Most breaches do not start with a clever exploit; they start with an email that looks like a colleague, an invoice or a courier. The attack surface is human attention under time pressure — 'urgent', 'final notice', 'the boss needs this today' — which no firewall filters.
Defence is layered: DMARC/SPF so your domain cannot be forged, link protection and MFA so a stolen password is not enough, and a culture where 'I clicked, what now' is reported in minutes instead of hidden. The technical floor matters; so does making reporting safe.
Related terms
MFA / 2FA
Multi-factor authentication — proving identity with something you know plus something you have, so a leaked password alone cannot log in.
Ransomware
Malware that encrypts your files and sells the key back to you — the attack where your backups decide whether it is a bad week or a closed business.
Incident response
The plan and the practice for what happens between noticing something is wrong and being back to normal.
The bench this belongs to
CybersecurityPurple Team: the same person writes the exploit and closes the hole. Most agencies only harden, which means hardening against a threat nobody tested.
