A convincing phishing email can reach an accounts inbox at 09:12, be opened on a mobile phone at 09:13, and trigger a payment or stolen login before the business has identified what happened. The best practices for phishing response are therefore not limited to teaching people to spot suspicious emails. They create a clear, calm process for containing an incident, protecting evidence and restoring normal operations with minimal disruption.
For most small and mid-sized organisations, the difference between a nuisance and a serious security event is the first hour. Staff need to know what to do without worrying that they will be blamed for reporting a mistake. Managers need a route to reliable technical advice. IT teams need the visibility and authority to act quickly.
Why phishing response needs a defined process
Phishing has moved well beyond poorly written emails asking for bank details. Criminals now impersonate suppliers, senior leaders, Microsoft 365 notifications, parcel firms and trusted colleagues. They use compromised accounts to send messages from real email addresses and tailor requests around public information, invoice cycles or ongoing projects.
That means prevention alone is not enough. Even well-trained staff can be caught by a convincing message when they are busy, working remotely or dealing with an urgent request. A response plan accepts that possibility and limits the impact when it occurs.
A practical plan should answer three questions quickly: what has the recipient done, what information or access may have been exposed, and what action will prevent the attacker from moving further? It should be proportionate. An unopened suspicious email requires a different response from a message that has led to a password being entered, a malicious attachment being opened or money being transferred.
Best practices for phishing response in the first hour
The first priority is containment, not a lengthy investigation. Ask the person affected to stop interacting with the message. They should not reply, forward it to colleagues or click links again to check whether they work. They should report it through the organisation’s agreed route, ideally using an email-reporting function or a dedicated service desk contact.
If they entered a password after following a link, their password should be reset immediately from a known-safe device. Active sessions should be revoked where possible, and multi-factor authentication should be checked for unfamiliar prompts, newly registered methods or changes to recovery details. If the account has elevated permissions, the urgency is greater, as access may extend beyond one mailbox.
If a file was opened or software was downloaded, disconnect the device from the network where this can be done safely. Do not switch it off immediately unless directed by IT or a security specialist. Keeping the device powered on can preserve useful evidence, while network isolation can reduce the chance of malware spreading to shared folders or other systems.
For a suspected payment diversion fraud, contact the bank without delay using a trusted number, rather than any contact details in the email. Notify the supplier through an established channel as well. Speed matters, but so does verification: it is common for attackers to continue impersonating both parties while the incident is being resolved.
The response team should then establish the scope. Review the reported message, who else received it, whether anyone else clicked, and whether similar messages were sent from internal accounts. In a Microsoft 365 environment, this often includes checking sign-in activity, mailbox forwarding rules, sent items, deleted items and suspicious OAuth application consent. Attackers frequently set rules to hide replies or forward finance-related correspondence after compromising an account.
Preserve evidence without slowing down containment
It is tempting to delete the email and move on once an account is secured. That can remove clues needed to understand the incident and protect others. Preserve the original message, including headers where available, along with screenshots, affected usernames, timestamps, URLs, attachments and any payment details used.
This information helps determine whether the incident is isolated, part of a wider campaign or connected to an account compromise. It may also be needed for insurers, banks, regulators, law enforcement or contractual discussions with customers and suppliers.
Evidence preservation should not become an excuse for delay. Password resets, access revocation and banking escalation take priority. The aim is to gather sufficient information while the technical team blocks the threat and confirms that the organisation remains in control.
Communicate clearly and avoid unnecessary alarm
A phishing response is an operational issue as well as a technical one. If a message has reached multiple people, a short internal alert can prevent further clicks. It should describe the sender, subject line and expected action in plain English. Avoid circulating the malicious link or attachment unnecessarily.
The tone matters. A message that shames the person who reported the email will discourage future reporting. Staff should hear that rapid reporting is the right action, including when they have clicked a link or entered information. A culture of early disclosure gives the organisation more time to contain risk.
Where customer, employee or supplier data may be involved, senior management should be informed early. The organisation may need advice on data protection obligations and whether a report to the Information Commissioner’s Office is required. That decision depends on the nature of the data, the likely impact on individuals and the controls already in place. It should be evidence-led, rather than assumed either way.
Remove the route the attacker used
Once the immediate incident is contained, identify the weak point that allowed it to succeed. It may be a reused password, missing multi-factor authentication, an overly permissive mailbox setting, a lack of payment verification, an unpatched device or simply a process that made an urgent-looking request believable.
This is where a phishing incident can produce useful improvement rather than repeated disruption. A sensible review may result in better email filtering, conditional access policies, stronger account monitoring or a clearer process for changing supplier bank details. For example, finance teams should verify changes to payment instructions by calling a known contact, not by replying to the email that requested the change.
Training should be targeted too. Sending every employee the same generic reminder after an incident rarely changes behaviour for long. If the attack impersonated a senior manager, explain the signs that were present and rehearse the verification route. If it used a fake Microsoft 365 sign-in page, show staff how to check the web address and encourage them to report unexpected authentication prompts.
Test the process before a real incident
A phishing response procedure only works if people can use it under pressure. Test it with a short tabletop exercise involving leadership, finance, operations and IT. Use a realistic scenario, such as a compromised colleague requesting an urgent payment or a staff member entering credentials into a fake cloud sign-in page.
The exercise should expose practical questions. Who has authority to freeze payments? Who can reset accounts outside normal working hours? How are remote devices isolated? Which supplier contacts are verified? Where is the incident log kept? These details are often more valuable than a lengthy policy document.
Review the process after every exercise and every real event. Contact lists change, systems change and attackers change their methods. A good plan stays simple enough to follow, but specific enough to guide decisions when time is limited.
When to bring in specialist support
Some incidents can be handled internally, particularly when a suspicious email has been reported before anyone interacts with it. Others need deeper investigation. Bring in specialist support when credentials may have been compromised, malware may be present, sensitive data may have been accessed, fraudulent payments have been made or there are signs that an attacker has gained persistent access.
An experienced managed IT and cybersecurity partner can help investigate sign-in activity, secure accounts, assess affected devices, preserve evidence and restore services in an orderly way. The value is not simply technical capacity. It is having a response that protects uptime, gives decision-makers clear information and avoids costly guesswork at a stressful moment.
The most useful phishing response plan is one your people trust enough to use immediately. Make reporting easy, treat early disclosure as a positive action and practise the decisions that matter before an attacker forces them. That is how security becomes a source of operational confidence rather than another source of disruption.

