Question/Issue
What steps should be taken when a staff member reports a suspicious email requesting confidential information?
Cause
Phishing emails are designed to trick users into revealing sensitive data or credentials.
Resolution
- Do not click any links or download attachments from the suspicious email.
- Quarantine the email using your organization’s email security tools.
- Update spam filters to block similar messages in the future.
- Notify all staff about the phishing attempt and provide examples of what to look for.
- Offer or require phishing awareness training for staff.
- If any information was disclosed, follow your organization’s incident response plan.