The most valuable asset of any organization is information; that's why every company spend a large amount of money to protect it. On the other hand, hackers do their best to get access to this information either for their personal gain or for other competitor organizations using various methods and techniques; one of which phishing is the most common. Phishing attacks aim to steal users' credentials such as usernames and passwords, social security numbers, credit or debit cards information; or anything that can let the phishers(hackers) access a system or steal money from their victims. The thread phishing attacks cause lead to financial loss and loss of reputation for the victims. Therefore, this study aimed at supporting the prevention and detection of phishing attacks at the organization level through the adoption of a preventive and detective model.