top of page

Essentials for Phishing Incident Response

Phishing - the hackers favourite type of cyber attack

Phishing attacks are the most likely form of initial entry to an organisations system. So, it’s important that any organisation has a phishing incident response plan that can be activated when a phishing attack is confirmed.  When a possible phishing attack is discovered, organisations must act rapidly to prevent a single-clicked link from turning into an enterprise-wide breach. The response requires prompt action involving employee communication, technical assessment, and rapid containment.

1. Assessment

The most likely first alert will come from a vigilant employee who has spotted a suspicious email and reported to the IT team.  The IT team need to assess the email and confirm whether or not it is malicious by analysing the headers of the reported email to find the true sending IP, domain authentication status (SPF, DKIM, DMARC) and whether  links or attachments are malicious. If the email is confirmed as a malicious then steps to notify the organisation of the threat, establish its scale and subsequently eradicate it should be taken

2. Preventing Spread & Alerting Colleagues

The immediate goal is to stop other employees from interacting with the email

  • Issue an Immediate Out-of-Band Alert: Send a clear, concise warning via a channel less likely to be compromised by the phishing attack itself

  • Include Visual Identification: Highlight the exact sender address, the precise subject line, and include a screenshot of the email.

  • Give Clear Instructions: Tell employees exactly what to do if they see it (e.g., "Do not click links, do not open attachments, and use the 'Report Phishing' button immediately"). Emphasise if they have already clicked a link or downloaded any attachments, they must self-report to IT immediately without fear of punishment.

3. Assessing the Scale of the Threat

The security or IT team must quickly determine the scope and sophistication of the attack.

  • Search the email gateway, looking for the specific sender, subject line, or attachment hash across the entire organisation to establish how many mailboxes received the message.

  • Identify "Clickers" and Data Submission: Check network, DNS, and proxy logs to see if any internal IP addresses successfully connected to the malicious phishing URL.

4. Eradication

Once the scale and nature of attack has been established, contain both the email itself and any compromised accounts.                       

  • Use administrative tools to "hard delete" or quarantine the phishing email from all user mailboxes globally, preventing unread messages from being opened later.

  • If a users’ credential are suspected of being compromised (by entering their credentials on a fake login page, for instance):

    • Terminate all active sessions and OAuth tokens for the user.

    • Force an immediate password reset.

    • Review their account to ensure the attacker hasn’t already added a new, rogue MFA device or set up email forwarding rules to exfiltrate data silently.

  • Blacklist the sender’s domain on your email gateway. Add the malicious phishing URL to the organisations firewall, web proxy, and endpoint protection systems so that even if an employee clicks the link later, the page is blocked.

  • the phishing email contained a malicious attachment (like a malware-laden PDF or macro-enabled document) and it was opened by a user, isolate the specific device from the network to prevent the malware from moving laterally.

  • Steve Dance Managing Partner
  • Linkedin

Follow or connect with Steve,  RiskCentric's owner & founder via LinkedIn

bottom of page