Employee Security Incident Reporting Instructions
Purpose
Employees should report cybersecurity concerns quickly, even when they are unsure whether something is actually an incident.
Early reporting often prevents a small problem from becoming a serious one.
Report Immediately If You Notice
- A suspicious email, message, QR code, attachment, or link.
- An unexpected MFA prompt.
- A password or account you believe may be compromised.
- A login you do not recognize.
- A lost or stolen device.
- Malware or a security warning.
- Information sent to the wrong person.
- Sensitive information shared publicly.
- A suspicious payment or bank-detail request.
- Someone impersonating an executive, colleague, customer, or vendor.
- Unusual behavior on a company device.
- An account behaving unexpectedly.
- Anything else that appears suspicious.
How to Report
Primary reporting method:
Alternative method:
Emergency phone:
If normal email or chat may be compromised, use the alternative reporting method.
What to Include
Where possible, provide:
- What happened
- When it happened
- Which device or account was involved
- What you clicked, opened, sent, or approved
- Any screenshots or suspicious messages
- Whether you entered a password
- Whether you approved MFA
- Whether money or sensitive information may be involved
What Not to Do
Unless instructed:
- Do not delete suspicious messages.
- Do not wipe the device.
- Do not attempt your own investigation.
- Do not contact the suspected attacker.
- Do not continue using a clearly compromised account.
- Do not hide a mistake.
If You Made a Mistake
Report it immediately.
Examples:
- Clicked a phishing link
- Entered a password
- Approved an unexpected MFA request
- Sent information to the wrong person
- Uploaded information to the wrong service
Security mistakes are easier to manage when reported quickly.
Practical Rule
If something feels wrong, report it.
You do not need to prove that an incident occurred before asking for help.