To stop spear-phishing attacks, security teams must first train users to recognise, avoid and report suspicious e-mails. Every employee must realise that their roles grant them access to different data and the information economy's currency. Second, security teams must implement, maintain and update security technology and processes to prevent, detect and respond to ever-evolving spear-phishing threats. Finally, security teams must strive to stay ahead of attackers by investing in actively updated threat intelligence and expertise to meet their needs.