Incident reporting: the first 15 minutes
What to do if you clicked, entered a code, sent data, or see strange activity.
The employee reports quickly, preserves evidence, and does not hide mistakes.
Threat
Damage grows when a person is afraid, deletes traces, or quietly tries to fix the situation alone.
What to know
- An incident can be caused by a mistake, inattention, or lack of knowledge. The goal is to limit harm, not find blame in the first minute.
- Time, sequence of actions, message content, sender, links, and screenshots matter.
- If money is at risk, the first action may be contacting the bank or stopping the payment.
- If a work account is at risk, the account must be secured and IT or the responsible person informed.
Actions
- Stop the risky action and do not enter more data.
- Keep evidence: email, SMS, link, screenshot, time, and what you did.
- Report through the company’s defined channel, even when you are not sure.
- Do not trade guilt for silence. A fast report can save the company.
Workplace scenario
The first 15 minutes
An employee realises they entered a password into a fake page. They are not sure anything happened and consider waiting until tomorrow.
Think before the test
- Why does waiting increase harm?
- Which evidence should be kept immediately?
- What is first if money is at risk, and what is first if an account is at risk?
For the manager and responsible person
The best security metric is not zero mistakes. It is fast, honest, usable reporting.
- Give employees one clear incident-reporting path.
- Promise that early reporting will not be treated like concealment.
- Update course material after an incident if a new risk appears.