Thought Leadership

You Just Had a Phishing Scare. Here’s What to Do in the Next 30 Days.

September 1, 2026

The email looked real enough to fool someone smart. Someone clicked, replied, opened an attachment — or caught themselves halfway through.  

Now everyone is asking the same question: What do we do? 

A phishing scare needs a prompt response, but it does not need panic. Whether your company almost fell for a phishing email or someone clicked before realizing what it was, the first steps are the same: Get the facts, limit exposure, and give the response a clear owner. 

This small business phishing incident checklist covers what to do after a phishing attack or near miss, from the first few hours through day 30. It will help you handle the immediate issue, close the gaps it revealed, and give your people a simpler way to act the next time something feels off.  

Phishing scare next steps: Find out what happened in the first few hours

Start with the person who received the email. Keep the conversation matter-of-fact and leave blame out of it. Right now, accuracy matters more than how obvious the warning signs may seem in hindsight. Ask what they remember:  

  • When did the message arrive?
  • Who appeared to send it?
  • Did someone click a link or open an attachment?
  • Did they reply or share a password, payment information, or other sensitive data? 
  • Did they approve a sign-in request? 
  • Did they download or install anything?  
  • Did anything unusual happen afterward? 

Ask your employee not to delete the email. Your IT contact or managed service provider (MSP) may need the original message to review its sender, links, and attachments.  

If no one interacted with the message, report it through your company’s normal channel and remove it from affected inboxes. If someone clicked, replied, shared information, or opened a file, move directly into response mode. This is where your phishing incident response begins:  

Secure anything that may have been exposed and document every action you take. 

Next action: Write down what happened, when it happened, and which accounts, devices, or information may be involved. 

Day 1: Protect what may have been exposed

What you do next depends on what happened.  

If a password has been compromised, change it using the real website or app. Do not return to the link in the email. If that password was used elsewhere, change it there, too.  

Then, review the affected account for:  

  • Sign-ins from unfamiliar devices or locations 
  • Unexpected password or recovery-setting changes 
  • New email forwarding rules 
  • Messages the employee did not send 
  • Unexpected payment, payroll, or banking changes 
  • Multi-factor authentication prompts the employee did not initiate 

If an attachment was opened, a file was downloaded, or the device is behaving unexpectedly, contact your IT provider or MSP. Tell them exactly what was opened and when. They can inspect the device and decide whether it should be disconnected from the company network.  

If financial information was shared or a payment was sent, contact the bank or payment provider immediately through a trusted phone number. Ask what can be stopped, recalled, or monitored.  
 
Do not reply to the supposed sender through the email itself. If the message appears to come from a vendor, executive, or colleague, contact them through a phone number or communication channel you already trust.  
 
Next action: Change exposed credentials, review the affected accounts, and place one person in charge of coordinating the response.  

Days 1-2: Put one person in charge

A 50-person company doesn’t need an incident response committee. It needs one name on a whiteboard.  

Choose one response lead. This may be an IT manager, office manager, operations leader, owner, or outsourced MSP. This person keeps the work moving and records what your company has checked, changed, and still needs to do. Depending on the incident, bring in: 

  • Your internal IT contact or MSP 
  • The employee’s manager 
  • A company owner or senior operations leader 
  • Finance, if money or financial accounts were involved 
  • Human resources, if employee information was exposed 
  • Your cyber insurance provider, if you have one 
  • Legal counsel, if sensitive company, customer, or employee information may have been accessed

Not every phishing scare requires company-wide communication. Tell people what they need to know for the role they will play. If other employees received the same message, send a short internal notice showing them how to recognize and report it. 

Keep the tone neutral: “We identified a suspicious email and are reviewing it. If you received a similar message, report it without clicking, replying, or forwarding.” 
 
Clear. Calm. Useful. 
 
Next action: Name the response lead and tell each person involved exactly what you need them to do.   

Days 2-3: See whether it went beyond one inbox 

The email someone reported may be the only copy. It may also be sitting in 40 other inboxes.  

A coworker won’t think twice about a request from someone they’ve sat next to for three years, even when that account isn’t really them anymore. 
 
Ask your email administrator or MSP to search for messages with the same sender, subject line, links, or attachments. Remove matching emails where possible.  
 
Next, check whether the affected account sent any messages the employee does not recognize. An email from a real company account can be especially convincing to coworkers, customers, and vendors. 
 
If the account sent suspicious messages:  

  1. Secure the account
  2. Remove unfamiliar forwarding rules or connected apps 
  3. Identify the recipients
  4. Tell them what to disregard and how to contact you through a trusted channel

Keep a simple incident record as you go. Include dates, what you found, what you changed, who owns each follow-up, and what remains unresolved. This record will be useful once the details start to blur, and the rest of the workday takes over. 

Next action: Confirm whether the message or affected account reached anyone else, then record what you found.  

Days 4-7: Fix the gaps the incident exposed

Once the immediate issue is under control, it’s time to move from response to readiness.  

A phishing scare often reveals small gaps with clear fixes. Start with the changes that would have made this incident easier to prevent, report, or contain:  

  • Turn on multi-factor authentication for important accounts
  • Replace reused passwords with unique ones  
  • Confirm that the company devices receive regular updates 
  • Review access to email, payroll, financial, and customer systems 
  • Remove access that former employees no longer need 
  • Check that important company data is backed up 
  • Give employees one obvious way to report a suspicious email  

Reporting is often the simplest place to improve. Give someone three steps to report a suspicious email and most people will do two of them, then get pulled into a meeting.   

Choose the three changes that matter most. Give each one an owner and a date rather than letting all three become “something IT should look at.”  

Next action: Choose three improvements and give each one an owner and due date. 

Week 2: Write a one-page plan

A small business phishing response plan should be useful on a busy Tuesday afternoon. Think of it as an incident response plan for your small business, not a technical manual. 

Your plan should answer five questions:  

  1. How should an employee report an email? Choose one method and make it easy to find. 
  2. Who receives the report? Name a primary contact and a backup. If an MSP handles reports, include the correct contact information.
  3. What details should you collect? Record who received the message, when it arrived, what they did, and which accounts or information may be involved.
  4. Who can make the decisions? Clarify who can reset an account, inspect a device, contact the bank, notify leadership, or communicate with customers.
  5. Where do you record the response? Keep one incident record with dates, actions, owners, and unfinished work.  

Once the page is written, test it with the question someone will actually ask: “Someone at my company clicked a phishing link. Now what?” The answer should be immediate: Report the email, change any exposed password, and contact the person responsible for reviewing the account or device. 

If the answer is obvious, the plan is already doing something useful. 

Next action: Save the one-page plan somewhere your team can find it quickly. 

Week 3: Make it easier to speak up

The person who reports a suspicious email quickly gives your company more time to respond. That is true even if they already clicked. The same principle applies when the employee catches the message in time. Knowing how to respond to a phishing near-miss helps you improve the process before a real loss occurs.  

How you handle this incident will influence what happens next time. If your employee feels embarrassed or blamed, coworkers may decide to stay quiet when they make a similar mistake.  

Thank the person for reporting it. Then, give the rest of the company a short refresher built around useful actions:  

  • Pause when a message creates unusual urgency 
  • Confirm payment and account-change requests through another trusted channel 
  • Do not approve a sign-in prompt you did not initiate 
  • Report suspicious emails, even after clicking 
  • Ask for help instead of investigating the message alone 

Employees do not need a crash course in email forensics. They need to recognize when something feels wrong and know exactly where to send it.  

Next action: Have every employee practice using the reporting method.

Week 4: Keep up the momentum 

At the end of the month, bring the response lead and task owners together for a short review. Ask a few direct questions:  

  • Does everyone know how to report a suspicious email?  
  • Do those reports reach someone who can act?  
  • Is there a backup contact?  
  • Are important accounts protected with multi-factor authentication?  
  • Does every unfinished task still have an owner? 
  • When will the company review this plan again?  

Keep measurement simple. You don’t need a metrics dashboard. You need three numbers: How many people reported something, how fast someone looked at it, and how many follow-ups actually got closed. 

Then, schedule another check-in for 60 or 90 days from now. Put it on the calendar while everyone is still in the room.  

Next action: Close the remaining tasks and put the next review on the calendar.   

Small business phishing incident checklist: The first 30 days

Use this phishing attack recovery checklist to confirm that the immediate response is complete and that the follow-up work has an owner.   

In the first 24 hours:  

  • Record what happened 
  • Preserve and report the email
  • Change exposed passwords 
  • Review the affected accounts 
  • Contact IT, your MSP, the bank, or other partners as needed 
  • Give the response one clear owner 

During the first week:  

  • Search for other copies of the message 
  • Check whether the affected account sent anything unusual 
  • Secure the accounts and devices involved  
  • Choose the three most important improvements 
  • Assign an owner and deadline to each 

During the rest of the month: 

  • Write a one-page response plan 
  • Give employees one reporting method 
  • Reinforce quick, blame-free reporting 
  • Confirm responsibilities with leadership and your MSP 
  • Review what changed and schedule the next check-in 

Make the next report easier

The goal is not to turn every employee into a phishing expert. The goal is to make sure they recognize a questionable moment and know what to do with it.  

When something looks wrong, people hesitate. Not because they don’t care, but because reporting usually means stopping, explaining, and hoping they’re not overreacting. NINJIO ALERT turns that hesitation into one click, right inside the inbox.   

Ready to reduce your organization’s human risk?