Phishing and business email compromise: incident response playbook
Use it when: Someone clicked a link, entered a password, opened an attachment, or a mailbox is sending messages it shouldn't.
First 15 minutes
- Reset the user's password and sign out all their sessions.
- Check the mailbox for new forwarding rules and remove them.
- Block the sender and the link at the email gateway.
- Search for the same email in other mailboxes and remove it.
Set the severity and download a first-response checklist
What the full playbook covers
- Contain (3 steps)
- Eradicate (2)
- Recover (2)
- Who to notify
- Evidence to keep
The full playbook is in the Incident Response & Business Continuity Kit with 8 more, the IR plan, a BCP/DR plan and 6 tabletop exercises.