A cyber incident does not begin when systems go offline or a ransom demand appears. Often the first sign is something much smaller: a suspicious login, a misdirected email, an unexpected MFA prompt, a lost device, a clicked link or a phone call that just didn’t feel right.
These early signs are valuable. When reported quickly, they give the response team more time to investigate, contain the issue, protect others and consider any contractual or legal notification requirements. Waiting for certainty can let a small event become a much larger one.
Employees don’t need to be certain an attack has happened before saying something. Reporting anything unusual, even if it turns out to be nothing, gives organisations the best chance of stopping harm before it spreads.
What should employees report?
What a useful report should include
Every little detail helps the response team act faster. Employees should explain what happened, when it happened and which account, device or data may be involved. Where it’s safe to do so, they can include the sender, subject line, phone number, link or screenshot.
They should also be honest about any action they took, whether that’s clicking, replying, downloading a file, approving a prompt, entering information or making a payment. This lets the response team give the right instructions. Evidence should not be deleted, and employees should not attempt to investigate an attacker themselves unless directed to.
Make reporting clear and blame-free
People are less likely to report quickly when the route is hard to find or when they fear being blamed for an honest mistake. Organisations should advertise one primary reporting channel and provide an alternative if normal systems are unavailable.
The response plan should define named owners, escalation thresholds and decision-making authority. It should cover triage, containment, evidence preservation, recovery and communications, including how the organisation will assess whether customers, partners, insurers, regulators or law enforcement need to be notified.
Regular exercises can reveal gaps before a real incident happens. Each report, near miss and test should feed back into practical improvements to controls, training and response procedures.
Build response capability into information security management
ISO 27001 can help organisations place incident management within a wider Information Security Management System, connecting roles, risk assessment, controls, monitoring and continual improvement.
When specialist help is required, our sister company WorkNest, has a Cyber Incident Response Team that can support organisations in responding to and recovering from cyber incidents.
A written plan is important, but confidence comes from making it usable. Clear contact routes, understood responsibilities, practised decisions and a culture that rewards early reporting are essential.
Help your people turn four simple habits into everyday action: spot the pressure, verify the person, protect accounts and data, and report concerns early.
