A step-by-step response plan for the first hour after a phishing click — password resets, session revocation, inbox rules, and when to call for help.
Someone on your team clicked a link they shouldn't have — or worse, typed their password into a page that looked exactly like Microsoft 365. What you do in the next hour matters more than what the attacker did. Here's the playbook.
The most dangerous phishing click is the one nobody reports. If your culture punishes the person who clicked, the next incident stays hidden until it's a breach. Make it loudly known: reporting fast is the win condition.
Beyond the immediate cleanup: reviewing sign-in logs for unfamiliar locations and devices, checking whether anything was forwarded or downloaded, confirming no new app permissions or account delegations were granted, and screening for the same message across every other inbox in the organization — phishing rarely targets just one person.
Layered defenses turn this from a crisis into a logged incident: email security that stops most malicious messages before delivery, endpoint detection that catches what runs after a bad click, a 24/7 response team watching identity sign-ins, dark web monitoring for credentials that leak anyway, and ongoing phishing training so fewer messages get clicked in the first place.
If you're reading this mid-incident and don't have a response team, call us at (844) 247-5227 — the emergency line is answered.
Talk to our team — we'll give you a straight answer, even if the answer isn't AIS.