Someone on your team clicked a link they should not have clicked. They told you — or they told a coworker who told you. The useful response is boring and fast. The expensive response is shame, a wipe-from-orbit, and waiting overnight “to see if anything happens.”
This is a first-hour playbook for Lincoln, Omaha, and Midwest offices. It is generic. It does not describe a named client. It is not legal advice and it is not a substitute for your incident plan or your carrier’s instructions. If you already have a managed security partner, call them first.
If email is simply down rather than hostile, use outage vs compromise instead of this list.
Need a human on the line? 531-625-2111 routes 24/7 for suspected compromise. After the fire: Get Your Free Security & IT Assessment.
What does a “phishing click” usually look like in a real office?
It is rarely a skull-and-crossbones page. It is a shared-file notification, a voicemail-to-email, a shipping exception, a DocuSign lookalike, or a “your password expires tonight” banner that opened a login form. The user may have typed a password. They may have only clicked. They may have opened an attachment. Those are different jobs, which is why the first questions are factual: what did they click, what did they type, what did the browser do, which account was signed in, and what time.
Thank them. Shame trains the next person to hide it until finance wires money.
What are the 6 things to do in the first hour?
1. Capture facts without turning it into a deposition
Write down: approximate time, the URL if still visible, whether credentials were entered, whether an attachment or macro ran, and which mailbox / VPN / SaaS app they were in. Screenshot the message headers if you can do it quickly. Do not forward the lure to the whole company “as a warning” from the affected mailbox — that is how you spread it.
If the reporter is rattled, one calm sentence is enough: we would rather hear this in minute ten than in week two.
2. Isolate the device if malware is plausible — without theatrical shutdowns
If they opened an attachment, ran a macro, installed a “browser update,” or the machine is slow/popping, pull Wi-Fi and VPN. Leave the laptop powered on unless your incident lead says otherwise. RAM and EDR telemetry are more useful than a hard power-off that makes everyone feel decisive.
If it was a web click with no download and the browser looks normal, identity is still the risk. Do not skip the next steps because “nothing happened on the PC.”
Do not plug the suspect USB “to see what it is” on a working finance workstation.
3. Reset identity from a known-good device
Assume the session is hostile until proven otherwise. From a different computer or phone that you trust:
- Reset the password for the affected account.
- Revoke active sessions / sign out everywhere (Microsoft 365 and Google both have this).
- Review MFA methods. Attackers love enrolling their own authenticator and leaving yours in place so you do not notice.
- If they reuse passwords (they do), reset the ones that matter — banking, EHR, payroll — from known-good devices.
Do not perform the reset on the possibly infected PC and declare the incident closed. That is how you hand the new password to the same malware.
Program context: email security.
4. Hunt for mailbox persistence even if the laptop looks fine
A click that “did nothing” is still how mailbox takeover starts. In Microsoft 365 or Google Workspace, check:
- Inbox rules that hide, delete, or forward mail.
- Forwarding to an external address.
- Delegation / full-access mailboxes they should not have.
- OAuth apps with mail or files scopes that nobody remembers approving.
- Sent items and deleted items for mail the user did not write.
If you find forwarding or rules you did not expect, you are no longer in “phishing click” — you are in business email compromise. Preserve screenshots before you delete the rules.
5. Warn finance and vendors out-of-band if payments are in scope
If the user touches invoices, payroll, premium disbursements, or vendor ACH, pick up the phone. Use numbers you already have — not numbers in the suspicious thread. Tell them to ignore payment-change requests until you say otherwise.
Do not post a dramatic all-hands email from the affected mailbox. Do not negotiate with the sender. Do not pay a pop-up.
Clinics: billing and scheduling mailboxes are a favorite. Start from healthcare realities, not a generic “we have antivirus” claim.
6. Escalate to EDR/SOC and a human who does this during the day and at 2 a.m.
Have your EDR console (Huntress or Guardz on SAINT-managed environments) review the host before it rejoins file shares and backups. If you do not have that, you are guessing. Guessing is how a click becomes ransomware by the weekend — see the generic ransomware playbook.
Call 531-625-2111. SAINT coordinates containment from Hickman; Huntress SOC investigates endpoints 24/7 when that stack is in place. After-hours is for suspected compromise and outages, not a lecture.
Do not wait overnight to “see if it clears up.”
What should you not do in that first hour?
- Do not punish the reporter in front of the office.
- Do not reset passwords from the infected endpoint and move on.
- Do not wipe the only evidence before EDR has a look — unless you have no choice and your IR lead said so.
- Do not email the attacker to ask if this is real.
- Do not invent a press story. Facts, access, notifications.
What happens after the hour — so the next click is less likely?
Containment is not hardening. After the host is cleared:
- MFA coverage and admin-role hygiene.
- External sender tagging, forwarding audits, DMARC progress.
- Phishing simulations tied to real campaigns, not an annual video.
- Identity threat detection so a phished password is not the end of the story.
That program lives on email security and cybersecurity (Huntress or Guardz — one stack). If a carrier questionnaire is next, run /tools/insurability.
How do you tell a phishing click from “email is just down”?
If several people lost mail at the same moment, webmail fails the same way as the desktop app, and there are no strange sent items or MFA prompts, treat it as an outage first — email down in Lincoln or Omaha. If it is one user (especially finance, billing, or a provider), partners report odd mail from your domain, or you just found a forwarding rule, stay on this playbook and assume identity until proven otherwise.
Mixing the forks wastes the hour. A password reset from the infected PC during an outage does not help. Waiting overnight during a compromise does not help either.
Lincoln: Hickman-based, no storefront, same-day triage is a drive. Omaha-metro: say which building clicked; on-site is scheduled. Same number.
When the dust settles, book a free assessment so this is not a quarterly sequel. If you need a person now, call. If you need a plan, use Calendly or /#talk.
First hour, then a plan. 531-625-2111 · Free Security & IT Assessment · cybersecurity · email security.


