Incident Reporting & Response

MODULE 05 / CRITICAL11 min / Includes knowledge checks and quiz

Incident Reporting & Response

When something goes wrong, the first 15 minutes matter. Learn exactly what to do, who to call, and what to document when you suspect a security incident.

A calm professional on a phone call at their desk, taking notes while reporting an incident

What You Will Learn

When something goes wrong, the first few minutes matter. This module teaches you exactly what to do, who to call, and what to document when you suspect a security incident.

  • When to report: recognizing the signs that something is wrong
  • How to report: the channels, the information to include, and the timeline
  • What NOT to do: common mistakes that make incidents worse
  • First 15 minutes: the immediate containment steps that limit damage
  • Documentation: what to record for your organization and for compliance

Why Fast Reporting Matters

Prompt reporting is the fastest way to contain an incident. The longer a breach goes unreported, the more damage attackers can do. Many regulatory frameworks (HIPAA, SOC 2, ISO 27001) require documented incident reporting procedures, and some require notification within specific timeframes.

The key insight: you are not in trouble for reporting. You are in trouble for NOT reporting. Every organization experiences security incidents. What separates resilient organizations is how quickly they detect and respond.

Quick Check

You realize you entered your password on a fake login page 10 minutes ago. What should you do FIRST?

A) Shut down your computer immediately
B) Disconnect from the network and change your password from a different device
C) Wait to see if anything happens
D) Delete the suspicious email and move on

When to Report

Report immediately if you experience any of the following:

  • You clicked a link or opened an attachment from a suspicious email
  • You entered your password on a page that might have been fake
  • Your computer is acting strangely with pop-ups, slow performance, or unexpected software
  • A device is lost or stolen including laptops, phones, USB drives, and tablets
  • You receive an unexpected MFA prompt because someone may have your password
  • You notice unfamiliar activity like emails you did not send or logins from unknown locations
  • You see sensitive information exposed where it should not be

How to Report

Every organization should have a clear reporting process. Use whichever channel is available to you: the important thing is to report, not to figure out the perfect channel.

  • Report Phishing button in your email client (if configured)
  • Email your IT contact or security team directly
  • Phone call to your IT team or STM. For urgent incidents, calling is always better than emailing.
  • In person if you are in the same building as your IT contact
  • STM clients: Call us directly. We will walk you through immediate steps and help contain the incident.

Quick Check

You notice emails in your sent folder that you did not send. What does this indicate and what should you do?

A) A glitch in your email client – restart your computer
B) Your account may be compromised. Change your password, check for forwarding rules, and report to IT immediately.
C) Someone is borrowing your computer – ask your colleagues
D) It is nothing to worry about – delete them

The First 15 Minutes

If You Clicked a Link or Entered Credentials

  • Step 1: Disconnect. Turn off Wi-Fi or unplug the Ethernet cable. Do NOT shut down because you may lose evidence.
  • Step 2: Change your password from a different device (phone, another computer). Use a new, strong password.
  • Step 3: Reset MFA if you enrolled a new device or approved a new login.
  • Step 4: Check email forwarding rules. Attackers often set up auto-forwarding to capture future messages.
  • Step 5: Report. Contact IT or STM immediately with details of what happened.
  • Step 6: If money was involved, call your bank immediately to request a wire recall and file a police report.

What NOT to Do

Common Mistakes That Make Incidents Worse

  • Do not shut down your computer. This can destroy evidence. Disconnect from the network instead.
  • Do not try to fix it yourself. Unless you are IT, do not run antivirus scans, delete files, or try to undo what happened.
  • Do not keep it to yourself. Embarrassment is normal, but silence is dangerous. IT teams and STM have seen everything.
  • Do not pay any ransom or respond to extortion demands without consulting IT or law enforcement.
  • Do not delete the suspicious email. Keep it as evidence. Forward it to IT or take a screenshot.

How This Looks in Your Industry

Healthcare Practices

Under HIPAA, you must document and report security incidents. If patient data may have been exposed, a formal breach assessment is required. If confirmed, affected individuals must be notified within 60 days. Fast internal reporting gives you time to assess and respond within that window.

Legal Firms

If client data is exposed, you may have an ethical obligation to notify affected clients. The faster you detect and contain, the less data is exposed and the smaller the notification scope.

Nonprofits

Grant agreements often require you to notify the grantor of any data breach. Some grants specify notification timelines. Fast reporting ensures you meet those obligations and maintain trust with your funders.

Daycares and Schools

If student or parent data is exposed, state laws may require notification. FERPA and state child privacy laws have specific breach notification requirements. Fast internal reporting ensures you can assess the scope and meet legal deadlines.

Key Takeaways

  • Report immediately. The faster you report, the more contained the damage.
  • Disconnect from the network but do NOT shut down. You may lose evidence.
  • Change your password from a different device, then check for email forwarding rules.
  • There is no judgment in reporting. IT and STM have seen everything. Silence is the only mistake.
  • Document what happened: what, when, what you did, and which device was involved.

Module Quiz

Select an answer for each question to reveal the correct response and explanation.

1. You realize you entered your password on a fake login page. What should you do FIRST?

A) Shut down your computer immediately
B) Disconnect from the network and change your password from a different device
C) Wait to see if anything happens
D) Delete the suspicious email and move on

2. You notice emails in your sent folder that you did not send. What does this indicate?

A) A glitch in your email client
B) Your account may be compromised. Report it immediately.
C) Someone is borrowing your computer
D) It is nothing to worry about

3. Under HIPAA, if patient data may have been exposed in a security incident, what is required?

A) Nothing. Just fix the issue internally.
B) A formal breach assessment, and if confirmed, notification to affected individuals within 60 days.
C) Notification to the police only.
D) Notification to the EHR vendor only.

4. Why should you NOT shut down your computer after a suspected incident?

A) It wastes electricity
B) Shutting down can destroy forensic evidence that IT needs to investigate
C) It takes too long to restart
D) It is actually the recommended first step

5. What information should you include when reporting a security incident?

A) Only your name and department
B) What happened, when it happened, what you did after, which devices were involved, and any screenshots or emails
C) Just say something is wrong and let IT figure it out
D) A full technical analysis of the attack

Module 05 of 10 – Cybersecurity Essentials Training

Previous ModuleBack to ResourcesNext Module