Small business phishing protection

Phishing protection for small businesses that rely on email, links and online bookings

ScanLens reviews the public signals attackers commonly abuse: suspicious links, fake invoices, weak email domain authentication, cloned website risk and customer-facing trust gaps.

What the review checks

This service looks at practical phishing exposure rather than theoretical risk. It is designed to answer a simple business question: if a customer or staff member receives a suspicious link, invoice or login request involving your brand, what visible weaknesses could make the scam more believable?

  • Suspicious links and short URLs
  • Fake invoice and payment redirection risk
  • SPF, DKIM and DMARC signals
  • Website HTTPS and security headers
  • Public trust and contact signals
  • Practical staff reporting steps

Sample output

Example finding: "Staff payment-change requests do not have a documented secondary verification step. Priority: high. Recommendation: verify every bank-detail change through a previously known contact method before payment."

See a sample report showing the finding, business-impact and recommendation format.

Business Protection Setup

For teams that need a workflow
£399

Includes the Starter review plus a staff workflow for suspicious links, fake invoices, reporting and response steps.

  • One business or team, one main website and up to two email domains
  • Suspicious link and email workflow
  • Anti-phishing checklist for staff
  • Scam response steps
  • Written follow-up support by email
  • 14 calendar days of email follow-up
  • One review call of up to 45 minutes and one workflow/checklist revision
  • Delivery within five business days after complete information and scope confirmation

Typical findings

Missing DMARC

Attackers may find it easier to spoof your domain in fake invoice or account-warning emails.

Weak trust signals

Unclear contact, company or security reporting information can make it harder for customers to verify the real business.

Broad browser policy

Missing or broad security headers can increase exposure if a page or script is abused.

Unclear staff workflow

People may not know where to report suspicious links, payment changes or login prompts.

Scope note

This is not a penetration test, vulnerability assessment, compliance audit or guarantee that every scam will be detected. It is a non-invasive review focused on visible phishing, scam and domain-trust signals. Additional websites, domains, teams, calls or revisions require a separate quote.

Purchase FAQ

What must I provide?

Provide the public website, email domain, main concern and accurate background requested by ScanLens. Do not send passwords, payment-card data, licence keys or private documents through the enquiry form.

Are the prices total prices?

Yes. Starter is £99 and Business Protection Setup is £399. Prices shown are the total prices. No VAT is currently charged.

When does work begin?

After written order acceptance, payment, complete required information and scope confirmation.

Which package suits a team?

Choose Business Protection Setup when you need a tailored staff workflow, checklist, review call and follow-up. Use the enquiry form if the scope is unclear.