Phishing, BEC & Security Habits Playbook

A practical companion to the September 2026 Virtus Group newsletter. Use it to define verification rules, staff reporting, and first-response actions for phishing, credential theft, business email compromise (BEC), invoice fraud, account-recovery abuse, and unsafe sharing.

1. Stop-and-Verify Triggers

ScenarioRequired ActionWho VerifiesEvidence to Keep
Supplier or customer bank details changeVerify using a trusted number already on record or independently sourced; do not rely on contact details in the change request.Finance + second approverVerifier, method, date/time, outcome
Urgent or unusual payment requestUse the normal approval path and confirm outside the originating message.Manager/director + financeApproval record and payment reference
Unexpected MFA promptDeny it. Do not approve to make prompts stop. Report immediately.User + IT/security ownerTime, account, device, screenshots if available
Password or MFA reset requestVerify identity using the established recovery process before changing credentials or factors.IT/helpdesk + authorised ownerVerification method, operator, change performed
Suspicious shared file or linkDo not continue interacting with it; report for review.User + IT/security ownerOriginal message, sender, URL/file details
Request for password, MFA code, or recovery codeDo not share it. Stop the interaction and escalate.User + IT/security ownerOriginal request and escalation note

2. Staff Reporting Message

Report early: If an email, text, phone call, login prompt, file share, payment request, or account request feels unusual, report it.

Include: sender/caller, time, what you opened or clicked, whether credentials were entered, whether MFA was approved, and any payment action taken.

Preserve: keep the original message and screenshots where safe. Do not keep clicking links to test them.

Culture: early reporting is usefulβ€”even when the event turns out to be harmless.

3. First-Response Checklist

IncidentImmediate ActionsFollow-UpOwner
Phishing link clicked, no credentials enteredStop interacting; report; capture the URL/message. If anything downloaded or executed, isolate the device and escalate.Review endpoint/email telemetry as appropriate and block malicious indicators where possible.
Credentials entered into suspected phishing pageFrom a trusted device, reset the password and revoke active sessions/tokens where supported. Report immediately.Review sign-in activity, MFA methods, mailbox rules, forwarding, admin changes, and other affected services.
Unexpected MFA prompt approvedReport immediately; revoke sessions; reset credentials as appropriate; confirm registered MFA methods.Investigate sign-in logs and determine whether account access occurred.
Suspected mailbox compromiseContain access, revoke sessions, reset credentials, and review authentication methods.Inspect forwarding/inbox rules, sent/deleted items, OAuth/app access, and impacted contacts; preserve evidence.
Suspected invoice/payment fraudStop pending payment where possible and contact the bank immediately if funds may have moved. Preserve the request.Verify the genuine supplier/customer through a trusted channel, begin incident response, and report the incident as appropriate.
Suspicious password/MFA reset requestDo not complete the reset until identity is independently verified. Escalate the failed verification.Review related account activity and warn relevant helpdesk/admin staff.
Unsafe external sharingRemove inappropriate access where safe to do so and record what was exposed.Review sensitivity, access logs, recipients, and whether notification/escalation is needed.

4. Account-Recovery Verification Checklist

5. Monthly Human-Layer Security Review

6. Ten Habits Worth Reinforcing

  1. Pause when a request creates unusual urgency, secrecy, or pressure.
  2. Verify payment and bank-detail changes through a separate trusted channel.
  3. Report suspicious messages and prompts early.
  4. Deny unexpected MFA prompts.
  5. Never share passwords, MFA codes, or recovery codes.
  6. Use approved file-sharing locations and check external permissions.
  7. Store business credentials in an approved password manager.
  8. Keep devices and applications updated.
  9. Ask before introducing new SaaS, AI tools, or browser extensions into business workflows.
  10. Escalate uncertainty instead of guessing.

Best habit: You do not need every employee to identify every scam. You need people to verify high-risk requests, protect credentials, and report uncertainty early.

7. New Zealand External Escalation

For a cyber security issue affecting a New Zealand individual or business, the National Cyber Security Centre provides an online reporting service. Where fraudulent funds may have been transferred, contact the relevant bank immediately as well as starting your internal incident response.

NCSC β€” Report a cyber security issue

πŸ‘‰ Book your free consultation today:
πŸ“§ hello@virtusgroup.biz
🌐 virtusgroup.co.nz
πŸ“ž 0800 847 887 (VIRTUS)

References and further reading