For years, the advice for spotting a phishing email was "look for bad spelling and weird grammar." In 2026, that advice is dead. AI now writes flawless, natural, personalized emails — and attackers use it to target small businesses at scale, cheaply. If your defense still relies on employees "just noticing," you're exposed. Here's what actually works.
Why AI changed the threat
The dangerous part isn't smarter malware — it's smarter messages. With AI, an attacker can:
- ▸Write perfect emails in your language, tone, and industry jargon.
- ▸Personalize at scale — reference your real vendors, projects, or people scraped from LinkedIn and your site.
- ▸Clone voices for phone and voicemail scams ("vishing").
- ▸Impersonate your boss convincingly enough to trigger a wire transfer or a shared password.
The result: emails that pass the "does this look legit?" test almost every time. So the defense has to stop depending on the human eye alone.
The defense: layers, not vigilance
You don't beat this with a smarter workforce — you beat it with a setup that assumes people will eventually be fooled, and limits the damage when they are.
1. Lock the front door: email authentication. Properly configured SPF, DKIM and DMARC stop attackers from spoofing your domain to scam your customers and staff — and improve your own deliverability as a bonus. Most small businesses have these misconfigured or missing.
2. Enforce 2-Step Verification for everyone. A stolen password is worthless without the second factor. Make it mandatory, not optional. Prefer app-based or passkey 2FA over SMS.
3. Least-privilege access. Nobody should have access to more than their job needs. When one account is compromised, the blast radius should be small — not your whole Drive.
4. Kill standing risks.
- ▸Remove access the same day someone leaves.
- ▸Review "anyone with the link" sharing.
- ▸Turn on Workspace's admin security alerts.
5. Approvals for anything irreversible. Money movement and password/access changes should require a second channel of confirmation — a quick call, not just a reply to an email.
The goal isn't a team that never clicks a bad link — that team doesn't exist anymore. It's a setup where clicking one doesn't hand over the business.
The quiet wins most teams miss
- ▸Passkeys — phishing-resistant sign-in that's genuinely easier than passwords.
- ▸Device management — a lost laptop shouldn't mean lost data.
- ▸Regular access audits — permissions drift; review them on a schedule.
- ▸A simple "when in doubt, verify" rule — one internal norm: confirm any money or access request through a second channel, every time.
Most of these are settings, not software you have to buy — they're already in Google Workspace, just switched off or misconfigured.
Where to start
If you're not sure whether your SPF/DKIM/DMARC are right, whether 2FA is truly enforced, or who can see what — that uncertainty is the risk. A short security review usually finds several quick, high-impact fixes.
That's exactly what we do: audit your Google Workspace, close the gaps, and set up defenses that hold even when someone has a bad day.
Want to know where your business is actually exposed? Book a free security review — we'll map the gaps and fix the urgent ones.
Want this set up for your business?
VB Easy does this for clients every week. Let's talk about your setup — no obligation.