C1.4Not started

Reporting a suspected incident

Reading depth

What you'll learn

  • Report fast; IR prefers false alarms to delayed real reports.
  • Use the documented channel; include what + when + data + your contact.
  • Don't investigate or delete; preserve evidence for IR.

If you suspect an incident — clicked a phishing link, mis-shared restricted data, lost a device, saw something off in a colleague's account — report it immediately. The incident-response (IR) team would rather get five false alarms than one delayed real one. Reporting fast is the most important habit in security; investigating is their job.

How to report: use the documented channel (typically a #security-incident Slack channel, security@ alias, or hotline — your policy specifies which). Include what happened, when, what data may be involved, and your contact info. Do not start investigating yourself — preserving the evidence matters more than your guess about whether it's real.

What not to do: don't forward the suspicious email widely ('FYI all'), don't try to log in again, don't delete anything. If you clicked a link, isolate the device by disconnecting from the network and wait for IR to triage.

Key points

  • Report fast; IR prefers false alarms to delayed real reports.
  • Use the documented channel; include what + when + data + your contact.
  • Don't investigate or delete; preserve evidence for IR.

Pitfalls

  • Forwarding the phish to your whole team to 'warn them'.
  • Hours of guilt before reporting — by which time the attacker has moved.

Ask your security team

In a real Adept rollout this routes to your company's security Claude project; in the demo it opens a fresh Claude chat.