An employee clicked a phishing link. What should the business do?
Speed matters, but panic causes mistakes. The response depends on what happened after the click: simply opening a page is different from entering a password, approving MFA, downloading a file or making a payment.
6 practical answers.
### What should the employee do first?
Report it immediately through the organisation's incident route. Do not hide the mistake or keep experimenting with the suspicious page. Record what was clicked, what information was entered and what happened afterwards.
### What if they entered their Microsoft 365 password?
Treat the account as potentially compromised. Start the agreed account-containment process, review sign-in activity and suspicious changes, invalidate access where appropriate, reset credentials through a known-good route and investigate for persistence such as inbox rules or app access.
### What if they approved an MFA request?
Escalate urgently because the attacker may already have a valid session. Investigate sign-ins and sessions, contain the account and review whether stronger authentication methods and number matching or phishing-resistant options are available.
### Should the computer be disconnected from the network?
If a malicious file was opened, software executed or there are signs the device is compromised, follow your endpoint-containment process. Avoid destroying evidence or making uncoordinated changes before the incident lead understands what happened.
### What if bank or payment details were supplied?
Contact the relevant bank or payment provider using a trusted number immediately and follow its fraud process. Preserve evidence and also consider whether email, supplier or customer accounts are being impersonated.
### Should staff be blamed for clicking phishing emails?
No. Fast reporting is more valuable than blame. Training should make it easy for people to recognise unusual requests and escalate quickly, while technical controls reduce reliance on perfect human behaviour.