REFERENCE / EMERGENCY CARD
Incident Response Quick Card
Who to call, what to document, and what NOT to do in the first 15 minutes of a suspected security incident.
If You Clicked a Link or Entered Credentials
Step 1: Disconnect. Turn off Wi-Fi or unplug the Ethernet cable. Do NOT shut down because you may lose evidence.
Step 2: Change your password from a different device (phone, another computer). Use a new, strong password.
Step 3: Reset MFA if you enrolled a new device or approved a new login.
Step 4: Check email forwarding rules. Attackers often set up auto-forwarding to capture future messages.
Step 5: Report. Contact IT or STM immediately with details of what happened.
Step 6: If money was involved, call your bank immediately to request a wire recall and file a police report.
If a Device Is Lost or Stolen
Report immediately to IT or STM. Do not wait to see if it turns up.
Change passwords for all accounts that were accessible from the device.
Request remote wipe if your organization has MDM or tracking enabled.
File a police report if the device was stolen.
Document what data was on the device for breach assessment purposes.
If You Receive a Suspicious Email
Do not click any links or open any attachments.
Do not reply to the email.
Report it using the Report Phishing button or forward to your IT team.
Delete it after reporting.
If you already clicked, follow the steps above for clicked links.
What NOT to Do
Common Mistakes That Make Incidents Worse
- Do not shut down your computer. This can destroy evidence. Disconnect from the network instead.
- Do not try to fix it yourself. Unless you are IT, do not run antivirus scans, delete files, or try to undo what happened.
- Do not keep it to yourself. Embarrassment is normal, but silence is dangerous. IT teams and STM have seen everything.
- Do not pay any ransom or respond to extortion demands without consulting IT or law enforcement.
- Do not delete the suspicious email. Keep it as evidence. Forward it to IT or take a screenshot.
Who to Contact
STM Clients
- Call STM directly at our support number. We will walk you through immediate steps and help contain the incident.
- If you are not yet an STM client, contact your internal IT team immediately. If you do not have IT support, call us for emergency assistance.
What to Document
- What happened (clicked a link, lost a device, received a suspicious email)
- When it happened (date and time)
- What you did after (disconnected, changed password, reported)
- Which devices were involved (laptop, phone, desktop)
- Any evidence (screenshots, the original suspicious email, forwarding rules you found)
This quick card is a supplement to Module 05: Incident Reporting and Response. Complete the full module for interactive training and knowledge checks.