
27,128 reports in six months. That is how many cyber incidents the public and companies voluntarily reported to the Swiss Federal Office for Cybersecurity in the first half of 2026, documented in the BACS semi-annual report 2026/1 (in German). More interesting than the big number are two observations from the same report: attackers are increasingly taking over business accounts in Microsoft 365 and using them for further phishing. And they now use AI systematically to make personalized messages credible.
The usual reaction to numbers like these is an awareness campaign. Another phishing test, another poster next to the coffee machine. We consider that the wrong first measure. Phishing prevention in a business is first of all an architecture question, not a behavior question. The email your team never sees needs nobody to spot it. And the click that reaches nothing needs no training.
Why training is so popular as the first answer
A short look at the incentives explains a lot. An awareness campaign is visible, budgetable and uncomfortable for nobody except the employees who fail the test. A DMARC record set to "reject" is invisible, costs nothing and shows up in no management report. What gets sold is what can be shown.
Add to that the convenient story of the human as the weakest link. It sounds like insight, but it is mostly a reallocation: it makes employees responsible for a risk the operation could defuse. Whoever clicks has not failed. They opened an email, and opening emails is their job. What failed is the environment in which a single click makes the difference.
So let's go through it, along the three levels.
Phishing prevention starts before the inbox
The largest part of the defense is invisible and runs before a human is involved. Three DNS records decide how easily your domain can be forged: SPF, DKIM and DMARC. Translated: SPF and DKIM prove that an email comes from your servers, DMARC tells the receiving side what to do with forgeries. The records are free and need no maintenance contract. Still, in our experience at least one of them is missing in many SME environments, or DMARC has been sitting on "monitor" instead of "reject" for years. The status takes two minutes to check, any freely available DMARC check tool shows it. There are few places in IT security where so little effort closes so much surface.
The topic has two directions, and the second one is often overlooked. One protects you: a properly configured filter rejects forged senders before they land in the inbox. The other protects your customers and suppliers: with DMARC on "reject", nobody can send invoices with a new account number in your name. If your domain is abused to defraud your customers, you are the weak link in the supply chain without ever having been hacked yourself.
That leaves the filter itself. Whoever licenses Microsoft 365 Business Premium already owns link checking and attachment analysis with Defender for Office. Bought, yes; switched on, often only halfway. Before you discuss an additional mail security product, it is worth asking whether the existing one is fully used. That is the quiet part of cost optimization: first exhaust what is already paid for.
The click is part of the plan
Any prevention plan that assumes nobody clicks is not a plan. Given enough attempts, someone eventually clicks, and with AI-personalized messages the attempts get better, not worse. The question is therefore what a click can reach when it happens.
What companies measure here is telling. Almost every management team knows the click rate from the last phishing test, it is right there in the vendor's report. What a clicked account could reach in their own house, hardly anyone can quantify. What gets measured is what the test vendor delivers, not what determines the damage. Yet the second quantity is the one you can act on.
The game has shifted in recent years. Modern phishing kits insert themselves as a proxy between the victim and the real login page. The victim types in the password and the six-digit code from the authenticator app, both pass through the attacker's hands, and the attacker takes over the running session. Multi-factor authentication based on codes does not protect against this approach. This is exactly how many of the taken-over Microsoft 365 accounts described by BACS in its report come about.
The answer to it is unspectacular: phishing-resistant sign-in methods. Passkeys and FIDO2 keys bind the sign-in cryptographically to the real domain. On a fake page the sign-in does not work, no matter how convincing it looks. Rolled out company-wide, that is a project. For administrators and finance roles it is an afternoon, and that is where most of the risk sits.
Two more levers belong on the same level. Conditional Access can tie sign-ins to conditions, for example managed devices: a stolen session that suddenly wants to continue from an unknown machine does not get in at all. And app consents: not every attack wants your password. Some slip you a harmlessly named app that you grant permanent access to your mailbox with one click, no credentials involved. Whether users may grant such consents themselves is a single setting in the tenant.
And then the question of radius. If this one account is taken over, what does it reach? An accounting account with read access to the file share is a nuisance. The same account with global admin rights, because that was convenient once in 2019, is a business interruption. Permissions are phishing prevention, even though they appear in no awareness brochure.
After the click: the first thirty minutes
At some point it happens anyway. Then what counts is whether your operation knows a practiced path or improvises.
The reporting path first: reporting must be easier than deleting. A button in the mail client, a known address, and above all a person who looks at reports and is allowed to act. A phishing report that dies in a shared mailbox is not a control, it is decoration. What this operation can look like without an in-house security team is something we described in our post on running IT security without a security team.
Then the takeover itself. A password reset alone is not enough. Running sessions must be ended, newly created forwarding and inbox rules checked and app consents reviewed. Attackers like to settle in quietly after a takeover: one inconspicuous rule that hides certain replies, and weeks later the prepared payment request goes out to your customers, from your real account, in your name. The BACS report describes exactly this pattern, taken-over business accounts as the starting point for the next phishing wave.
We regularly see what it looks like when nobody has rehearsed this. The typical case rarely starts with an alert. It starts with an irritated phone call: a customer asks why the payment reminder suddenly carries a different account number. From there, everything runs backwards. Who had access, since when, which rules sit in the mailbox, who else was written to. Answers that should take a quarter of an hour then take days, because nobody knows where to look and who may decide.
Whoever has walked through these steps once needs minutes in a real case. The difference is half an hour of preparation with clear responsibility, not new software.
Where training has its place
None of this means training is useless. It lowers the click rate, and more importantly, it speeds up reporting. A team that forwards suspicious emails without fear of embarrassment is a better sensor than any filter. What training can realistically deliver and where its limits lie is something we covered in our post on security awareness training in SMEs.
Only the order has to be right. A program that starts with people and stops before the architecture trains people to compensate for a gap that could be closed. First harden the environment, then strengthen the people. In this order the two complement each other; in the reverse order one only appears to replace the other.
A side effect of the right order: the training becomes more honest. If you can tell your team "one click does not take down the company here, but your report makes us faster", you train attention instead of fear. That sticks better than any threat scenario.
Three questions show where you stand
For all of this you need no new tool list and in most cases no additional budget. Most of it sits in licenses you already pay for and in configuration work that has to be done properly once. Taken together we are talking about days, not months, and about nothing that disrupts a running business.
Is DMARC for your domain set to "reject"? Do your administrators sign in with a passkey or FIDO2 key, or with a code that can be phished in real time? And does every person in the company know where a suspicious email goes, and who looks at it within the hour?
Three times yes: then your phishing risk is better managed than at many companies. A hesitation on one of the questions: start exactly there, not with the next awareness poster. If you want to approach this in a structured way, it is the core of our Security Management & Operations offering: configuring and operating the controls you own instead of buying new ones. An initial conversation is free of obligation.
One question interests us most: if an account in your company were taken over tonight, who would be the first to notice tomorrow?




