Reporting a suspected incident
What you'll learn
- Report fast; IR prefers false alarms to delayed real reports.
- Use the documented channel; include what + when + data + your contact.
- Don't investigate or delete; preserve evidence for IR.
If you suspect an incident — clicked a phishing link, mis-shared restricted data, lost a device, saw something off in a colleague's account — report it immediately. The incident-response (IR) team would rather get five false alarms than one delayed real one. Reporting fast is the most important habit in security; investigating is their job.
How to report: use the documented channel (typically a #security-incident Slack channel, security@ alias, or hotline — your policy specifies which). Include what happened, when, what data may be involved, and your contact info. Do not start investigating yourself — preserving the evidence matters more than your guess about whether it's real.
What not to do: don't forward the suspicious email widely ('FYI all'), don't try to log in again, don't delete anything. If you clicked a link, isolate the device by disconnecting from the network and wait for IR to triage.
Key points
- Report fast; IR prefers false alarms to delayed real reports.
- Use the documented channel; include what + when + data + your contact.
- Don't investigate or delete; preserve evidence for IR.
Pitfalls
- Forwarding the phish to your whole team to 'warn them'.
- Hours of guilt before reporting — by which time the attacker has moved.
Ask your security team
In a real Adept rollout this routes to your company's security Claude project; in the demo it opens a fresh Claude chat.