Last month, someone tried to phish us. Nothing new about that. Small businesses get poked at constantly. But this one was different. The email was a message from "our CEO" asking accounting to change the wire details on a vendor payment. There was no link. No attachment. No misspellings. It matched his voice, referenced a real client, and even had a plausible reason for the urgency.
Two people on the team almost forwarded it to finance before someone else noticed the reply-to address was one character off.
That's when I realized what everyone in cybersecurity has been quietly saying for a year: phishing has gotten really, really good. AI writes the emails now. They don't look like the "Nigerian prince" scams your parents mock. They look like your actual coworkers. Our regular spam filter never flinched. Nothing about that email fit the "bad link, sketchy attachment" patterns filters were built for.
I went looking for something more serious and stumbled onto Sentaro. It's an email security plugin that sits on top of Google Workspace or Microsoft 365. Small company, Stockholm-based, EU-hosted (which matters to some of our clients). Their pitch is enterprise-grade defense against AI-era phishing, priced for small businesses. Six dollars per seat per month, support included. I set it up in under five minutes. Not exaggerating.
The feature that sold me was something they call Risk and Threat labels, colored flags that appear directly on emails in your inbox. Green means safe. Yellow means suspicious. Red means don't click. The labels show up even in the mobile inbox, which is honestly where I do most of my triaging and where I have the least ability to hover-check senders. Now, before I read a single word, I know what I'm looking at.
Under the hood, it's doing more than pattern-matching. It learns how your team normally communicates. Who emails whom, how often, at what times. So when an email pretends to be a colleague asking for a favor, the system notices that this "colleague" has never emailed this person before, at this hour, with this tone. It reads intent and urgency the way a wary human would. Their published detection rate is 95%, and in the two weeks since I installed it, three emails have been quietly moved to spam that I know I would have at least opened.
One honest edge: Sentaro only supports Google Workspace and Microsoft 365. If your team is on some other email provider, this isn't for you. But if you're on either of those two, and most SMEs are, and you haven't upgraded your email defenses in a while, spend the five minutes.
If you want to try it: sentaro.com has a walkthrough. Given how good AI-written phishing has gotten, and how cheap the protection is, I don't have a good reason to wait anymore.

