Skip to main content

How the SLAM Method Can Improve Phishing Detection in 2026 — The Buff IT Guy’s Guide

Media How Using the SLAM Method Can Improve Phishing Detection

 

Phishing emails used to have a reputation for being easy to spot.

Bad spelling. Strange grammar. Terrible logos. A mysterious prince offering you several million pounds if you could just provide your bank details.

Those emails still exist.

But they are no longer what businesses should train employees to expect.

Modern phishing can be professionally written, carefully targeted and almost indistinguishable from legitimate communication. A fake Microsoft 365 notification may look exactly like the real thing. A fraudulent invoice request might appear to continue an existing conversation. An attacker can create urgency without using a single spelling mistake.

Phishing therefore remains a problem that technology alone cannot completely solve. The NCSC recommends organisations build multiple layers of defence, combining technical controls with an environment where employees can recognise and quickly report suspicious messages.

One simple framework can still help:

SLAM

S — Sender
L — Links
A — Attachments
M — Message

It gives employees four things to check before trusting an unexpected email.

The Buff IT Guy approves of simple security advice.

But the SLAM method needs an upgrade for 2026.

Here's how to use it properly.

S = Sender

Start by looking at who the message claims to be from.

Suppose an email says:

Microsoft Security Team

At first glance, that looks reassuring.

But what is the actual email address?

Attackers frequently use addresses designed to look similar to genuine domains.

For example:

accounts@microsoft-security-example.com

might look convincing during a quick glance even though it has nothing to do with Microsoft.

Other attacks can involve compromised genuine accounts, meaning the message may actually come from somebody you recognise.

That is why simply checking the sender address is useful — but no longer enough.

Ask whether the message makes sense

Suppose your usual supplier emails you saying:

“We've changed bank accounts. Please send all future payments here.”

The sender may be genuine.

But that does not automatically mean the request is genuine.

Their mailbox could have been compromised.

So your SLAM check should include context:

Was I expecting this?

Does this person normally make requests like this?

Is the request unusually urgent?

Is money involved?

Does this change an established process?

For high-risk requests, verify using another communication channel.

Call the supplier using the telephone number you already have on record.

Do not telephone the convenient number included at the bottom of the suspicious email.

Buff IT Guy Rule #1

Recognising the sender isn't the same as verifying the sender.

Attackers love trusted relationships because people naturally lower their guard.

L = Links

Links remain one of the most common tools used in phishing.

An email may ask you to:

View a SharePoint document.

Reset your Microsoft password.

Review an invoice.

Listen to a voicemail.

Confirm an account.

Sign a document.

The link then takes you somewhere designed to steal credentials or other information.

Hovering your mouse over a link before clicking can still be useful because it may reveal the actual destination.

But it shouldn't be treated as a perfect phishing detector.

A malicious domain may look convincing.

Attackers can use shortened links, compromised legitimate websites and redirection services. More sophisticated phishing attacks can even relay authentication between the victim and a genuine service.

The NCSC notes that traditional passwords and some forms of MFA can still be defeated by live phishing attacks where credentials or approvals are captured and relayed.

A better approach: don't use the link

If Microsoft apparently tells you there is a problem with your Microsoft 365 account, you do not necessarily need the button in the email.

Open Microsoft 365 yourself.

If your bank tells you there is suspicious activity, use its official app.

If Amazon says there is an order problem, open Amazon independently.

This simple behaviour removes much of the attacker's control over where you go next.

Buff IT Guy Rule #2

When an email creates a problem and conveniently supplies the only button that can fix it, don't automatically trust the button.

Go to the service independently.

Passkeys Can Make Fake Login Pages Much Less Effective

This is also where modern authentication can help.

The NCSC strengthened its advice around passkeys in April 2026, explaining that they are resistant to phishing because authentication is cryptographically tied to the legitimate service. A fake site cannot simply steal a passkey in the same way it can capture and reuse a password.

That is why businesses should increasingly combine phishing awareness with phishing-resistant authentication, rather than expecting employees to identify every fake Microsoft login page perfectly.

Humans should have help.

A = Attachments

Unexpected attachments deserve caution.

An attacker might disguise malware as:

An invoice.

A purchase order.

A CV.

A delivery note.

A contract.

A scanned document.

The important word is unexpected.

An attachment does not become safe simply because it is a PDF or Word document.

Likewise, not every unfamiliar attachment is malicious.

Context matters.

If somebody you have never dealt with sends you:

URGENT OVERDUE INVOICE.zip

perhaps don't double-click it enthusiastically.

If you're unsure whether an attachment genuinely came from a customer or supplier, verify it before opening.

Don't Depend Entirely on Employees

Businesses should also have technical protection around email and endpoints.

The NCSC recommends a layered defence against phishing rather than making employees solely responsible for deciding whether every message is malicious.

Depending on the organisation, those controls may include:

Email filtering and anti-phishing protection

Microsoft Defender for Office 365

Endpoint Detection and Response

DNS and web filtering

Application controls

Managed security updates

Restricted user privileges


The employee is one defence layer.

They shouldn't be the only defence layer.

Buff IT Guy Rule #3

If the entire cyber-security strategy is “hopefully Sandra doesn't open the attachment”, you don't have a cyber-security strategy.

M = Message

This is the part of SLAM that needs the biggest 2026 update.

Older phishing training often concentrated on spelling and grammar.

Certainly, poor writing can still be suspicious.

But a beautifully written message is not evidence that an email is legitimate.

Generative AI has made creating polished communication extremely easy.

Instead of analysing commas, look at what the message is trying to make you do.

Watch particularly for:

Urgency

“You must respond within 30 minutes.”

Attackers often want you acting before you have time to think.

Fear

“Your account will be permanently disabled.”

Fear encourages rushed decisions.

Financial requests

“Please send today's payment to our new account.”

Payment changes deserve independent verification.

Requests for authentication

“Sign in to view this document.”

Unexpected login requests are especially valuable to criminals targeting Microsoft 365.

Unexpected MFA prompts

If you're being asked to approve an authentication request you didn't initiate, don't approve it just to make the notification disappear.

Requests for sensitive information

Passwords, card information, payroll records and confidential documents should not be handed over simply because an email sounds authoritative.

Unusual behaviour

Perhaps the finance director normally asks you to process payments through the accounting system.

Today they suddenly want you to buy £2,000 of gift cards urgently.

That change of behaviour should matter more than whether the message contains a spelling mistake.

The Buff IT Guy's Updated SLAM Test

Before acting on an unexpected email, mentally run through:

S — Sender

Who actually sent this?

Does the request make sense coming from them?

L — Links

Where does the link really go?

Do I need to use the link at all?

A — Attachments

Was I expecting this file?

Do I trust where it came from?

M — Message

What is this message trying to make me do?

Is it creating urgency, fear or pressure?

That entire thought process can take only a few seconds.

Sometimes those few seconds are enough to stop a serious incident.

SLAM Needs One More Step: Verify

If something feels wrong, don't simply stare at the email trying to decide whether it passes or fails the SLAM test.

Verify it independently.

Suppose an email says your managing director urgently needs a payment.

Telephone them.

A supplier changes their bank details.

Call your established contact.

Microsoft says your password has expired.

Open Microsoft 365 yourself.

A delivery company says your parcel needs attention.

Open its official app.

Verification is one of the most powerful ways to break social-engineering attacks because it moves the conversation away from the communication channel the attacker controls.

And Another Step: Report

A good phishing programme does not end with the employee pressing Delete.

Report suspicious messages.

The NCSC operates the UK's Suspicious Email Reporting Service, and suspicious emails can be forwarded to:

report@phishing.gov.uk

The NCSC says it has received tens of millions of reported scams through its reporting services and used those reports to identify and remove malicious websites.

For business environments, employees should also have an easy way of reporting phishing directly to IT.

That might be:

A Report Phishing button.

A dedicated email address.

A helpdesk ticket.

A telephone call.

The exact mechanism matters less than making it easy and obvious.

What If an Employee Already Clicked?

This is where company culture becomes extremely important.

If an employee clicks a suspicious link, you want them telling IT immediately.

Not tomorrow.

Not after lunch.

Not once they have spent 45 minutes trying to quietly fix it themselves.

If they entered a password, IT may need to investigate the account.

If they approved MFA, active sessions may need checking.

If they opened malware, the endpoint may require isolation and investigation.

The sooner IT knows, the faster protective action can begin.

Punishing employees for reporting mistakes encourages employees to hide mistakes.

That is the exact opposite of what you want.

Buff IT Guy Rule #4

An employee admitting “I think I've clicked something dodgy” is useful security intelligence.

Don't make them afraid to tell you.

Phishing Training Shouldn't Happen Once a Year

SLAM works best when employees actually remember it.

That means cyber-security awareness should be reinforced throughout the year rather than appearing as one annual training exercise.

Short refreshers can cover:

Fake Microsoft 365 logins.

QR-code phishing.

Payment fraud.

MFA fatigue.

Malicious attachments.

Supplier impersonation.

Smishing.

AI-assisted scams.

The threat changes.

Training needs to change with it.

Technology Should Back Up the SLAM Method

Even perfectly trained employees will occasionally make mistakes.

So a modern phishing defence should combine people with technology.

For Microsoft 365 businesses, that can mean Microsoft Defender for Office 365, Microsoft Entra ID, Conditional Access, managed endpoints, EDR and phishing-resistant authentication such as passkeys or FIDO2.

The NCSC's current guidance specifically recommends multiple layers that make it harder for phishing to reach users, harder for users to act on malicious messages and harder for attackers to benefit if credentials are compromised.

That is the right philosophy.

Don't demand perfect users.

Build an environment capable of surviving imperfect decisions.

The Buff IT Guy Verdict on SLAM

The SLAM method is still useful in 2026.

But it needs to evolve.

Sender shouldn't just mean checking whether you recognise an email address.

Links shouldn't simply mean hovering and deciding whether the URL looks funny.

Attachments shouldn't rely entirely on knowing which file extensions are dangerous.

And Message definitely shouldn't mean hunting for grammatical errors.

Modern phishing detection is about recognising unexpected behaviour, pressure and context.

Use SLAM as the trigger that makes somebody stop for five seconds before acting.

Then:

Verify.

Report.

And let your technical security controls provide another layer of defence.

The Buff IT Guy may have enormous arms, but even he knows that cyber security works better with layers.

How Hamilton Group Helps Businesses Fight Phishing

Hamilton Group can help businesses build phishing protection that goes beyond asking employees to “be careful”.

We can help with cyber-security awareness training, Microsoft 365 security, Microsoft Defender, email protection, EDR, Microsoft Entra ID, Conditional Access, passkeys and phishing-resistant MFA, DNS/web filtering and managed IT support.

We can also help businesses create sensible reporting procedures so employees know exactly what to do when something suspicious arrives.

Because the important thing isn't creating an organisation where nobody ever clicks anything incorrectly.

It is creating one where attacks are harder to deliver, harder to exploit and detected quickly when something does go wrong.

And when your team needs IT support, our aim is to make first contact within 15 minutes.

Call Hamilton Group on 0330 043 0069 or visit hgmssp.com to speak with one of our IT and cyber-security experts.