Phase 1: Finding the Attack (Identification)
The first step is figuring out that an attack is happening. Time is very important here.
- Listen to your team: If an employee says "I think I clicked a bad link," thank them for telling you. Do not get angry. If they are scared to tell you, the hackers win.
- Check system alerts: Look at your antivirus or email security tools. Did they block a virus? Did they stop a weird login attempt?
- Look at the email: Find the bad email. Look at the sender address, the subject, and the link inside it. Do not click the link yourself!
Phase 2: Stopping the Attack (Containment)
Once you know there is a problem, you must stop it from spreading. Imagine a broken pipe—your first job is to turn off the water.
Immediate Actions to Take:
- Disconnect the computer: If an employee downloaded a file, tell them to unplug their computer from the internet (unplug the network cable and turn off Wi-Fi). Do not turn the computer off completely, just disconnect it.
- Reset the password: If the employee typed their password into a fake website, force a password reset immediately. Also, check if they use that same password anywhere else.
- Log them out: Use your admin tools (like Microsoft 365 or Google Workspace admin center) to sign the user out of all their current sessions.
- Block the sender: Add the bad email address or domain to your company's blocklist so no one else gets the email.
Phase 3: Fixing the Damage (Eradication)
Now that the attack cannot spread, it is time to clean up the mess.
- Run a full virus scan: Scan the employee's computer with your strongest antivirus tool to remove any hidden malware.
- Delete the bad emails: Search your company's email server. Delete the bad email from every employee's inbox so no one else can click it.
- Check for hidden rules: Hackers often create hidden email rules. For example, they might set a rule that forwards all new emails to the hacker's personal address. Check the affected user's email settings for any weird forwarding rules.
Phase 4: Getting Back to Work (Recovery)
It is time to return things to normal, but safely.
- Reconnect the computer: Once you are 100% sure the computer is clean, you can connect it back to the internet.
- Watch the account closely: Keep a close eye on the affected user's account for the next few days. Look for unusual logins from strange countries or strange times.
Phase 5: Learning from the Mistake (Lessons Learned)
Never waste a good mistake. This is how your company gets stronger.
- Write it down: Document exactly what happened, when it happened, and how you fixed it.
- Train your team: Tell the rest of the company about the attack (without embarrassing the person who clicked). Show them what the bad email looked like so they can spot it next time.
- Improve your tools: Ask yourself: "Why did our email filter not catch this?" Maybe you need to turn on Multi-Factor Authentication (MFA) or buy better email security software.