
The latest UK cyber warning is a useful reminder for small businesses: email security cannot rely on staff awareness alone.
On 23 July 2026, the National Cyber Security Centre and international partners warned about a Russian state-supported campaign targeting vulnerable Zimbra Collaboration Suite email systems. The technique, known as “beehive” or “Ulej”, is described as zero-click because a user only needs to view a malicious email in a vulnerable webmail service for compromise to begin.
Most BM Technologies clients will not be running Zimbra, and this specific advisory is aimed at higher-risk organisations. The business lesson still matters: attackers are moving beyond obvious scam emails. If email, cloud accounts, patching and monitoring are not managed properly, even careful staff can be put in an unfair position.
Phishing is still the main route in
The UK government’s Cyber Security Breaches Survey 2025/2026 found that phishing remained the most common type of cyber breach or attack identified by businesses. Among organisations that experienced cyber crime, phishing dominated the picture, and the survey estimated that around 248,000 UK businesses experienced phishing cyber crime in the last 12 months.
That does not mean every incident is sophisticated. Many still start with a fake invoice, a password reset prompt, a Microsoft 365 login page or a supplier impersonation email. But the NCSC’s July warning shows the direction of travel: email compromise is becoming more technical, more automated and less dependent on someone making an obvious mistake.
Awareness training helps, but it is not a complete defence
Staff training is still worth doing. People should know how to report suspicious messages, check unexpected payment requests, and pause before entering passwords into unfamiliar pages.
The problem is that training only works against attacks people can reasonably spot. It will not patch a vulnerable email server, block a stolen session token, detect unusual mailbox access, or stop an attacker using an old admin account. Those jobs belong to technical controls and day-to-day IT management.
What layered email protection looks like
For most small and medium-sized businesses, the practical answer is not buying every security product available. It is getting the basics consistently right, then adding monitoring where risk justifies it.
- Keep email platforms, plugins, firewalls, VPNs and endpoint software patched
- Turn on multi-factor authentication for Microsoft 365, Google Workspace and other cloud services
- Use strong conditional access rules where possible, especially for admin accounts
- Remove old accounts, shared mailboxes and unused app passwords that no longer need access
- Configure phishing and malware filtering properly, not just at default settings
- Monitor for suspicious inbox rules, unusual sign-ins and impossible travel events
- Back up important cloud data and test recovery, including Microsoft 365 data where needed
- Make suspicious email reporting simple so staff do not sit on concerns
Cyber Essentials is becoming a better baseline
The April 2026 Cyber Essentials updates also point in the same direction. The scheme is tightening expectations around security updates, cloud services and MFA because common internet-facing weaknesses are being exploited quickly. For businesses that handle client data or work in supply chains, Cyber Essentials is increasingly less of a badge and more of a sensible minimum standard.
If your business has not reviewed its Cyber Essentials position this year, now is a good time. The useful question is not “could we pass the questionnaire?” It is “are these controls actually working across our laptops, cloud apps, admin accounts and suppliers?”
A simple email security review for this week
You do not need to wait for an incident to improve your position. Start with a quick review of the systems attackers care about most.
- Check every mailbox has MFA enabled
- Check admin accounts are separate from everyday user accounts
- Review external forwarding rules and unexpected inbox rules
- Confirm mail filtering is active and correctly licensed
- Patch any self-hosted email, webmail, VPN or firewall systems
- Review backup coverage for email, files and business-critical cloud data
- Agree a clear route for staff to report suspicious emails
At BM Technologies, we help businesses put those layers in place without turning security into a full-time admin burden. That includes Microsoft 365 security, endpoint protection, backup, patching, monitoring, staff guidance and practical Cyber Essentials support.
If you are not sure whether your email setup would stand up to today’s phishing and account compromise tactics, start with a quick cyber risk check.
Sources
- NCSC: UK and partners expose Russian state-supported actors for new zero-click phishing campaign
- Joint Cybersecurity Advisory: Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite
- UK Government Cyber Security Breaches Survey 2025/2026
- NCSC Small organisations guide to cyber security
