Someone comes to your desk and says they clicked something they probably shouldn't have. Maybe they entered a password. Maybe they aren't sure. They look like they'd rather be anywhere else.

The next thirty minutes decide whether this is a non-event or the opening of an intrusion, and almost none of that work is technical. It is asking the right questions, not letting the wrong instincts run, and looking at a short list of settings in your email system.

This is written for the person who is actually standing there - the owner, the office manager, whoever people come to. Not a technician.

Start by not making them regret telling you

The single most damaging thing you can do in the first minute is react in a way that teaches everyone else to stay quiet. Reported quickly, this is usually containable. Reported three days later because somebody was embarrassed, it usually isn't.

So the first words are some version of: you did the right thing by telling me, let's sort it out. Mean it, and say the same thing afterward regardless of how it turns out. Every future incident in your business gets reported faster or slower depending on how this one goes.

What to ask them, in this order

Ask these before you touch anything. Write the answers down as they speak.

  1. What was the message, and is it still there? Ask them to leave it in their mailbox. Do not let them delete it. It is the only copy of the evidence.
  2. When did this happen? Not "this morning" - as close to an actual time as they can give you. Everything you look at afterward gets checked against that time.
  3. What did you click, and what happened next? A link that opened a page, an attachment that opened a document, a button inside a document. The answers lead different directions.
  4. Did you type anything in? A username and password is a different incident from a click alone. So is a credit card number, a bank detail, or a one-time code.
  5. Did you approve anything? This is the question people forget to ask. Did a prompt appear on their phone asking them to approve a sign-in, and did they tap approve? Did a page ask for permission to access their mail or files, and did they allow it? Did they enter a code somebody read to them over the phone?
  6. Did you reply, or do anything the message asked for? Sending a file, changing a payment detail, buying gift cards, forwarding it to a colleague.
  7. Who else got it? Almost always the answer is that they aren't the only recipient.

What not to have them do

  • Do not delete the email. You need it, and so does anyone who helps you later.
  • Do not reply to it, not even to test whether a real person is there.
  • Do not forward it around the office as a warning. Warn people by walking over or in a chat message that describes it. Forwarding puts a live link in more inboxes.
  • Do not have them change their password on the same machine if there is any chance that machine is running something it shouldn't. Do it from a different device.
  • Do not wipe or reimage the computer, and do not let anyone "clean it up" yet. If this turns into a real incident, that is destroying the record.
  • Do not power the machine down. If you think it is compromised, unplug the network cable and turn off Wi-Fi instead, and leave it running. The reasoning behind that is the whole point of the first hour of a cyber incident.

The next thirty minutes, in order

Lock the account first, before you investigate. This is the part people get backwards. Investigation takes time; an attacker with a working password does not wait for you to finish. If a password was typed into anything, reset it from a clean device and, in the same pass, sign the account out of everywhere. A password reset on its own does not end a session that is already running - the attacker stays signed in until the sessions themselves are revoked. In Microsoft 365 that is the sign-out-of-all-sessions action on the user; in Google Workspace it is the option to sign the user out of all devices.

Then look at what was changed while you were not watching. Attackers do the same small set of things immediately after they get into a mailbox, because those things buy them persistence and quiet. That list is short enough to check by hand and is covered below.

Then widen it. Find out who else received the message and whether any of them interacted with it. Your email admin tools can search across all mailboxes for a message; that search is worth doing before you assume this was one person.

Then decide whether you are done. Not by how you feel about it - by the specific conditions further down.

What to check in Microsoft 365 or Google Workspace

Both platforms expose the same handful of things. You are looking for changes you did not make.

Mailbox rules. The classic move is a rule that files incoming mail into an obscure folder, marks it read, or deletes it - so the account owner never sees the replies to messages the attacker sends. Look at every rule on the affected mailbox and confirm the user recognizes each one. A rule nobody remembers creating is not ambiguous.

Forwarding. Check whether mail is being forwarded to an outside address, both in the user's own settings and in the admin settings for that mailbox. Forwarding set at the admin level will not show up in the user's own mail app.

Connected apps and permissions. If the message led to a consent screen, an application may now hold standing access to that mailbox or file storage. That access survives a password change and survives MFA. Review the third-party apps connected to the account and remove anything unfamiliar.

Authentication methods. Look at the phone numbers, authenticator apps, and alternate email addresses registered to the account for sign-in and password recovery. An added method is how an intruder keeps an account after you reset the password. Remove anything the user does not recognize.

Sign-in history. Pull the recent sign-ins for that account around the time they gave you. You are looking for successful sign-ins from places or devices that do not fit, and for successful sign-ins that happened after the click. A failed sign-in from somewhere strange is background noise on the internet. A successful one is an incident.

Sent mail and deleted items. If the account was used, it usually shows: messages the user did not send, and an empty or recently purged sent folder.

Anything financial they touched. If the message was about an invoice, a payment, or a bank change, check whether a payment detail was actually altered somewhere - in your accounting system, with your bank, or in a reply to a customer. This is the version of the incident that costs money immediately.

When it is contained, and when it isn't

Treat it as contained when all of these are true: nothing was typed in and nothing was approved, no successful unexpected sign-in appears after the click, no rules, forwarding, connected apps or authentication methods were added, and the account has been reset and signed out everywhere as a precaution. Write it up, tell the person they did the right thing, and move on.

Treat it as not contained, and get help, when any one of these is true:

  • A password, code, or approval was given, and there is a successful sign-in you cannot account for.
  • There is a mailbox rule, a forwarding address, a connected app, or an authentication method that nobody can explain.
  • Mail was sent from the account that the user did not send.
  • Money moved, or a payment detail was changed anywhere.
  • The person who clicked has administrative access to your email system, your finance system, or your network.
  • Anything was installed, or the machine is behaving oddly - slow, unexpected windows, security software disabled.
  • You cannot tell. "I'm not sure" belongs in this column, not the other one.

The line between these two lists is not how bad it looks. It is whether anything happened that you cannot explain.

Sensitive data raises the stakes independently. If the mailbox held health information, financial account details, or personal data about customers or employees, containment is no longer the only question - whether a notification obligation was triggered is a separate determination with its own clocks, and it is not one to make casually.

What to write down

Do this while it is happening, not afterward. A page of contemporaneous notes is worth more than a careful reconstruction later, and if this becomes an insurance claim or a regulatory question, the timeline is the first thing anyone asks for.

Record: who reported it and when they reported it; when they say the click happened; what the message was and who it appeared to come from; exactly what they clicked and what they entered or approved; who else received it; every check you ran and what you found, including the checks that came back clean; every action you took and the time you took it; who else you told and when.

The clean findings matter as much as the dirty ones. "We reviewed mailbox rules and forwarding and found none" is a real finding, and six weeks later nobody will remember whether you looked.