Frequently Asked Questions

What is the most common email security threat for small businesses?

Phishing is the most common, but business email compromise is the most financially damaging. Many attacks combine both: a phishing email is the first step, credential theft is the second, and BEC fraud or account takeover follows. Addressing phishing with training and email filtering reduces exposure across multiple threat types simultaneously.

Do I need DMARC if I already have an email security tool?

Yes. Email security tools and DMARC solve different problems. An email security tool filters inbound messages to protect your team. DMARC protects your domain reputation by preventing attackers from sending emails that appear to come from your address. Without DMARC, attackers can spoof your domain to target your customers and partners -- and your email security tool cannot stop that.

How do I know if my email account has been compromised?

Common signs include emails sent that you did not write, unexpected password reset messages, unfamiliar inbox rules or forwarding addresses, and login alerts from unusual locations or devices. If you use Microsoft 365 or Google Workspace, both platforms offer sign-in activity logs in their admin consoles. Review them regularly and investigate anything unfamiliar.

Is multi-factor authentication enough to stop account takeover?

MFA is highly effective, but not foolproof. Attackers have developed MFA fatigue attacks (a flood of push notifications hoping you approve one by accident) and adversary-in-the-middle phishing kits that can intercept MFA tokens in real time. Phishing-resistant MFA methods like hardware security keys (FIDO2) or Microsoft's Authenticator with number matching offer stronger protection than standard push notifications.

What is the difference between phishing and business email compromise?

Phishing is a broad attack type -- an email designed to trick you into clicking a link or entering credentials. BEC is a specific, targeted fraud that impersonates a trusted person (usually an executive or vendor) to manipulate financial processes. Phishing often involves malware or credential harvesting at scale. BEC is usually surgical, low-volume, and focused on a single financial transaction. Both can result in significant losses; BEC typically results in larger individual losses.

References

1. FBI Internet Crime Complaint Center (IC3), 2025 Internet Crime Report. ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf

2. StationX, "Small Business Cybersecurity Statistics and Trends [2026]." app.stationx.net/articles/small-business-cybersecurity-statistics

3. Adaptive Security, "Email Security Statistics 2026: Phishing, BEC & AI." adaptivesecurity.com/blog/email-security-statistics-2026

4. Medha Cloud, "52 Email Security Statistics for 2026 -- BEC, Spam & Phishing." medhacloud.com/blog/email-security-statistics-2026

5. Rexxfield, "BEC Statistics 2025: $3B Losses in the FBI IC3 Report." rexxfield.com/bec-by-the-numbers-2025-ic3-report

6. Medha Cloud, "52 Email Security Statistics for 2026." medhacloud.com/blog/email-security-statistics-2026 (DMARC adoption data)

7. Proofpoint, "The Human Factor 2025 - Vol. 2: Phishing and URL-Based Threats." proofpoint.com/au/resources/threat-reports/human-factor-url-phishing

8. eSentire / Infosecurity Magazine, "Account Compromise Surged 389% in 2025." infosecurity-magazine.com/news/account-compromise-surged-2025