
Article Summary: Employees should use standard accounts for email, web browsing and everyday work. Administrator access should be limited to approved IT tasks and protected with a separate account.
Administrator access often starts with one request. An employee needs to install a printer, update a specialist program or change a setting on their computer.
Giving them administrator access gets the job done. The problem is that the access usually stays after the request has been completed.
From then on, the employee can approve other software installations and make changes that would normally require help from IT. If they install the wrong program or someone takes control of their account, those permissions can also be used to change the computer.
For everyday work, employees should use standard accounts. Administrator access should be kept for tasks that require it.
What Administrator Access Allows Someone to Do
An administrator has more control over a computer than a standard user.
On Windows, members of the local Administrators group have full control over the resources on that computer. According to Microsoft’s guidance on local accounts, Microsoft recommends limiting the number of users in that group.
Depending on the computer and how it is managed, an administrator may be able to:
- Install and remove software
- Add drivers for printers and other equipment
- Create, change or remove user accounts
- Change system settings
- Change permissions on files and folders
- Install services that continue running in the background
- Make changes to some security settings
Mac computers also have standard and administrator accounts. Apple says administrators can install and remove software, manage other users and change settings. Apple recommends limiting the number of administrative users and using a standard account when administrator rights are not required.
Local administrator access applies to the computer itself. It is different from Microsoft 365, Google Workspace, network or server administrator access. Those accounts may control email, cloud files, user accounts or several systems at once.
An employee may have local administrator access to a laptop without being a Microsoft 365 administrator. Both types of access should be reviewed separately.
Why Permanent Administrator Access Increases Your Risk
Software launched by an employee normally starts with the permissions available to that employee.
If the software asks for administrator approval and the employee approves it, the program may be able to install system components, change settings or affect information belonging to other users.
That matters when someone downloads a fake installer, opens a harmful attachment or installs software from an untrusted website. The employee may think they are approving a legitimate update while giving the program permission to change the computer.
Windows uses User Account Control to ask for approval before many administrative changes. An employee signed in with an administrator account can approve the request themselves. A standard user is normally asked for credentials belonging to an administrator.
Microsoft describes the standard account as the recommended and more secure way to use Windows.
Standard accounts also reduce the number of people who can change security settings without review. Employees cannot approve every installation themselves so IT has a chance to check the program, where it came from and what permissions it needs.
CISA advises businesses to control local administrator access and restrict who can install software. The Australian Cyber Security Centre includes restricting administrative privileges in its Essential Eight security measures and recommends creating separate accounts for administrative work.
Standard Accounts are Suitable for Everyday Work
A standard account can still be used for normal business tasks including:
- Reading and sending email
- Using a web browser
- Working in Microsoft 365 or Google Workspace
- Accessing approved business applications
- Joining online meetings
- Printing with an installed printer
- Opening and saving files
- Changing personal settings that do not affect other users
Some applications can be installed for one user without administrator access. Others need administrator approval because they add drivers, services or files in protected parts of the computer.
An employee should not receive permanent administrator access because one program needs an update. IT can approve the installation, deploy the update remotely or use a separate administrator account for that task.
Older business applications sometimes expect the user to have administrator rights. Test those applications before changing account permissions. In many cases, IT can update the application, adjust its configuration or grant access to the specific folders it needs.
How to Manage Software Installations Without Permanent Administrator Access
Staff can still get software installed and updated without keeping administrator rights.
Let IT install Approved Software
Your IT team or provider can install the program remotely. This also gives them a chance to confirm that the installer came from the software company and that the requested version is supported.
Use Managed Software Deployment
Businesses with managed computers can send approved applications and updates to employees without asking each person to run an installer. The available method will depend on the operating system and device management service.
Approve Individual Requests
An employee can contact IT when an installation requires administrator approval. IT can review the request and enter the required credentials without giving the password to the employee.
Provide Time-Limited Administrator Access
Some roles need to install or test software as part of their work. Give those employees a separate administrator account that is enabled only for the approved task and then disable it afterward.
Create a Separate Administrator Account
Employees who regularly perform approved technical work can have a separate administrator account. They should continue using their standard account for email, browsing and normal work.
The administrator account should only be used when a task requires the extra permissions.
Who Should Have Administrator Access?
Administrator access should be limited to people with work that requires it.
That may include:
- Your internal IT staff
- Your IT provider
- An approved technical employee
- A software specialist responsible for a particular system
Business owners should use standard accounts for their normal work too. Ownership of the company does not require permanent administrator access to every computer.
Your IT provider should keep a managed administrator account so they can support each device. The password should be protected and should not be shared with employees.
Using the same local administrator password on every computer creates another problem. If that password is stolen from one device, it may work on the others. Each computer should have a unique administrator password or use a management service that controls those passwords.
How to Remove Administrator Access Safely
Do not remove every administrator account at once. Someone still needs a working way to manage and repair each computer.
1. Check which employees have administrator access.
Review the local Administrators group on every Windows computer and the administrator users on every Mac. Include old accounts, shared accounts, vendor accounts and accounts created during the original setup.
2. Confirm why each person has it.
Ask what tasks require administrator access. A clear business need should exist for every account that keeps the permission.
Needing to update one application occasionally does not require permanent access.
3. Make sure IT has a working administrator account.
Confirm that your IT team or provider can sign in with a protected administrator account before removing permissions from employees.
Test the account on each device. This prevents the business from being locked out of its own computers.
4. Test important software.
Check the programs each employee needs for their job. Confirm that they open, update and work correctly when the employee uses a standard account.
Any application that fails should be reviewed before administrator access is removed permanently.
5. Change the employee’s account to a standard account.
Once the computer has been checked, remove the employee from the local administrator group or change the account type.
The employee should then sign out and sign back in so the new permissions apply correctly.
6. Tell staff how to request an installation.
Give employees one place to contact when they need software installed or a setting changed. Explain what information to include such as the program name, the reason it is needed and the official download page.
7. Review access when roles change.
Check administrator access when an employee changes jobs, receives new responsibilities or leaves the business. Include it in your regular access reviews as well.
Frequently Asked Questions
Can a standard user install software?
It depends on the software. Programs that only install inside the employee’s user profile may not need administrator approval. Software that changes protected system files, installs drivers or adds background services usually requires administrator credentials.
Will removing administrator access stop employees from working?
Normal business applications should continue working. Test specialist and older applications before making the change across every computer.
Does removing administrator access stop malware?
It reduces what many harmful programs can change but it does not prevent every attack. You still need supported software, security updates, endpoint protection, email security, MFA and tested backups.
Should the business owner keep administrator access?
Use a standard account for everyday work. If you need administrator access for an approved task, use a separate account and keep its password protected.
Is local administrator access the same as Microsoft 365 administrator access?
No. Local administrator access controls one computer. Microsoft 365 administrator roles can control cloud users, email, files, security settings and other parts of the company’s Microsoft environment.
Both should be limited and reviewed.
Sources and Further Reading
- Microsoft Learn: Local accounts
- Microsoft Learn: How User Account Control works
- Apple Support: Set up your Mac to be secure
- CISA: StopRansomware Guide
- Australian Cyber Security Centre: Restricting administrative privileges
If you are not sure who has administrator access or whether your employees need it, ask your IT provider to review the accounts on your business computers.
If you don’t have an IT provider, feel free to reach out to us and we will help you sort it out.

Article Summary: The tools that run your business like Microsoft 365, your accounting app or your booking system are reliable most of the time but they do go down. When one does, work can stop for hours and you often can't do anything but wait for the provider to fix it. A simple plan keeps your team working and your customers informed while you wait.
Most of your business probably runs in the cloud now. Email, files, accounting, bookings and payments are all online. Then one day a service goes down and nobody can send an email, open a file or take a payment.
It doesn't take a hacker for this to happen. In July 2024, a faulty software update from the security company CrowdStrike crashed millions of Windows computers around the world in a few hours. Microsoft estimated it hit 8.5 million devices which grounded flights and stopped work at banks and hospitals.
Outages Happen Even to the Big Names
Microsoft 365 itself has had days where email or Teams stopped working for hours. Internet providers have bad days too and when yours does, everything online goes with it. Any tool you depend on can go down.
So much of a small business runs on a handful of online services now and if one goes down, the work that depends on it stops until it is back. Being with a big well-known provider doesn't protect you from this.
What an Outage Does to a Small Business
When a key service goes down, your team can't get to email or files so work stops. If your payment or booking system is offline, you can't take money or appointments. Customers try to reach you and can't and you can't reach them either. Staff end up sitting around waiting.
You usually can't fix it yourself. When a big provider has an outage, all you can do is wait for them to sort it out. The goal of a plan is to keep working and keep customers informed until they do.
What a Simple Plan Covers
A good plan answers these questions:
- Which tools are critical? List the handful of services that would stop the business if they are down like email, your payment system or your booking tool. Ignore the ones you could live without for a day and focus on the few that would halt the work.
- How will people keep in touch? Have a backup way to reach staff and customers that doesn't depend on the tool that is down. That might be phone numbers, a group chat on a different app or text messages.
- What do you need reachable offline? Keep a copy of the essentials like your customer contact list, key phone numbers and important documents somewhere you can open if the main system is down. A printout or a copy on a phone is enough.
- Who is in charge? Decide who makes the decisions during an outage and who keeps customers updated. When it is clear in advance, people act instead of waiting to be told.
- Where do you check and who do you call? Know where to see whether it is a wider outage (which is usually the provider's status page) and who to call for help (which is usually your IT provider).
What to Do the Moment an Outage Hits
- Check whether it is just you. Look at the provider's status page or ask whether anyone else is having the same problem. If it is a wider outage, there is nothing to fix on your end so stop trying.
- Tell your team. Let people know what is down and what to use instead so nobody wastes an hour rebooting a laptop that was never the problem.
- Switch to your backup way to communicate. Move to the phone, text or another app so the team can still coordinate.
- Tell customers if it affects them. If you can't take bookings or payments, say so and tell them when to try again.
- Note when it started and what is affected. A couple of lines is enough. It helps you follow up afterward and spot anything that needs fixing once things are back.
A Few Things That Make Outages Hurt Less
- Keep key files available offline. With OneDrive or SharePoint, recent files can sync to the device so you can still open them when the service is down. Ask your IT provider to make sure this is set up.
- Have a backup way to get online. A mobile hotspot from a phone can get a few key people working again if your main internet drops.
- Know your status pages. Bookmark the status page for Microsoft 365 and your other main tools. It is the fastest way to tell whether the problem is them or you.
- Keep contacts off the cloud. Have your important phone numbers and contacts somewhere that doesn't need the internet like a printout or your phone's own contact list.
- Ask your IT provider about alerts. Many can set up a warning that tells you about an outage before your customers do.
Keep Your Plan on One Page
Keep this to a single page somewhere you can reach without your main systems whether that is printed or in a separate app. Write down your critical tools, your backup way to communicate, where the essentials live, who is in charge and who to call. Review it once or twice a year so the names and numbers stay current.
Frequently Asked Questions
Isn't the cloud always available?
No. Cloud services are reliable but they still have outages and even the biggest providers go down sometimes. The CrowdStrike outage in 2024 took millions of computers offline in a few hours. It is safer to assume an outage will happen eventually and have a plan for it.
What should a continuity plan include?
It should include the basics such as which tools are critical, a backup way to reach staff and customers, where to find essential information if the main system is down, who is in charge during an outage and who to call for help. One page is enough for most small businesses.
What if the internet itself goes down instead of just one app?
Plan for that too. A mobile hotspot from a phone can get key people back online and a phone call still works when your systems don't. Keep important numbers and contacts somewhere that doesn't need the internet.
How can my team keep working if Microsoft 365 is down?
It depends on the work but options include using files already saved on a synced device, switching to phone or text to stay in touch and handling anything urgent on paper until service returns.
How long do outages usually last?
There is no set answer. Some are fixed in minutes and others take most of a day. That is the reason to plan around them since you can't count on a quick fix and you can't speed it up from your end.
Whose job is this?
Yours with help from your IT provider. They can tell you which of your tools are most at risk, set up things like synced files and a status-page alert and help you write a simple plan.

Article summary: Shared mailboxes can become a security risk when they lack a clear owner, strong authentication, and regular access reviews. Blocking direct sign-in and giving authorized users delegated access through their own accounts reduces the risk of password spraying and account takeover. Regular permission reviews keep shared mailboxes useful without leaving unnecessary access open.Read more

Article summary: Attackers who compromise a business email account can create malicious email forwarding rules that secretly hide, delete or redirect important messages. These rules can expose invoices, wire instructions and password reset emails even after the original account compromise is discovered. Regular mailbox rule reviews and tighter forwarding controls can uncover this hidden access before it leads to data theft or financial fraud.Read more

Article summary: Guest Wi-Fi and smart devices can create a security risk when they share the same network as computers handling sensitive business data. Guest Wi-Fi network security separates visitors and connected devices from systems that access payroll, client records and financial information. This limits how far a compromised device can reach and closes an often overlooked gap in small business security.Read more

Article summary: Canceling a cloud service or marketing tool can leave behind a dangling DNS record that still points to the old provider. Attackers can exploit these records to host scam pages, malware or other content under a legitimate business domain. Subdomain takeover prevention removes these forgotten connections before they can become a security risk.Read more

Article Summary: Most small business websites run on WordPress and the biggest risk is usually old plugins that nobody has updated. Attackers scan the web for these known weak spots and use the sites they find to spread malware, post spam or steal what visitors type into forms. Keeping the site and its plugins updated and knowing who is responsible for that prevents most of it.
Your website is one of those things you set up once and then stop thinking about. It sits there doing its job so there is no reason to touch it. That is exactly why a neglected website is one of the common ways a small business gets hacked.
Most small business sites run on WordPress which powers more than 40% of all websites according to W3Techs. WordPress itself is solid. The risk is usually the plugins and themes added to it (which often don't get updated for years).
How a Neglected Website Gets Hacked
Attackers don't usually pick your business by name. They run automated tools that scan huge numbers of websites looking for known weak spots like a plugin with a security hole that has not been fixed. When the tool finds one, it breaks in. It is all automatic and it isn't aimed at you personally.
That is why old plugins are the problem. When a plugin maker finds a security flaw, they release an update to fix it. Until you install that update, the hole stays open and the automated scanners know exactly what to look for. Security researchers who track WordPress flaws find that the large majority are in plugins and themes rather than in WordPress itself.
What a Hacked Website is Used For
A hacked website rarely announces itself. Instead of shutting your site down, attackers usually keep it running and use it for their own purposes:
- Serving malware. Your site gets changed so that visitors are infected or pushed to a page that tries to install something.
- Spam and scam pages. Attackers add hidden pages selling fake goods or pushing scams to ride on your site's good standing with search engines.
- Stealing form data. If your site has a contact or checkout form, a hacked site can copy what people type into it (including personal or payment details).
- Visitors who click your link get sent somewhere else (often a scam or malware site).
The damage lands on you even though the attacker was after your visitors. Search engines flag hacked sites with warnings and drop them down the rankings and browsers may block them so customers see a red "this site may be dangerous" screen instead of your homepage.
Is Your Website at Risk?
It depends on how your site is built.
If you use a hosted website builder like Wix, Squarespace or Shopify, most of the security and updates are handled for you behind the scenes so your risk is lower.
If you have a self-hosted WordPress site (usually set up by a web designer or agency on your own hosting) then keeping WordPress, the plugins and the themes updated is someone's job. The question is whose. On a lot of small-business sites, the honest answer is that nobody has touched it since it launched.
You can usually tell your site is at risk if you don't know who maintains it, it hasn't been updated in a year or more or it is running plugins from a developer who has since disappeared.
How to Keep Your Website Safe
Keep everything updated. WordPress, plugins and themes all need updating when new versions come out. Many sites can be set to update automatically.
- Remove plugins you don't use. Every extra plugin is another thing that can go wrong. If you are not using it, delete it.
- Stick to well-known plugins. Use ones that are popular, well-reviewed and updated recently. Avoid anything that hasn't been touched in years.
- Watch for abandoned plugins. Sometimes a plugin stops being updated or gets removed from the plugin store because of a security problem. When that happens, it stops getting fixes so check now and then that the plugins on your site are still supported and replace any that aren't.
- Lock down the admin login. Use a strong and unique password for the website's admin account and turn on multi-factor authentication if your setup supports it.
- Add a security plugin or web firewall. A reputable one can block common attacks and warn you when something changes. Your web host or IT provider can recommend one.
- Keep backups. If the worst happens, a recent backup lets you restore the site instead of rebuilding it from scratch.
- Know who is responsible. Decide who looks after updates and security,whether that is your web designer, your IT provider or your hosting company and make sure it is clearly somebody's job.
What to Do if Your Site is Hacked
If your site does get hacked, moving quickly limits the damage:
- Get help straight away. Cleaning a hacked site properly is a job for your web host, IT provider or a website security service. Most hosts have dealt with this many times and can help.
- Take the site offline. Putting up a simple "down for maintenance" page stops visitors from being harmed while it is cleaned up.
- Change the passwords. From a device you know is clean, change the passwords for your hosting account and the website's admin login and turn on multi-factor authentication.
- Restore a clean backup. If you have a backup from before the hack, restoring it is often the fastest fix. If you don't, the site will need to be cleaned by hand.
- Update and tidy up before it goes back live. Update WordPress, the plugins and the themes and remove anything you don't recognize or no longer use so the same hole doesn't get used again.
- Tell anyone whose data was affected. If the site handled customer details or payments, check whether any of that was exposed and let those people know if it was.
Frequently Asked Questions
How do I know if my website has been hacked?
Common signs are a warning from Google or your browser such as a drop in search traffic, pages or pop-ups you didn't add or your web host getting in touch about a problem. If you are not sure, your IT provider or web host can check.
Do I need to update my website if it works fine?
Yes. A site can look completely normal to you while an out-of-date plugin leaves a door open for attackers. Updates close those holes which is why they matter even when nothing looks wrong.
I use Wix or Squarespace. Am I at risk?
Much less so. Hosted builders handle the updates and most of the security for you. You should still use a strong admin password and MFA but you are not responsible for patching plugins the way a self-hosted WordPress site is.
Who should maintain my website?
Someone should own it clearly: your web designer or agency, your IT provider or your hosting company depending on your setup. The important thing is that someone is actually doing the updates.
What is a security plugin or web firewall?
It is a tool that sits on your website, blocks common attacks, watches for changes and can alert you to problems. On WordPress, a reputable security plugin is a common and low-cost way to add that protection.

Article Summary: Scammers buy ads on Google and other search engines using the names of trusted brands and software so their fake site shows up at the very top above the real one. Click it and you can land on a fake page that steals your login or installs malware. You can avoid nearly all of it by skipping the sponsored results and going to the real website yourself.
When you search Google for a program to download or a website to log into, the first thing you see is usually an ad. It sits at the top marked "Sponsored" and most people click it without a second thought because the top result is normally what you wanted.
Scammers count on that. They buy ads on the names of trusted companies and popular software so their fake site appears right at the top above the real one and you click it thinking it is the official page.
How the Scam Works
The trick is called malvertising (short for malicious advertising). A scammer buys a search ad for a term people trust like the name of your bank, a Microsoft login or a common program such as a PDF reader or a video player. The ad looks normal with the real brand name and a web address that looks right.
When someone clicks it, they land on a page built to look exactly like the real one. Sometimes that page asks you to log in and hands your username and password straight to the scammer. Other times it offers the software you were after and the download installs malware instead of the real program.
Why These Ads Are So Easy to Fall For
These ads are convincing. They sit above the real result so they are the first thing you see. They use the real company's name and a web address that looks right. They show up on a search you started yourself so they don't feel as suspicious as a random email or text would.
Attackers have also gotten good at hiding from the checks meant to stop them. They show a clean and harmless page to the ad reviewers and the real malicious page to everyone else so the ad can pass review and still do damage.
How Common is This?
Very. In its 2025 Ads Safety Report, Google said it blocked or removed more than 8.3 billion ads that broke its rules, suspended 24.9 million advertiser accounts and took down 602 million ads tied to scams. Google also noted that criminals are now using AI to make fake ads faster.
Security researchers have found scam search ads pretending to be well-known programs like VLC, 7-Zip and CCleaner and even Google's own apps with downloads that installed password-stealing malware. These show up on the everyday searches your team runs.
What This Means for Your Business
For a business, the risk comes up in two everyday situations: downloading software and logging in.
When someone downloads software, they search for a tool, click the top ad and install something that steals the passwords and logins saved in their browser.
When someone logs in, they search for "Microsoft 365 login" or their bank, click the ad rather than the official link and type their username and password straight into a fake page.
In both cases, the problem is info-stealing malware. Once it is on a machine, it can steal saved passwords, browser cookies and session tokens which can get an attacker into accounts even when multi-factor authentication is switched on.
How to Protect Your Team
Scroll past the sponsored results. The ads sit at the top marked "Sponsored" or "Ad." The real website is usually just below in the normal results.
- Don't download software from an ad. Type the maker's web address yourself or search and use the normal result and then download from the official site.
- Bookmark the sites you log into. For your bank, Microsoft 365 and other important accounts, use a saved bookmark instead of searching each time.
- Keep devices and browsers updated. Turn on automatic updates so a bad download is less likely to work.
- Tell your team this is a thing. Most people have no idea the top result can be a trap and once they know they stop clicking it.
Frequently Asked Questions
Aren't ads at the top of Google checked and safe?
Google reviews ads and removes billions that break its rules but scammers still slip through by showing reviewers a clean page and everyone else the malicious one. A "Sponsored" label doesn't mean the site is safe.
What is malvertising?
Malvertising is short for malicious advertising. Scammers buy online ads often on trusted brand names to send people to fake sites that steal logins or install malware.
How do I download software safely?
Go to the maker's official website by typing the address yourself or search and use the normal (non-ad) result. Don't download from a sponsored ad and don't trust a download that arrives through one.
What should I do if someone clicked a scam ad?
If they only visited the page, close it and don't enter anything. If they typed a password, change it and turn on MFA. If they downloaded and ran a file, disconnect the device and have your IT provider check it for info-stealing malware.
Does an ad blocker help?
It can. A reputable ad blocker hides many sponsored results which takes the fake links off the page before anyone can click them. It isn't a complete fix so keep the habits above too.

Article Summary: Scammers now use AI to write their phishing emails so the spelling and grammar mistakes that used to give them away are gone. The UK's National Cyber Security Centre and the FBI both warn that AI makes these messages cleaner, more personal and harder to spot. The way to catch them now is to look at what an email is asking you to do because the writing no longer gives anything away.
For years, the advice for spotting a scam email was simple: look for bad spelling and clumsy grammar. A real bank or supplier writes properly so a message full of mistakes was probably fake. This made sense in the past. It was easy to teach and for a long time it worked.
It doesn't anymore. Scammers now use AI to write their emails and AI writes cleanly. The typos and awkward phrasing that gave phishing away are gone and the messages landing in your team's inbox read as well as anything from a real company. They can be written to sound like they came from someone you already know.
Why the Old Advice Stopped Working
The spelling-and-grammar tell worked because a lot of scammers were writing in a language that wasn't their own and the mistakes showed. AI took that away.
The UK's National Cyber Security Centre says generative AI can now create convincing phishing lures "without the translation, spelling and grammatical mistakes that often reveal phishing." The FBI says the same: criminals use AI to limit the grammar and spelling errors that used to mark a message as fake so it reads as believable. That means the one thing most people were trained to look for no longer tells you much.
Why These Emails are so Convincing Now
- The writing is clean. A scam email reads like a normal business email because a machine wrote it in seconds in whatever tone the attacker asked for.
- It is personal. Attackers can feed public details about your company into an AI tool pulled from your website, your team's LinkedIn profiles or a press release and get a message tailored to you: the right names, the right job titles and a believable reason to be in touch.
- There is more of it. AI makes each message faster to produce so attackers send far more. The FBI's Internet Crime Complaint Center added a section on AI to its annual report for the first time tied to more than 22,000 complaints and nearly $893 million in reported losses.
These days the scam email isn't the obvious one anymore. Instead of "Dear customer, your account is suspended," someone in your finance team gets a message that looks like it is from a supplier they really deal with, mentions a real project and asks to update the bank details for the next invoice. It reads exactly like a real supplier email. The only thing wrong is that the supplier never sent it.
Your Spam Filter Won't Catch Them All
It is tempting to assume your email security will handle this. It catches a lot and you should keep it switched on. However, a well-written and personalized email that asks a normal-sounding question doesn't always look dangerous to a filter when it carries no obvious bad link or attachment. Both the NCSC and the FBI expect AI to push more of these messages through which is why the last line of defense is a person who knows what to check.
It is Not Just Email Anymore
AI has done the same thing to phone calls and texts. The FBI warns that criminals can clone a voice from a short audio clip enough to leave a voicemail that sounds like your boss or a family member asking for an urgent payment. The same thing that makes AI emails so convincing makes AI phone scams convincing too. The defense is the same. If a call or voicemail asks for money or logins, hang up and call the person back on a number you already have.
Here Are the Signs You Should Still Pay Attention To
If you can't trust how an email is written, look at what it is asking you to do. That is where the real warning signs are and AI hasn't changed them:
- It asks for money, gift cards or a payment to a new account.
- It asks for a login, a verification code or personal details.
- It creates pressure: a deadline, a threat or a "do this now."
- It asks you to change the bank details for an invoice or a supplier.
- It comes with a link or attachment you weren't expecting.
- The display name looks right but the actual email address doesn't match it.
Every one of these is about what the email is asking for. So the rule to teach your team is simple: when a message is about money, logins or how you pay someone, slow down before you act.
How to Protect Your Team
- Check money and login requests another way. If an email asks you to pay a new account or change a supplier's bank details, call the person on a number you already have. Don't reply to the email or use a number it gives you.
- Stop telling staff to watch for bad spelling. Tell them to look at what the email is asking for and to slow down when it is about money or logins.
- Make one rule for payment changes: Confirm every change to bank details by phone even when it is urgent.
- Turn on phishing-resistant MFA or passkeys so a stolen password is harder to use even if someone gets tricked.
- Make it easy to report a suspicious email and make sure nobody feels silly for checking.
- Remind the team now and then that scam emails look perfect these days. A quick five-minute chat beats a poster nobody reads
Frequently Asked Questions
Can you still spot a phishing email by bad spelling and grammar?
Not reliably. Attackers use AI to write clean and correct emails now so a message with perfect spelling can still be a scam. Judge it by what it asks you to do.
What are the warning signs that still work?
The request itself: paying money, changing bank details, sharing a login or code or being pushed to act urgently. Those signs don't depend on how the email reads.
Is AI-generated phishing really more effective?
Yes. The NCSC and the FBI have both warned that AI makes phishing more convincing and more personal and the FBI has tied AI to tens of thousands of fraud complaints and hundreds of millions in losses. Cleaner and tailored messages get opened and clicked more often.
Will my spam filter stop AI phishing?
It will catch a lot and you should keep it on. However, a well-written and personalized email with no obvious bad link can still look legitimate to a filter so don't rely on it alone. A trained person is the backstop.
What should staff do if they aren't sure about a message?
Slow down and check through a channel they trust like calling a known number or asking the person directly. Report it even if it turns out to be genuine.

Article Summary: A passkey lets you sign in to an app or website using the same fingerprint, face or PIN you use to unlock your phone or laptop with no password to type. It is built on a security standard called FIDO that can't be phished because the passkey only works on the real site and there is no password to steal or reuse. Most major platforms and a growing list of business tools support passkeys and Microsoft 365 includes them at no extra cost. For most businesses, it is worth starting to roll them out beginning with the most sensitive accounts.
Passwords are the weak point in most businesses.
People reuse them across accounts, write them on sticky notes and type them into convincing fake login pages without realizing it.
Passkeys are the technology built to replace passwords and they fix the parts that cause the most trouble.
A passkey lets you sign in with the same fingerprint, face scan or PIN you already use to unlock your phone or laptop. There is no password to type so there is nothing for an attacker to steal, guess or trick out of you.
Let's look at what passkeys are, why they are so much harder to attack than passwords and whether your business should start using them.
What is a passkey?
A passkey replaces your password with your device's own security.
Instead of typing a password, you prove it is you the same way you unlock your phone: a fingerprint, a face scan or a PIN.
When you set up a passkey for a website, your device creates two matching keys.
The private key stays locked on your device and never leaves it.
The public key is stored by the website.
When you sign in, the site sends a challenge that only your private key can answer, your device answers it once you confirm with your fingerprint or PIN and you are in. The website never sees a password because there isn't one. This approach comes from a standard called FIDO which Apple, Google and Microsoft all build on.
Why Passkeys are Harder to Attack Than Passwords
A password is a secret you share with the website every time you log in and that is exactly what attackers go after.
A passkey has no shared secret. That one difference fixes the biggest problems with passwords.
- They can't be phished. A passkey only works on the real website it was created for. Land on a convincing fake and the passkey simply won't work so there is nothing to hand over. That matters because phishing is how most break-ins start.
- There is no password to steal in a breach. The website only keeps your public key which is useless on its own. If the company gets hacked, there is no password list to grab and try on your other accounts.
- Nothing to reuse or forget. Each passkey is unique to one site and made automatically so reused and weak passwords stop being a problem.
Older methods like text-message codes and app approval prompts can still be tricked out of people.
Where You Can Use Passkeys Already
Support has spread fast.
You can already sign in with passkeys to Microsoft, Google and Apple accounts plus a growing list of banks, password managers and business tools.
Apple, Google and Microsoft have built passkeys into their phones, laptops and browsers so the device in your pocket can already store and use them.
There are two types worth knowing.
A synced passkey is backed up to your Apple, Google or Microsoft account so it works across all your devices and you are covered if you lose one.
A device-bound passkey stays on a single device like a physical security key you plug in which is the most locked-down option and a common pick for sensitive accounts.
Should Your Business Use Them?
Most businesses should use them and you can start small. There is no need to switch everything overnight or drop passwords on day one.
If you use Microsoft 365, passkeys are already available through Microsoft Entra.
Staff can sign in with a passkey stored in the Microsoft Authenticator app, a security key or their own device. Google Workspace supports them too.
They are also faster. Microsoft says signing in with a synced passkey takes about 3 seconds against roughly 69 seconds for a password plus a traditional MFA code. Across a whole team, that adds up.
Here is how you can start using passkeys:
- Turn passkeys on for your most sensitive accounts first: administrators, finance and anyone who can move money or change systems.
- Let everyone else add a passkey as a faster and safer way to sign in alongside their normal login at first.
- Make sure each person has a backup (like a second device or a security key) so a lost phone doesn't lock anyone out.
Your IT provider can switch this on and run the rollout so nobody gets locked out along the way.
What to Watch Out For
Passkeys are not magic and a few things are worth planning for.
- Account recovery. If someone loses the only device with their passkey and has no backup, they can get locked out. A synced passkey or a second registered device fixes this but you need to set it up ahead of time.
- Not everything supports them yet. Support is growing fast but some older systems and smaller vendors still rely on passwords so you will run both side by side for a while.
- Shared devices and logins. Passkeys are tied to a person and their device so any shared computers or shared accounts need their own plan.
Frequently Asked Questions
What is a passkey in simple terms?
It is a way to log in using your fingerprint, face or PIN instead of a password. Your device proves it is you to the website and no password is ever typed or stored.
Are passkeys safer than passwords?
Yes. They can't be phished, there is no password for a hacker to steal in a data breach and there is nothing to reuse or forget. Security agencies like CISA recommend FIDO-based logins (which is what passkeys are) as the strongest widely available option.
What happens if I lose the device with my passkey?
If it was a synced passkey, it is backed up to your Apple, Google or Microsoft account and still available on your other devices. If it was device-bound and you have no backup, you would use a recovery method to get back in which is why setting up a second passkey or device in advance matters.
Does Microsoft 365 support passkeys?
Yes. Passkeys are available through Microsoft Entra at no extra cost including the free tier. Staff can use a passkey in the Microsoft Authenticator app, a security key or their device.
Do passkeys replace multi-factor authentication?
A passkey can count as multi-factor authentication on its own. Unlocking it needs both your device (something you have) and your fingerprint, face or PIN (something you are or know) so it covers two factors in one step and can replace the old password-plus-text-code routine.
