Reporting Security Incidents

About this module

When a security incident starts, the first five minutes decide whether it stays contained or becomes a major breach. This incident reporting training module trains your response.

You'll learn the four warning signs: unexpected login alerts, emails you didn't send, files that won't open, systems behaving strangely, and the three-step drill that follows: stop and disconnect, document what you saw, and contact IT Security on a number you already know.

Unreported breaches take an average of 277 days to identify and contain; reported ones cost dramatically less. By the end you'll act on instinct: false alarms cost nothing, silence costs everything.

Key takeaways

  • Unreported breaches take an average of 277 days to identify and contain
  • Stop. Document. Contact. In that order, every time
  • Never reboot a compromised machine: it destroys forensic evidence
  • You will not be penalized for reporting: false alarms cost nothing

Full Transcript

When a security incident occurs, every minute matters. What you do in the first five minutes, whether you act or wait, can be the difference between a contained incident and a major breach.

When incidents go unreported, the average time to identify and contain a breach is two hundred and seventy-seven days. Reported immediately, that number drops dramatically, and so does the cost.

Every hour an attacker spends undetected inside your network, they move deeper, access more systems, and cover their tracks. Fast reporting is the only thing that stops dwell time from becoming catastrophic damage.

Sign one: unexpected login notifications. If you receive an alert that your account was accessed from an unfamiliar location or device, report it now.

Sign two: emails sent from your account that you didn't write. This means someone has access to your account and is using it.

Sign three: files you can't open or that look encrypted or renamed. This is a classic sign of ransomware in progress.

Sign four: your system is unusually slow, programs crash, or settings change without your action. Something may be running in the background.

Any one of these: report it immediately. Even if you think it's nothing.

First: stop. Stop what you're doing immediately. Disconnect from the network: unplug the cable or turn off W-i-fi.

Do not shut down or restart. That destroys forensic evidence.

Second: document. Note the time, exactly what you observed, and any actions you took. Take screenshots of anything on screen.

Don't delete files or clear your browser history.

Third: contact. Call I.T. Security immediately using a number you already know, not one from the suspicious message.

Report everything you documented. You will not be penalised for reporting. Stop.

Document. Contact. In that order, every time.

Critical: do not reboot, it destroys evidence. Do not delete files. Do not tell colleagues before I.T. has been notified.

Do not attempt to fix it yourself. And never pay a ransom without I.T. guidance.

The fastest way to limit breach damage is also the simplest: pick up the phone and report it. False alarms cost nothing. Silence costs everything.

If something feels wrong, report it. Right now. Don't wait.

Don't second-guess. Module Ten covers cybersecurity dos and don'ts to close out the course.