Recommended Actions After an Employee Reports a Phishing Email
A repeatable response when a user reports a suspicious message — containment, investigation, and communication.
- Affected
- Email users
- Updated
- June 24, 2026
Risk summary
A reported phishing email frequently indicates a broader campaign. Prompt response limits credential theft, business email compromise, and secondary infections.
Recommended actions
- Thank the reporter — reporting culture is the control that scales.
- Search the mail environment for other recipients of the same or similar messages.
- Remove delivered copies from mailboxes where the platform supports it.
- If a link was clicked, evaluate the account and endpoint for compromise.
- If credentials were entered, initiate the suspicious sign-in response.
- Add the observed indicators to allow/block lists as appropriate.
North Shield security advisories provide general educational and operational guidance. Organizations should evaluate recommendations against their own systems, risk profile and applicable vendor instructions.
Related resources
- Responding to Suspicious Microsoft 365 Sign-In Activity
A structured response to suspicious sign-in signals in a Microsoft 365 tenant — session revocation, mailbox rule review, and access audit.
Related services
- Cybersecurity
Managed detection & response, EDR, SIEM, and continuous compliance monitoring.
Stay informed about important IT and security developments.
Receive practical technology guidance, educational security updates and new North Shield resources by email.
Frontend preview — subscription delivery is not yet connected.
Turn advisory guidance into standing controls.
North Shield can help translate this guidance into runbooks, monitoring, and automation.