How to Prepare a Phishing Response Plan for Work

How to Prepare a Phishing Response Plan for Work

A suspicious email lands in a member of staff’s inbox at 9:12am. It appears to be from Microsoft, a supplier or the managing director. By 9:18am, somebody has entered their password into a convincing fake sign-in page.

The difference between a contained incident and a costly business disruption is rarely just the email itself. It is whether your team knows exactly what to do next. Knowing how to prepare a phishing response before an incident happens gives your business the best chance of stopping account theft, fraudulent payments and ransomware before they spread.

Why a phishing response plan matters

Phishing is no longer limited to poorly written emails promising a prize. Criminals research businesses, copy supplier branding, impersonate senior staff and use genuine-looking login pages to steal credentials. They may send an invoice request to finance, a shared-document alert to an office manager or a password-reset message to every employee.

For a small business, the immediate concern is often the lost time. Staff stop work, systems may need to be checked and customers may be affected. The bigger risk is what happens after a password is captured. An attacker may access email, reset other passwords, search for bank details, send messages from a trusted account or use stolen information to target clients and suppliers.

A response plan turns panic into a set of sensible actions. It tells staff who to contact, gives decision-makers a clear route to follow and makes sure the right technical checks happen quickly. It also helps you preserve evidence and communicate calmly, rather than making rushed decisions with incomplete information.

How to prepare a phishing response plan

Your plan should be short enough to use under pressure. A document hidden in a long policy folder will not help the person who has just clicked a link. Start with a one-page staff procedure, then support it with a more detailed technical and management playbook.

Define what staff should report

Employees should report more than obvious phishing emails. Ask them to raise anything that seems unusual: a login prompt they did not expect, a supplier changing bank details, an email sent from a colleague’s account that feels out of character, or a message asking for urgent gift cards, payroll data or passwords.

Make reporting easy. Give staff one clear route, such as a dedicated email address, a ticket option or an agreed phone number for urgent concerns. They should know they will not be blamed for reporting something that turns out to be harmless. Fast reporting is far more valuable than silent embarrassment.

The initial staff instruction can be simple: do not reply, do not forward the message to colleagues, do not click anything else, and report it. If they have already entered a password or opened an attachment, they should say so immediately. That detail changes the response.

Agree severity levels before you need them

Not every suspicious email needs the same response. A clearly fake delivery notification that was reported before anyone interacted with it may only require blocking and awareness. A staff member who entered credentials into a fake Microsoft 365 page needs urgent account protection. A fraudulent payment request that was acted upon may require contact with the bank, insurers and potentially affected parties.

Set practical severity levels that match your business. For example, distinguish between a suspicious message, a clicked link with no credentials entered, a suspected credential theft, and a confirmed compromise involving financial or sensitive data. For each level, state who owns the incident and how quickly they must act.

This is particularly useful where you have an internal IT person, an outsourced provider and senior managers. Nobody should lose time wondering whether it is their responsibility to make the call.

Document the first 30 minutes

The first half-hour often matters most. Your response plan should set out the immediate actions in order, including who can authorise them. In most cases of suspected credential theft or malware, the priorities are to contain the risk, secure the account and understand what has happened.

Your technical team may need to:

  • reset the affected user’s password and revoke active sign-in sessions
  • check and strengthen multi-factor authentication
  • isolate a device if an attachment or download may be involved
  • review recent email rules, sign-ins, password resets and forwarding settings
  • search for similar messages or compromised accounts across the organisation

There is a trade-off here. Resetting passwords or disabling accounts can briefly interrupt work, but delaying action can give an attacker more time to establish access. Your plan should favour safe containment, while ensuring the affected employee has a clear route back to work once their account and device have been checked.

Protect the evidence without spreading the threat

Avoid deleting the original email immediately. It can contain useful information for tracing the attack, blocking related messages and understanding whether other staff received the same campaign. Capture the sender address, subject line, recipients, time received, any links or attachments, and screenshots of suspicious login pages if this can be done safely.

At the same time, do not ask staff to forward malicious messages around the business. Forwarding can trigger links, create confusion and make it harder to identify the original. Your IT provider can safely inspect message headers and technical details where required.

Keep a basic incident record. Note who reported it, what they did, which accounts or devices were affected, when key actions were taken and what was communicated. This record is useful for insurance, compliance questions and improving your defences afterwards.

Build the right people into the response

A phishing incident is not only an IT issue. Technology staff need authority to contain accounts and devices quickly, but management may need to decide how to communicate with customers, suppliers, insurers or regulators. Finance teams should have a separate, tested process for payment changes and urgent money requests.

Name a primary incident lead and a deputy. Include contact details that work outside normal office hours if your business depends on email, cloud systems or online transactions. Decide in advance when the managing director, finance lead, data protection contact and external IT support should be involved.

For many Sussex businesses, this is where a managed IT partner provides real value. My Tech Team can act as an extension of your team, helping contain the technical threat while giving business leaders clear, plain-English updates on what is known, what is being checked and what should happen next.

Reduce the chance that one email becomes a major incident

Response preparation works best alongside sensible prevention. Multi-factor authentication is one of the most effective controls because a stolen password alone is less likely to be enough for an attacker. It should be enabled across email, cloud storage, finance platforms and remote access, with stronger methods such as authenticator apps or security keys considered for higher-risk accounts.

Email filtering, device protection and software updates add further layers, but they do not remove the need for staff awareness. Run short, regular phishing training using examples relevant to people’s roles. A finance team should recognise invoice fraud. A charity may need to spot fake donation or grant communications. An automotive business should understand the risks around supplier accounts and specialist systems.

Training should not be a once-a-year box-ticking exercise. Brief reminders, simulated phishing tests and conversations after real reports help staff build confidence. The aim is not to catch people out. It is to create a culture where pausing and checking is normal.

Test the plan with a realistic scenario

A plan that has never been tested may look fine on paper but fail when people are busy. Choose a straightforward scenario: an employee reports that they entered their Microsoft 365 password after clicking a link in a fake shared-file email. Ask the people involved to talk through their actions, timings and decisions.

Can the employee report it quickly? Does the incident lead know who to call? Can IT revoke sessions and check sign-in activity? Does finance know how to handle a supplier payment request sent from the affected mailbox? These questions reveal gaps without needing a live incident.

Test at least annually and after significant changes, such as moving to a new email platform, introducing new finance software or changing your IT support arrangements. Update the plan after every real event too. Small improvements, such as a clearer reporting address or a better out-of-hours contact process, can make a meaningful difference.

A phishing response plan is not about expecting the worst from your staff. It is about giving good people a calm, practical way to protect the business when a convincing message gets through. When everyone knows their role, your technology is far more likely to keep working while the threat is dealt with.

More to read

Related Topics

A practical charity technology planning guide for stronger security, better use of grant funding and reliable day-to-day services for your team in Sussex.

You do not need to open up your computer, or know anything about circuit boards, to find out what motherboard it has. Windows already knows,

What does IT support cost? See typical UK pricing, what changes your monthly fee, and how to choose support that protects productivity, security and budgets