Report first, act second. Well-meaning cleanup — deleting the phishing email, wiping the odd process, rebooting the server — destroys exactly the evidence the response team needs. Nothing here is about blame: fast reporting is the single behaviour that most reduces incident cost.
Always reportable
- A link was clicked or an attachment opened in a suspicious message — even if "nothing happened"
- Credentials entered on a page that turned out to be fake
- A device behaving oddly after installing something
- Any unexpected MFA prompt you did not initiate
- A USB stick of unknown origin, found or received
- Data visible that should not be accessible to you
Channels by urgency
- Active compromise in progress (something is happening now): call the SOC hotline — 24×7, number on the back of your badge
- Suspected but not active (clicked yesterday, phishing in inbox): "Report Phishing" button in Outlook, or the Security → Report Incident portal form
- Policy questions and near-misses: security@ mailbox
What happens next
You will get an acknowledgement within 15 minutes for hotline reports and 4 business hours for portal reports. The response team may isolate your device remotely — this is routine containment, not an accusation, and a loan device is couriered the same day when it happens.
Was this article helpful?
98% of 2,021 readers found it useful