About this module
Employees do not need to fix an incident themselves. They need to report it quickly and to the right person. This module explains what to do when something looks wrong on a laptop, in email, or on a shared drive. Learners see why deleting files, closing pop-ups, restarting devices, or warning public channels can make things worse. The lesson gives clear reporting routes: a manager, the IT help desk, or a security hotline. Fast, calm reporting is the job.
Key takeaways
You don't have to fix a security incident. You have to report it, fast, and to the right person. When something looks wrong, on your laptop, in an email, on a shared drive, your job is not to solve it. Your job is to tell someone, right away, before you're sure.
Your instinct might be to delete the suspicious file, close the pop-up, or restart the machine. Resist it. Every one of those actions can destroy the evidence I.T. needs, and can make the damage worse. Don't post about it, don't warn the group chat, and don't mention it on social media.
A public heads-up can tip off an attacker, or turn an internal issue into a public relations crisis. You have three doors, and any one of them works: your manager, who can loop in security within minutes, the I.T. help desk, by phone, email, or ticket, or your company's dedicated security hotline, built for exactly this moment. Aim for five minutes.
From the moment something feels off to the moment I.T. knows about it. Filing a report takes under two minutes. Jot down when you first spotted it, describe it in your own words, leave the screen exactly as it is, get word to I.T. or the hotline, and stick around until someone confirms they've got it.
If you're not sure whether it's really a problem, report it anyway. A false alarm costs the security team a few minutes. A missed real incident can cost the whole company far more. 'Let me check first' is how a small incident becomes a big one. Every hour you wait to report gives whoever caused it another hour to move through your systems.
Remember this: the employee who reports first is never the one we blame. You will never be in trouble for reporting too early. Here's the sequence.
Someone confirms they've received it almost right away, the security team begins working the case immediately, they may circle back with a couple of clarifying questions, and after that, you're free to get back to your day unless they need more from you. Here's how the first hour typically unfolds. Right away, you flag what you noticed.
Within five minutes, I.T. lets you know it landed. By the half-hour mark, the security team is already working to contain it. And within the hour, your manager has the full picture.
Four numbers to remember: five minutes is your target, three channels always work, zero is the number of things you should try to clean up on your own, and one is your only real job, tell someone, fast. To recap: don't investigate it, don't post about it, and report within minutes through your manager, I.T., or the hotline, whichever is fastest.
You are the fastest sensor this company has. Notice it, report it, and let the experts take it from there. Up next, we'll cover what to do with the device itself once you've made that call.



