Join our Newsletter — 33% off our NHI Course

What should employees do after they suspect a phishing email but before they interact with it?

Employees should avoid clicking links or opening attachments, verify the request through a separate trusted channel, and alert IT or security immediately. Fast reporting gives defenders a chance to investigate, contain the message, and protect other users. If credentials may have been exposed, the response should include password changes and access review as soon as possible.

Pause, Verify, and Report Before You Interact

The safest next step is to stop interacting with the message and treat it as potentially hostile until proven otherwise. A separate trusted channel, such as a known phone number or internal chat that is not linked from the email, is the right way to confirm whether the request is real. Immediate reporting matters because it preserves evidence and lets security teams contain the message before others respond to it.

One practical habit is to assume the first visible detail may be the attacker’s hook, not proof of legitimacy. Link text, sender display names, reply-to tricks, and attachment names can all be manipulated to create urgency. If the message reached a shared mailbox, distribution list, or business process, the reporting step should happen even faster because the blast radius is larger.

What to Do If You Already Exposed a Secret

If the message was only suspected, the response is simple: do not click, do not open, and do not reply. If an employee already entered a password, opened a file, or approved a prompt for authentication, the situation changes from suspicion to potential compromise. At that point, password reset, session review, and account access review become time-sensitive actions rather than optional cleanup.

Fast containment is more important than trying to prove with certainty whether the email was malicious first. Security teams can inspect headers, quarantine similar messages, search for recipients, and look for follow-on activity, but employees should not wait for that analysis before reporting. The earlier the alert, the more likely defenders can stop token theft, mailbox rules abuse, or lateral phishing before it spreads.

Why Trusted-Channel Verification Is the Deciding Step

Trusted-channel verification is the control that breaks the attacker’s control over the conversation. A phishing email often tries to move the victim into the attacker’s preferred channel, such as a fake login page, a malicious document, or a fraudulent payment workflow. Verifying through a known-good route preserves decision quality because it avoids using the compromised message itself as the source of truth.

That verification should be specific, not casual. Employees should confirm the request with the named requester, the help desk, or the business owner using contact details already stored in an approved directory or internal portal. If the message claims urgency, payment, credential reset, or document review, the urgency itself is a warning sign, not a reason to accelerate interaction.

Risk and Threat Considerations

Phishing is dangerous because a single interaction can create immediate exposure through credential theft, session hijacking, or malicious code execution. Even when the first click does not fully compromise the account, it can give defenders too little time to stop inbox rules, token replay, or secondary delivery to colleagues.

Failure mechanism: The attacker relies on the employee to move from suspicion to interaction before verification happens, then uses the resulting trust step to capture credentials, tokens, or malware execution.

Impact: The organization can face account takeover, unauthorized access to mail or business systems, and wider internal spread if the same lure is forwarded or reused.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while NIST SP 800-53 Rev 5, NIST CSF 2.0 and OWASP ASVS set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
MITRE ATT&CK T1566 — Phishing Phishing is the core attack pattern behind the question.
Recommendation — Map suspicious email handling to T1566 detection and user-reporting workflows.
NIST SP 800-53 Rev 5 AU-6 — Audit Review, Analysis, and Reporting Fast reporting and investigation depend on reviewable evidence and alert handling.
IA-5 — Authenticator Management Password changes after suspected exposure are authenticator lifecycle actions.
Recommendation — Preserve message and access evidence for AU-6 analysis. Rotate exposed credentials under IA-5 as soon as compromise is plausible.
NIST CSF 2.0 RS.CO-2 — Incidents are reported consistent with established criteria The answer centers on immediate reporting to security or IT.
Recommendation — Establish phishing reporting criteria and route reports to response teams.
OWASP ASVS V16 — Security Logging and Error Handling The defender response depends on reliable logs and traceable user reports.
Recommendation — Log suspected phishing events so response teams can correlate follow-on activity.

Practitioner Guidance

What to verify: Train employees to verify the request itself, not just the sender name. The key question is whether the business action is expected by the real requester, not whether the email looks polished or comes from a familiar brand.

Decision rule: If there is any doubt and the message asks for credentials, payment, document review, or urgent action, report first and verify later through a trusted channel. If a password or MFA step may already have been exposed, treat it as a potential incident and move immediately to account protection and access review.

Practitioner takeaway: The critical control is not recognizing every phishing pattern, it is preventing a suspicious message from becoming an authenticated interaction before defenders can intervene.