As many as half of Flemish companies fell victim to cyberattacks in 2024. A study by VLAIO (Flanders Innovation & Entrepreneurship) shows that in 1 in 10 cases, those cyberattacks were also successful. Clearly, organisations are unable to sufficiently deal with cybercriminals, while small daily adjustments can have a major impact. For companies, even a single successful phishing attempt can cause financial damage, loss of reputation, and operational downtime. A well-thought-out policy and informed employees can make a big difference. Here are some practical tips to help prevent phishing and protect yourself and your colleagues from phishing attacks.
Know what you’re clicking on
To prevent phishing, avoid clicking on links or scanning QR codes in emails or text messages without first verifying their legitimacy. Whenever possible, try to go directly to an organisation’s official website by manually typing the URL. This way, you can avoid fake websites that appear trustworthy. Fraudsters very often send fake emails that appear to come from government agencies or banks. For example, if you receive a message from your e-box, don’t click on the URL in the email itself, but go directly to your e-box and log in with Itsme.
Protect your finances
Ensure that your company has clear payment agreements in place to prevent fraud. Who is authorised to make payments? What is the procedure for this? Also, always double-check payment requests, especially when they involve large amounts or urgent transfers. Verify the sender’s email address or phone number, even if it appears to be your colleague, manager, supplier, or bank. Not sure if something is legitimate? Contact the person you think you received the request from personally using a known number.
Protect your data
Investing in a clear cybersecurity policy is our third tip to prevent phishing. This means organising regular awareness training for employees, running phishing simulations from time to time, and working with clear internal agreements regarding payments and data management. Provide at least basic security measures such as using strong passwords and multifactor authentication.
But a bit of common sense can always go a long way. In this digital age, one can quickly and easily communicate everything online. Be careful when you do this, as you don’t always know who you’re dealing with on the other side of the screen. Never send bank details via email, text message, or Teams. Don’t share codes, passwords, or account numbers over the phone. A legitimate bank will never ask you to do this either.
Know what you’re posting
Protect your personal data on social media. Phishers use public information such as your address, job title, location, or travel plans to set up targeted attacks. Also check images you post for unintentionally visible data, such as screens, papers, or badges. And importantly, don’t just post other people’s photos or details, no matter how well-intentioned it may be, after that one fun company party.
Don’t keep quiet about it
Being scammed is never fun. Sometimes people even feel embarrassed about it. However, it is crucial to report something like this immediately to the IT department. The faster you respond, the more damage control you can do. This might not only resolve the problem, but you will also protect other colleagues by preventing them from experiencing the same thing. In case of financial fraud, it’s also best to contact your bank immediately. And lastly, you can report any case of phishing via Safeonweb, an initiative of the Belgian Government.

