Incident Reporting & Response
When something goes wrong, the first 15 minutes matter. Learn exactly what to do, who to call, and what to document when you suspect a security incident.
What You Will Learn
When something goes wrong, the first few minutes matter. This module teaches you exactly what to do, who to call, and what to document when you suspect a security incident.
- When to report: recognizing the signs that something is wrong
- How to report: the channels, the information to include, and the timeline
- What NOT to do: common mistakes that make incidents worse
- First 15 minutes: the immediate containment steps that limit damage
- Documentation: what to record for your organization and for compliance
Why Fast Reporting Matters
Prompt reporting is the fastest way to contain an incident. The longer a breach goes unreported, the more damage attackers can do. Many regulatory frameworks (HIPAA, SOC 2, ISO 27001) require documented incident reporting procedures, and some require notification within specific timeframes.
The key insight: you are not in trouble for reporting. You are in trouble for NOT reporting. Every organization experiences security incidents. What separates resilient organizations is how quickly they detect and respond.
Quick Check
You realize you entered your password on a fake login page 10 minutes ago. What should you do FIRST?
When to Report
Report immediately if you experience any of the following:
- You clicked a link or opened an attachment from a suspicious email
- You entered your password on a page that might have been fake
- Your computer is acting strangely with pop-ups, slow performance, or unexpected software
- A device is lost or stolen including laptops, phones, USB drives, and tablets
- You receive an unexpected MFA prompt because someone may have your password
- You notice unfamiliar activity like emails you did not send or logins from unknown locations
- You see sensitive information exposed where it should not be
How to Report
Every organization should have a clear reporting process. Use whichever channel is available to you: the important thing is to report, not to figure out the perfect channel.
- Report Phishing button in your email client (if configured)
- Email your IT contact or security team directly
- Phone call to your IT team or STM. For urgent incidents, calling is always better than emailing.
- In person if you are in the same building as your IT contact
- STM clients: Call us directly. We will walk you through immediate steps and help contain the incident.
Quick Check
You notice emails in your sent folder that you did not send. What does this indicate and what should you do?
The First 15 Minutes
If You Clicked a Link or Entered Credentials
- Step 1: Disconnect. Turn off Wi-Fi or unplug the Ethernet cable. Do NOT shut down because you may lose evidence.
- Step 2: Change your password from a different device (phone, another computer). Use a new, strong password.
- Step 3: Reset MFA if you enrolled a new device or approved a new login.
- Step 4: Check email forwarding rules. Attackers often set up auto-forwarding to capture future messages.
- Step 5: Report. Contact IT or STM immediately with details of what happened.
- Step 6: If money was involved, call your bank immediately to request a wire recall and file a police report.
What NOT to Do
Common Mistakes That Make Incidents Worse
- Do not shut down your computer. This can destroy evidence. Disconnect from the network instead.
- Do not try to fix it yourself. Unless you are IT, do not run antivirus scans, delete files, or try to undo what happened.
- Do not keep it to yourself. Embarrassment is normal, but silence is dangerous. IT teams and STM have seen everything.
- Do not pay any ransom or respond to extortion demands without consulting IT or law enforcement.
- Do not delete the suspicious email. Keep it as evidence. Forward it to IT or take a screenshot.
How This Looks in Your Industry
Healthcare Practices
Under HIPAA, you must document and report security incidents. If patient data may have been exposed, a formal breach assessment is required. If confirmed, affected individuals must be notified within 60 days. Fast internal reporting gives you time to assess and respond within that window.
Legal Firms
If client data is exposed, you may have an ethical obligation to notify affected clients. The faster you detect and contain, the less data is exposed and the smaller the notification scope.
Nonprofits
Grant agreements often require you to notify the grantor of any data breach. Some grants specify notification timelines. Fast reporting ensures you meet those obligations and maintain trust with your funders.
Daycares and Schools
If student or parent data is exposed, state laws may require notification. FERPA and state child privacy laws have specific breach notification requirements. Fast internal reporting ensures you can assess the scope and meet legal deadlines.
Key Takeaways
- Report immediately. The faster you report, the more contained the damage.
- Disconnect from the network but do NOT shut down. You may lose evidence.
- Change your password from a different device, then check for email forwarding rules.
- There is no judgment in reporting. IT and STM have seen everything. Silence is the only mistake.
- Document what happened: what, when, what you did, and which device was involved.
Module Quiz
Select an answer for each question to reveal the correct response and explanation.
1. You realize you entered your password on a fake login page. What should you do FIRST?
2. You notice emails in your sent folder that you did not send. What does this indicate?
3. Under HIPAA, if patient data may have been exposed in a security incident, what is required?
4. Why should you NOT shut down your computer after a suspected incident?
5. What information should you include when reporting a security incident?
Module 05 of 10 – Cybersecurity Essentials Training
