Join our Newsletter — 33% off our NHI Course
Home› FAQ› Threats, Abuse & Incident Response› What should employees do after they suspect a…
Threats, Abuse & Incident Response

What should employees do after they suspect a phishing email but before they interact with it?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 26, 2026 Domain: Threats, Abuse & Incident Response

Employees should avoid clicking links or opening attachments, verify the request through a separate trusted channel, and alert IT or security immediately. Fast reporting gives defenders a chance to investigate, contain the message, and protect other users. If credentials may have been exposed, the response should include password changes and access review as soon as possible.

Pause, Verify, and Report Before You Interact

The safest next step is to stop interacting with the message and treat it as potentially hostile until proven otherwise. A separate trusted channel, such as a known phone number or internal chat that is not linked from the email, is the right way to confirm whether the request is real. Immediate reporting matters because it preserves evidence and lets security teams contain the message before others respond to it.

One practical habit is to assume the first visible detail may be the attacker’s hook, not proof of legitimacy. Link text, sender display names, reply-to tricks, and attachment names can all be manipulated to create urgency. If the message reached a shared mailbox, distribution list, or business process, the reporting step should happen even faster because the blast radius is larger.

What to Do If You Already Exposed a Secret

If the message was only suspected, the response is simple: do not click, do not open, and do not reply. If an employee already entered a password, opened a file, or approved a prompt for authentication, the situation changes from suspicion to potential compromise. At that point, password reset, session review, and account access review become time-sensitive actions rather than optional cleanup.

Fast containment is more important than trying to prove with certainty whether the email was malicious first. Security teams can inspect headers, quarantine similar messages, search for recipients, and look for follow-on activity, but employees should not wait for that analysis before reporting. The earlier the alert, the more likely defenders can stop token theft, mailbox rules abuse, or lateral phishing before it spreads.

Why Trusted-Channel Verification Is the Deciding Step

Trusted-channel verification is the control that breaks the attacker’s control over the conversation. A phishing email often tries to move the victim into the attacker’s preferred channel, such as a fake login page, a malicious document, or a fraudulent payment workflow. Verifying through a known-good route preserves decision quality because it avoids using the compromised message itself as the source of truth.

That verification should be specific, not casual. Employees should confirm the request with the named requester, the help desk, or the business owner using contact details already stored in an approved directory or internal portal. If the message claims urgency, payment, credential reset, or document review, the urgency itself is a warning sign, not a reason to accelerate interaction.

Risk and Threat Considerations

Phishing is dangerous because a single interaction can create immediate exposure through credential theft, session hijacking, or malicious code execution. Even when the first click does not fully compromise the account, it can give defenders too little time to stop inbox rules, token replay, or secondary delivery to colleagues.

Failure mechanism: The attacker relies on the employee to move from suspicion to interaction before verification happens, then uses the resulting trust step to capture credentials, tokens, or malware execution.

Impact: The organization can face account takeover, unauthorized access to mail or business systems, and wider internal spread if the same lure is forwarded or reused.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while NIST SP 800-53 Rev 5, NIST CSF 2.0 and OWASP ASVS set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
MITRE ATT&CKT1566 — PhishingPhishing is the core attack pattern behind the question.
Recommendation — Map suspicious email handling to T1566 detection and user-reporting workflows.
NIST SP 800-53 Rev 5AU-6 — Audit Review, Analysis, and ReportingFast reporting and investigation depend on reviewable evidence and alert handling.
IA-5 — Authenticator ManagementPassword changes after suspected exposure are authenticator lifecycle actions.
Recommendation — Preserve message and access evidence for AU-6 analysis. Rotate exposed credentials under IA-5 as soon as compromise is plausible.
NIST CSF 2.0RS.CO-2 — Incidents are reported consistent with established criteriaThe answer centers on immediate reporting to security or IT.
Recommendation — Establish phishing reporting criteria and route reports to response teams.
OWASP ASVSV16 — Security Logging and Error HandlingThe defender response depends on reliable logs and traceable user reports.
Recommendation — Log suspected phishing events so response teams can correlate follow-on activity.

Practitioner Guidance

What to verify: Train employees to verify the request itself, not just the sender name. The key question is whether the business action is expected by the real requester, not whether the email looks polished or comes from a familiar brand.

Decision rule: If there is any doubt and the message asks for credentials, payment, document review, or urgent action, report first and verify later through a trusted channel. If a password or MFA step may already have been exposed, treat it as a potential incident and move immediately to account protection and access review.

Practitioner takeaway: The critical control is not recognizing every phishing pattern, it is preventing a suspicious message from becoming an authenticated interaction before defenders can intervene.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 26, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org