Phishing is still the opening move behind most ransomware and BEC losses we see regionally. The good news: a fast, boring response usually beats a heroic cleanup three days later.
When a user reports a click
- Thank them. Shame trains people to hide the next one.
- Isolate if warranted. If they opened an attachment, ran a macro, or the browser behaved strangely, pull the device off the network and leave it powered on for forensics/EDR rather than “nuking from orbit” immediately.
- Reset the identity path. Password + sessions + MFA methods. Attackers love quiet persistence in the mailbox even when the laptop looks fine.
- Scan for follow-on mail. Compromised accounts often send the same lure to contacts within hours.
- Let detection finish. Managed EDR / SOC review should clear the host before it rejoins file shares and backups.
Prevention that isn’t annual checkbox training
Simulations and short training tied to real campaigns beat a once-a-year video. Pair that with tenant hardening (external tags, safe links where licensed, DMARC progress) and identity threat detection. See email security and our default Huntress stack for how SAINT packages that.
Clinics and therapy practices: phishing often hits schedulers and billing first — start with behavioral health IT and HIPAA-aligned email hardening, not a generic “we have antivirus” claim.
Urgent? Call 531-625-2111. Non-urgent hardening: book an assessment via contact.
Lincoln and Omaha
Same number, same Huntress-backed stack. Lincoln is a primary market (Hickman-based, no storefront). Omaha-metro is multi-site more often — say which building clicked. If email is simply down, use the outage vs compromise fork instead of this playbook.


