When the phish comes from a vendor you trust
Their tenant, your payment. Callback still wins. So does knowing who is allowed to change details.
ITSIGN Administrator · October 22, 2025 · 2 min read
You cannot MFA a supplier. You can refuse to change bank details from email alone. You can keep a vendor register with a known phone number.
When a long-standing plumber's "bookkeeper" writes from a new domain, that is the test.
Train AP with security awareness. Review vendor risk in GRC.
Related reading
Email retention, PIPEDA, and the mailbox you never deleted
Keeping everything forever is not a strategy. It is a larger breach waiting for a number.
2 min read
Turn off IMAP and POP before someone else uses them
Legacy protocols skip modern MFA. They are still on in tenants that were migrated in a hurry.
2 min read
External email banners that help instead of training people to ignore them
If every newsletter is tagged EXTERNAL, staff will stop reading the tag. Tune it.
2 min read
Want this applied to your environment?
A short conversation, an honest assessment of your current setup, and a clear proposal. No obligation and no pressure.
