Skip to content
Severity: MediumSecurity Advisory

Recommended Actions After an Employee Reports a Phishing Email

A repeatable response when a user reports a suspicious message — containment, investigation, and communication.

Affected
Email users
Updated
June 24, 2026

Risk summary

A reported phishing email frequently indicates a broader campaign. Prompt response limits credential theft, business email compromise, and secondary infections.

Recommended actions

  1. Thank the reporter — reporting culture is the control that scales.
  2. Search the mail environment for other recipients of the same or similar messages.
  3. Remove delivered copies from mailboxes where the platform supports it.
  4. If a link was clicked, evaluate the account and endpoint for compromise.
  5. If credentials were entered, initiate the suspicious sign-in response.
  6. Add the observed indicators to allow/block lists as appropriate.

North Shield security advisories provide general educational and operational guidance. Organizations should evaluate recommendations against their own systems, risk profile and applicable vendor instructions.

Related resources

Related services

  • Cybersecurity

    Managed detection & response, EDR, SIEM, and continuous compliance monitoring.

Stay informed about important IT and security developments.

Receive practical technology guidance, educational security updates and new North Shield resources by email.

Frontend preview — subscription delivery is not yet connected.

By subscribing you agree to receive occasional updates from North Shield. See our privacy notice (placeholder). You can unsubscribe at any time.

Need help operationalizing this?

Turn advisory guidance into standing controls.

North Shield can help translate this guidance into runbooks, monitoring, and automation.