GRC Careers

HomeResourcesPhishing

CS-032 · Email Security

Phishing

Fraudulent messages that trick people into revealing credentials, sending money, or running malware.

Executive Summary

Phishing is a social engineering attack in which fraudulent messages, most often email, impersonate a trusted person or organization to trick the recipient into revealing sensitive information, clicking a malicious link, or running harmful software. It is the most common way attackers gain their first foothold in an organization. Because it targets human trust rather than a technical flaw, no single tool stops it, and awareness plus layered controls matter most.

What It Is

Phishing is an attempt to deceive a person into acting against their own or their employer's interest by pretending to be someone they trust. The classic form is a broad email blast impersonating a bank, a shipping company, or an internal department, urging the reader to log in, confirm a payment, or open an attachment. The goal is usually to harvest credentials through a fake login page, deliver malware through an attachment or link, or convince the victim to send money or data. Phishing is the umbrella term for a family of related attacks that target specific people (spear phishing), executives (whaling), or use other channels such as text messages (smishing) and voice calls (vishing).

Why It Matters

Phishing is the starting point for a large share of serious breaches, including ransomware and business email compromise, because stolen credentials or a single opened attachment can give an attacker the access they need. It is cheap to run at scale, easy to automate, and effective because it exploits normal human habits such as trusting familiar logos and reacting quickly to urgent requests. For organizations, one successful phishing message can lead to data theft, financial loss, regulatory exposure, and reputational damage. For professionals, recognizing and reporting phishing is now a baseline expectation in nearly every role, and defending against it is a core skill across security operations, incident response, and governance.

How It Works

A phishing campaign begins with a lure, a message crafted to look legitimate and to prompt a specific action. The attacker relies on visual imitation (familiar branding and layouts), plausible pretext (a password reset, an invoice, a delivery notice), and psychological pressure (urgency, fear, or curiosity). When the recipient clicks a link, they are typically taken to a counterfeit website that captures whatever they type, or a file downloads and attempts to run malicious code. Stolen credentials are then used directly, sold, or fed into further attacks. Modern phishing often defeats simple filters by using freshly registered domains, look-alike addresses, hijacked legitimate accounts, and links that only turn malicious after delivery, which is why layered defenses and human vigilance both matter.

Architecture Diagram

Attacker crafts a deceptive messageMessage impersonates a trusted sourceUser clicks a link or opens an attachmentCredentials are captured or malware runsAccess is used, sold, or escalated
Phishing follows a path from a deceptive lure to a captured action, ending in stolen credentials or delivered malware.

Visual Workflow

The attacker chooses a pretext and impersonates a trusted brand, colleague, or service.A lure is sent, usually by email, with urgent language and a link or attachment.The recipient is directed to a fake login page or prompted to open a file.Credentials are captured or malware executes on the device.The attacker uses the access to steal data, move money, or launch a broader attack.Reported messages are analyzed so filters and awareness training can be improved.

Common Attacks

Common Mistakes

Best Practices

Quick Checklist

Recommended Tools

Email security gateway
Filters malicious messages and inspects links and attachments before delivery
Multi-factor authentication
Blocks account takeover even when a password is phished
DMARC with SPF and DKIM
Authenticates senders and reduces domain spoofing
Phishing report button
Lets users report suspicious mail for fast analysis and takedown

Industry Standards

NIST SP 800-61
Incident handling lifecycle for responding to successful phishing
NIST SP 800-177
Trustworthy email guidance including sender authentication
CIS Critical Security Controls
Email and awareness safeguards central to phishing defense

Career Relevance

Phishing defense touches nearly every security role. SOC analysts triage reported messages and hunt for compromise, incident responders contain accounts that were tricked, and security awareness leads design the training and simulation programs that reduce click rates. Security engineers tune email gateways and authentication, while GRC analysts assess phishing resilience and awareness maturity against frameworks. For the AI-Governance-Jobs.com audience, phishing literacy is foundational across security and governance work.

Interview Questions

Related Certifications

CompTIA Security+ ISC2 Certified in Cybersecurity (CC) GIAC Security Essentials (GSEC)

Further Reading

Key Takeaways

Download PDFDownload PNG

FAQ

How can I tell if an email is phishing?

Watch for urgency, unexpected requests for credentials or payment, mismatched or look-alike sender addresses, links whose real destination differs from the visible text, and generic greetings. When in doubt, do not click. Navigate to the service directly and report the message.

Why does phishing still work despite email filters?

Filters catch a lot but not everything. Attackers use freshly registered domains, hijacked legitimate accounts, and links that only turn malicious after delivery. Because phishing targets human trust rather than a technical flaw, awareness and multi-factor authentication remain essential.

What should I do if I clicked a phishing link?

Report it immediately, change the affected password, and enable or confirm multi-factor authentication. Security teams can then reset sessions, check for further access, and contain any compromise before it spreads.

Get all 116 reference sheets
The complete AGJ Cybersecurity Professional Reference Library, print-ready PDFs and PNGs.
Browse the library

Related Careers

Related certifications

CompTIA Security+ISC2 Certified in Cybersecurity (CC)GIAC Security Essentials (GSEC)

Current openings

Live openings appear on the web version. Browse the job board for current GRC and security roles.
Browse all jobs

Suggested learning path

  1. Ground the basics with CS-001 Cybersecurity
  2. Study this sheet: Phishing
  3. Go deeper: Spear Phishing
  4. Go deeper: Whaling
  5. Validate it: work toward CompTIA Security+
  6. Find the role: browse current openings

Related sheets

More in Email Security

Share this LinkedIn Facebook X Email