Complete incident response guide for phishing attacks
Stay calm and avoid clicking any links or downloading attachments from the suspicious email.
Disconnect from the network if you suspect compromise. Do not delete the email yet.
Take screenshots of the email, headers, and any suspicious activities before taking action.
Immediately notify your IT security team or incident response team.
Never provide credentials, personal information, or financial details in response to suspicious emails. When in doubt, verify through official channels.
Update email filters to block similar phishing attempts across the organization.
Reset passwords for potentially compromised accounts and enable MFA.
Perform full antivirus and malware scans on affected systems.
Enhanced monitoring for suspicious activities and potential data exfiltration.
IT Security Team: ext. 911
Incident Response: security@company.com
Management: escalation@company.com