4. Responding and reporting
If you clicked: what to do next
Sooner or later, most people click something they should not have. Attackers are professionals, and everyone has moments of distraction. What separates a near miss from a serious incident is almost entirely what happens in the next few minutes.
Step one: tell IT immediately
Report it to your IT team or security contact straight away, before anything else, even if you are not sure anything bad actually happened. Clicked a link but closed the page? Report it. Opened an attachment that did nothing? Report it. Entered your password on a page that then looked wrong? Definitely report it, and say exactly that, because it changes what IT needs to do.
Do not spend an hour investigating on your own first, and do not wait to see whether anything odd happens. Speed matters far more than certainty.
If you entered your password
Change that password as soon as possible, and if you use the same password anywhere else, change it there too, then stop reusing it, which Lesson 3 in this section will help with. Where possible, make the change from a device you trust rather than the one that may be compromised. Your IT team can also revoke active sessions and check for suspicious sign-ins, which is one more reason they need to know quickly.
If you opened an attachment or installed something
Leave the device on but stop using it for sensitive work, and follow your IT team's instructions. If your organisation's policy says to disconnect the device from the network, do so, but do not delete files, run cleanup tools, or attempt fixes yourself, because that can destroy the evidence responders need.
What not to do
- Do not forward the phishing email to colleagues to warn them, as someone will click it. Let IT send any warning
- Do not reply to the attacker or engage with follow-up calls or texts
- Do not delete the email before reporting it, since responders need it
- Above all, do not stay quiet out of embarrassment
That last point matters enough to get its own lesson, next.
› Course contents
How social engineering works
Spotting phishing emails
Beyond email
Responding and reporting
Putting it into practice