Tips to improve your email security

July 31, 2023

Everyone knows someone who’s fallen prey and lost money to a scammer by clicking on a link in an email. The CERT NZ Q1 2023 report, the government’s cyber security organisation, indicates the number of scams & email based attacks are increasing in frequency (nearly 20,000 in quarter one) and the financial damaged caused was $5.8 million in quarter one this year (up 66% from quarter 4 last year).

So how can you protect yourself from inadvertently sharing information that results in you being scammed out of your hard-earned cash? Here are some specific things to look for in email based scams.


1.      Check the sender’s email address

Anyone can choose the name to display when sending an email. So even though an email says it’s from Xero it may not be. There’s an easy way to check, click on the information in the top of the email and you can see the email address the email has been sent from. Look closely at the spelling of the website or email address – does it look close but not quite right? Have they added a ‘1’ for a ‘l’ or extra prefixes or characters. If you don’t recognise it, assume it’s spam and contact the legitimate company.


2.      Watch for mistakes and generic greetings

Some emails from scammers contain obvious spelling and grammar mistakes. They also often use generic greetings such as “Dear Sir/Madam”, “Dear Customer”, “Dear Friend” or “Hi [first part of your email address] rather than your name.


3.      Suspicious links

Most scam emails contain links that take you to ‘dummy’ websites – websites that look like the real thing but are actually the scammers way of obtaining your information. This could be your login details for banking or asking weird questions such as the street you grew up on – all to have those details on hand when they pose as you. Unless you know the sender of the email, assume the email is spam. If you’re unsure, you can go to your browser and go to the company’s website and contact them.


4.      Verify independently

If you receive an email to verify a change or update and you didn’t expect the email (or do something directly moments before to trigger the verification) call the company and verify the request – preferably with someone you already know.


5.      Develop a process for a adding or changing supplier’s bank account details

Do you have a policy or procedure when loading new suppliers or requests for updates of bank account details? One of the most recent scams is to intercept an invoice and change the bank account details to the scammers. To the paying company, the invoice is legitimate and they assume that the company has updated their bank account details, so they make payment to the new account. Only later when reconciling, do they find out that they’ve paid it to a scammer’s account.


To combat this, create an extra verification step in your process when approving new suppliers and/or changing bank accounts from existing suppliers. One one to do this is verbal confirmation, so giving the company a call. Be wary of using the number on the invoice as this could have changed too and you could inadvertently phone the scammer, so use existing contact details to call the business and confirm the change.


6.      Watch Nigel Latta’s “You’ve Been Scammed” on TVNZ.

This series is available online at TVNZ and goes through the different scams to help prevent you becoming a victim.

 

7.      Turn on Multifactor Authentication in your email account

Turn this on for all mailbox logins to protect yourself. It’s a case of when rather than if you’ll credentials will be harvested and it’s almost impossible to get cyber risk insurance without this in place.


8.      Considering taking out Cyber insurance

As the scams get more sophisticated, some banks are not covering the loss so it may be time to consider taking out a cyber insurance policy. Most insurance companies offer cyber insurance to protect against loss of data and potential loss of funds from a scam. Discuss this with your insurance broker to determine the best policy to protect you.


More technical things to do

These can sound quite technical but they work in the background to protect you and your business. Your IT company will know what these mean and will be able to set these up for you.


9.      Implement advanced Sandbox filtering for malicious URL’s (links) and attachments

This means that any links or files attached to an email are pre-detonated in a virtual environment to see what they do before they get to your mailbox! Most people have some traditional spam filtering in place but if you have whitelisted certain clients and suppliers to ensure you always get their messages, BE WARNED - this can mean if a bad guy takes over their mailbox and then you’re at risk of getting malware delivered direct to your inbox.


10.  Implement Sender Policy Framework (SPF) & Domain-based Message Authentication, Reporting and Conformance (DMARC) rules on your domain name

These rules are quite tricky but without them in place or some other means to protect your VIP’s it means that it can your staff, customers and suppliers could be tricked into communicating with a scammer and it can be very difficult for individuals to pick this up. Just recently the NZ Govt Security and Communications Bureau has made this a mandatory requirement for the NZ Information Security Manual that all departments must abide. These rules also have a great side benefit of protecting your brand and help ensure your marketing & invoice emails don’t end up in the destination junk folder!


If in doubt, treat it as a scam

Unfortunately, scammers are becoming cleverer all the time and putting more effort into making websites and emails look like the real thing. Remember banks and other institutions will never ask for your account number, name, address or password in an email. Always err on the side of caution and treat anything suspicious as a scam. Don’t take the risk as become the scammer’s next victim.



October 15, 2025
For employers Christmas is a time to ensure you’re on top of your obligations around holiday pay. Here’s a quick guide to help small business owners across Aotearoa stay compliant and stress-free over the break.
September 30, 2025
The run-up to Christmas is one of the busiest times of the year for many Kiwi businesses. Whether you’re wrapping up projects, closing the books, or managing stock and customers before a summer break, it can be a time of high pressure and high pace. Add in social functions, school holidays, and year-end fatigue, and it’s easy for stress and burnout to creep in.  As an employer, you play a key role in supporting your team’s wellbeing. Investing in mental health isn’t just the right thing to do, it’s also good for business.
September 30, 2025
Growth is exciting, and with the right planning, it can be a turning point for your business. Here are four key questions to ask yourself before scaling up.
September 19, 2025
At BFA, we’re proud to support local students through the Gateway Programme – a fantastic initiative that helps young people gain real-world experience in industries they’re curious about.
September 11, 2025
How are you feeling about your business right now? Are you on solid financial footing, or taking a more cautious approach? Is demand steady, growing, or unpredictable?
September 2, 2025
A strong credit profile is the foundation of your business’s financial health. This blog looks at why it's important, and how you can build and protect a good score.
August 28, 2025
A core initiative for Kiwi businesses, Investment Boost is a new tax incentive to encourage investment in assets to increase productivity.
July 28, 2025
We were fortunate to have Mark Lister from Craigs Investment Partners as our guest presenter at a recent event co-presented by BFA and Craig's Investment Partners.
July 3, 2025
At BFA, our passion for numbers is matched only by our commitment to community, wellbeing, and having fun together. Here’s a snapshot of what we’ve been up to so far in 2025.
June 10, 2025
We love celebrating our clients success stories, and were delighted to read about our clients John and Kellie Penny's daughter Charlotte who was recently crowned Eventer of the Year.