4. Responding and reporting
Reporting: fast, easy, and blame-free
Why minutes matter
When phishing succeeds, the attacker starts working immediately: using stolen credentials, establishing persistence, reading email, and preparing fraud. Every minute between the click and the report is time they work unopposed. Report within minutes and IT can reset the password, revoke sessions, block the malicious site, and pull the same email out of everyone else's inbox before the next person clicks. Report the next day and the attacker may already be several steps ahead.
Your report also protects colleagues. Phishing rarely arrives to just one person, so the first reporter effectively raises the alarm for the whole organisation. One prompt report can end a campaign before it does any damage at all.
No blame, no shame
Here is the cultural point this whole course depends on: falling for a well-built phishing attack is not a sackable offence, a mark of stupidity, or something to hide. It is an expected event that security teams plan for. The NCSC's guidance to organisations is explicit that punishing people for clicking makes security worse, because staff who fear blame stop reporting, and unreported incidents are the ones that become disasters.
So the deal is simple: report fast and honestly, including the embarrassing details like "I entered my password", and the organisation's job is to fix the problem, not to blame you. A fast reporter who clicked has done more for security than a silent person who did not.
How to report
Inside the organisation, use the report or "report phishing" button in your email client if one is available, as it alerts the security team and improves filtering for everyone. Otherwise, contact your IT team or service desk directly through the usual channel. If you are unsure whether something even is phishing, report it anyway and let the specialists decide.
You can also report to national services that take attacks down at source:
- Forward suspicious emails to report@phishing.gov.uk, the NCSC's Suspicious Email Reporting Service, which analyses reports and removes malicious sites
- Forward suspicious text messages to 7726, a free service that lets mobile providers investigate and block scam numbers
These national reports take seconds and genuinely lead to takedowns. They complement, not replace, reporting to your own IT team.
› Course contents
How social engineering works
Spotting phishing emails
Beyond email
Responding and reporting