Enable strong spam filters to prevent phishing emails from reaching end users.
Implement a user training program to discourage users from visiting malicious websites or opening malicious attachments.
Filter emails containing executable files to prevent them from reaching end users.