Incident Response KitFree severity check

Phishing and business email compromise: incident response playbook

Use it when: Someone clicked a link, entered a password, opened an attachment, or a mailbox is sending messages it shouldn't.

First 15 minutes

  1. Reset the user's password and sign out all their sessions.
  2. Check the mailbox for new forwarding rules and remove them.
  3. Block the sender and the link at the email gateway.
  4. Search for the same email in other mailboxes and remove it.

Set the severity and download a first-response checklist

What the full playbook covers

The full playbook is in the Incident Response & Business Continuity Kit with 8 more, the IR plan, a BCP/DR plan and 6 tabletop exercises.

Other playbooks

Incident Response & Business Continuity Kit

More free security and AI governance tools