Module 4 · Lesson 4.2
Incident reporting process
Knowing how to report an incident is just as important as recognizing one.
Always watching. Always protecting.
Step 1: Stop & Contain
If safe to do so:
- Disconnect from the network (if malware suspected)
- Stop interacting with suspicious emails or links
- Do not delete evidence
Step 2: Report Immediately
- Use the approved reporting channel
- Notify your supervisor if required
- Provide details: what happened, when, and what system was involved
Do not wait to “confirm” it’s an incident. Security will assess.
Step 3: Cooperate
Follow guidance from IT/Security. Provide accurate information and avoid discussing the incident publicly or internally beyond need-to-know.