Skip to content
Security,AppliedContact the desk
Browse sectionsAct NowAccounts & IdentityDevices & DataSmall TeamsField NotesSecurity Action Index

Small Teams

Small business phishing reporting process

Create one low-friction reporting door and a response that does not blame staff.

A colleague forwarding a suspicious message to a shared security inbox

Create one low-friction reporting door and a response that does not blame staff. This guide starts with actions that are low-risk, reversible where possible, and useful even when the exact cause is still uncertain. If there is an immediate financial, workplace, safety, or legal concern, use the responsible provider or local authority’s current process.

First ten minutes

  1. 01
    Pause before deleting or resetting

    A rushed clean-up can remove the detail that makes recovery easier.

  2. 02
    Record the time, what changed, and the account or device involved

    A short note is often more useful than a perfect reconstruction later.

  3. 03
    Use a trusted route to the relevant provider or team owner

    Open saved bookmarks, device settings, or official support pages rather than links from an alert.

What to preserve

Keep the message, notice, filename, time, affected address or device name, and screenshots of unusual settings if doing so is safe. Do not send passwords, recovery codes, private keys, or unredacted identity documents to an unverified contact. A record supports a provider or team that needs to understand what happened.

Escalate when

Escalate when access cannot be recovered through an official route, a payment method or sensitive data may be involved, the event affects a workplace, or you are being pressured to act quickly. The appropriate destination might be an account provider, bank, employer, insurer, qualified incident responder, or public reporting route in your jurisdiction.

Recovery path

After containment, review recovery options, active sessions, forwarding rules, software updates, backups, and credentials reused elsewhere. Make one change at a time when you can, then write down what was changed. That record helps you avoid repeating work and gives a small team a usable handover.

Volunteer web teams usually report a suspicious message to a shared mailbox rather than to a security desk. Volunteer web team security applies the same reporting pattern to the accounts that carry a church site and its mail.

Reporting a phishing email is one half of the job. The other half is understanding how the message moved, and how the systems around it are kept running. The same questions of planning, handover and standard procedure appear in other domains, including the air. A short page on boom and probe-and-drogue refuelling explains how tanker aircraft transfer fuel in flight, how the two methods differ, how tanker fleets are organised, and why mission planning and standardisation matter. It is a useful read for anyone who wants to see how a routine, high-consequence transfer is made repeatable.

Related dispatches

Church website security for volunteer teams · Small business grants in Scotland and the records they require · Cybersecurity incident first steps · How Security, Applied works