Home Roadmap Resources Join Now
Back to Resources

Phishing Response Playbook

A simple, step-by-step guide on what to do when someone in your company clicks on a bad email link. Following these steps quickly will help stop hackers from causing more damage.

Phase 1: Finding the Attack (Identification)

The first step is figuring out that an attack is happening. Time is very important here.

  • Listen to your team: If an employee says "I think I clicked a bad link," thank them for telling you. Do not get angry. If they are scared to tell you, the hackers win.
  • Check system alerts: Look at your antivirus or email security tools. Did they block a virus? Did they stop a weird login attempt?
  • Look at the email: Find the bad email. Look at the sender address, the subject, and the link inside it. Do not click the link yourself!

Phase 2: Stopping the Attack (Containment)

Once you know there is a problem, you must stop it from spreading. Imagine a broken pipe—your first job is to turn off the water.

Immediate Actions to Take:

  1. Disconnect the computer: If an employee downloaded a file, tell them to unplug their computer from the internet (unplug the network cable and turn off Wi-Fi). Do not turn the computer off completely, just disconnect it.
  2. Reset the password: If the employee typed their password into a fake website, force a password reset immediately. Also, check if they use that same password anywhere else.
  3. Log them out: Use your admin tools (like Microsoft 365 or Google Workspace admin center) to sign the user out of all their current sessions.
  4. Block the sender: Add the bad email address or domain to your company's blocklist so no one else gets the email.

Phase 3: Fixing the Damage (Eradication)

Now that the attack cannot spread, it is time to clean up the mess.

  • Run a full virus scan: Scan the employee's computer with your strongest antivirus tool to remove any hidden malware.
  • Delete the bad emails: Search your company's email server. Delete the bad email from every employee's inbox so no one else can click it.
  • Check for hidden rules: Hackers often create hidden email rules. For example, they might set a rule that forwards all new emails to the hacker's personal address. Check the affected user's email settings for any weird forwarding rules.

Phase 4: Getting Back to Work (Recovery)

It is time to return things to normal, but safely.

  • Reconnect the computer: Once you are 100% sure the computer is clean, you can connect it back to the internet.
  • Watch the account closely: Keep a close eye on the affected user's account for the next few days. Look for unusual logins from strange countries or strange times.

Phase 5: Learning from the Mistake (Lessons Learned)

Never waste a good mistake. This is how your company gets stronger.

  • Write it down: Document exactly what happened, when it happened, and how you fixed it.
  • Train your team: Tell the rest of the company about the attack (without embarrassing the person who clicked). Show them what the bad email looked like so they can spot it next time.
  • Improve your tools: Ask yourself: "Why did our email filter not catch this?" Maybe you need to turn on Multi-Factor Authentication (MFA) or buy better email security software.