How the con actually works
Social engineering is just manipulation dressed up in a business context. An email appears to come from your bank, your supplier, Microsoft, or your own boss, and it manufactures a reason to act fast: an invoice overdue, an account about to be locked, a payment that must go out today. Phishing is the mass-email version; spear phishing is the tailored one, where the attacker has done homework and names real people and real projects. The most expensive variant, business email compromise, involves a message that looks exactly like your CEO or a known vendor asking you to change banking details or wire funds. In every case the goal is the same — get a human to skip their normal caution because the moment feels urgent.
The tells to train yourself on
The signals are consistent once you know them. Urgency and pressure — act now, or else. A request that breaks normal process, like paying to a new account or buying gift cards. A sender address that is subtly wrong, a lookalike domain off by one letter. Links whose real destination, revealed by hovering, does not match the text. Unexpected attachments. And requests for credentials or codes that no legitimate organisation asks for by email. Any one of these deserves a pause; two together should stop you cold. The instinct to build is simple: the more a message rushes you, the more slowly you should move.
Defences that survive a bad day
Awareness matters, but people have off days, so the strongest defences assume someone will eventually click. Turn on multi-factor authentication everywhere, and prefer phishing-resistant options like passkeys or an authenticator app over codes texted to a phone — then a stolen password alone is not enough. Verify any money-or-credentials request through a second channel you already trust: phone the supplier on their known number, walk over to the colleague, never reply to the suspicious message itself. Keep payment-change approvals to a documented process. And talk about this openly with your team so nobody is embarrassed to flag a mistake quickly.
You do not need a security department to shut most of this down — you need a little healthy suspicion, MFA switched on, and a habit of confirming unusual requests before acting. Those few practices stop the overwhelming majority of attacks aimed at small Canadian businesses, because the con only works when everyone is moving too fast to check.