Employees should report suspicious activity immediately to the IT or security team using the company’s approved process, such as email or an internal ticketing system. They should describe what they saw, avoid interacting further with the message or device, and preserve the evidence. Prompt reporting helps security teams contain the issue quickly and improves future awareness training.
What employees should do first when they spot suspicious activity
The first step is to report the event through the organisation’s approved incident path, then stop interacting with the suspicious message, file, device, or account activity. Rapid notification matters because early containment is usually much easier than late cleanup, especially when the activity involves credential theft, lateral movement, or other signs of an active compromise.
Employees should include enough detail for triage: what they observed, when it happened, where it appeared, and what they were doing just before it occurred. That makes the report actionable instead of just noisy, and it helps the response team decide whether to isolate a host, reset credentials, block an account, or preserve logs.
What to avoid so you do not make the incident worse
Do not click again, reply to the sender, forward the suspicious item indiscriminately, or keep testing the device or link “to see what happens.” Those actions can trigger malware, expose more data, or alert an attacker that the activity has been noticed. If the event involves a message or attachment, preserving the original item is usually more useful than deleting it immediately.
If the concern is on a workstation or mobile device, employees should avoid rebooting, wiping, or trying informal fixes before reporting unless the security team has already instructed them to do so. Uncoordinated action can destroy evidence, interrupt forensic review, and make it harder to confirm whether the event was a false alarm or a genuine incident.
What a useful report gives the security team
A good employee report shortens the path from suspicion to containment. The security team can correlate the employee’s observations with mail logs, endpoint telemetry, identity events, network data, or ticket history, then decide whether the issue is isolated, recurring, or part of a broader campaign. Clear reporting also improves future awareness training because the team can see which warning signs users actually notice.
When the suspicious activity may involve stolen credentials, compromised accounts, or unusual access to business systems, timely reporting is especially important. Those scenarios can move quickly from a single suspicious sign to account abuse, privilege escalation, or fraudulent actions, which is why response teams often treat employee escalation as a time-sensitive control rather than a routine helpdesk request.
Risk and Threat Considerations
Suspicious activity becomes materially riskier when it is ignored, delayed, or handled informally. The main exposure is that an attacker or unsafe process may keep running long enough to steal more data, spread laterally, or reuse captured credentials before the security team can intervene.
Failure mechanism: The incident remains active while the employee experiments with the message, link, file, or device, which can extend compromise, overwrite evidence, or give the adversary more opportunities to persist.
Impact: Faster escalation usually reduces blast radius, preserves logs and artifacts for investigation, and improves the odds that the team can contain the event before it affects additional users, endpoints, or accounts.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CIS Controls v8, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS-17 — Incident Response Management | Employees reporting suspicious activity directly supports incident intake and response coordination. |
| Recommendation — Define a simple reporting path and train staff to use it immediately for suspected incidents. | ||
| NIST CSF 2.0 | RS.CO-01 — Personnel know roles and order of operations for response | The question is about how employees should escalate a suspected incident into response workflows. |
| Recommendation — Publish and rehearse the employee escalation path for suspected incidents. | ||
| NIST SP 800-53 Rev 5 | IR-6 — Incident Reporting | Immediate reporting of suspicious activity is the core control objective of incident reporting. |
| IR-4 — Incident Handling | Preserving evidence and avoiding further interaction supports effective incident handling. | |
| Recommendation — Require prompt reporting of suspicious events through approved channels. Use incident handling procedures that preserve evidence and contain the event quickly. | ||
| ISO/IEC 27001:2022 | A.5.24 — Information security incident management planning and preparation | Employee reporting depends on preplanned incident channels and roles. |
| Recommendation — Prepare and communicate clear incident reporting procedures to all staff. | ||
Practitioner Guidance
What to verify: Employees should know the exact reporting channel before an incident happens, and the security team should verify that the channel is easy to use from normal work devices and remote locations. If staff are unsure where to report, reporting slows down at the moment it matters most.
What good looks like: A useful employee report is brief but specific, includes the observable symptom rather than a guess at the cause, and reaches the right team fast enough for containment decisions to still matter.
Common mistake: Treating a possible incident as a personal troubleshooting problem instead of a security event is one of the most common failure modes, especially when the initial sign looks minor or intermittent.
Practitioner takeaway: The best employee response is not to diagnose the incident, it is to preserve the signal, stop interacting, and hand the problem to the people who can contain it.
Related resources from NHI Mgmt Group
- What should incident response teams do when they see possible remote access, exfiltration, and authentication-bypass activity at the same time?
- What should users do after they notice a look-alike domain or suspicious URL?
- What should employees do after they click a suspicious link or open a phishing attachment?
- What should teams do when they discover an application after employees are already using it?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 27, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org