Blog/Security basics

Clicked a Phishing Link at Work? What to Do in the First 15 Minutes

Everyone clicks eventually. What happens next decides whether it becomes an incident. A calm, step-by-step guide for employees, and what security teams should make easy.

CyberWatch AI27 September 2026 · 3 min read
A man at his desk with his head in his hands in front of a laptop

It happens to careful people. The email looked right, you were busy, and you clicked. Maybe you even typed your password before something felt wrong. The sinking feeling is normal. What matters now is the next fifteen minutes, because a click reported quickly is usually a small problem, and a click kept quiet can become a very large one.

The most important step is the one people skip: tell your security or IT team straight away. You will not be the first person to do this, and a good team will thank you for it.

Step 1: Stop and do not go further

Close the page. Do not enter anything else, do not download anything it offers, and do not reply to the email. If the page asked for more details after your password, such as a code or card number, do not provide them.

Step 2: Work out what actually happened

What you do next depends on how far it went. Be honest with yourself, because it helps the people fixing it:

  • I only opened the link. The risk is lower, but still report it. Some pages try to exploit the browser, and your team will want to block the address for everyone else.
  • I entered my password. Assume the attacker now has it.
  • I entered a code or approved a sign-in. Assume they may already be in the account.
  • I downloaded or opened a file. Assume the device may be infected.
  • I entered card or bank details. Treat it as a financial emergency.

Step 3: Contain it

If you entered a password

Change it immediately, ideally from a different device, and change it anywhere else you used the same password. If your account has multi-factor authentication, check it is still on and that no new device has been added.

If you opened a file

Disconnect the device from the network: switch off Wi-Fi or unplug the cable. Leave the device switched on unless your IT team tells you otherwise, because they may need to examine it.

If you entered payment details

Call your bank on the number on the back of your card, block the card and tell them what happened.

Step 4: Report it, with the details

Tell your security or IT team what you clicked, when, and what you entered. Forward the original email if you still have it, or report it with your organization's report button. The time matters: an attacker with a fresh password often acts within hours.

Why reporting helps everyone: the same email almost certainly went to your colleagues. Your report lets the team remove it from other inboxes and block the page before anyone else clicks.

Step 5: Watch for the follow-up

For the next few weeks, look out for unexpected password reset emails, sign-in alerts, messages sent from your account that you did not write, and payments you do not recognise. Tell your team about anything odd.

For security teams: make the right thing easy

  • One-step reporting. If reporting takes a form and three screens, people will not bother.
  • No blame for honest mistakes. Punishing a click teaches people to hide the next one.
  • A clear, short procedure that every employee has seen before they need it.
  • Practice. Simulated phishing lets people rehearse the report, so it is automatic when a real one arrives.

How CyberWatch AI helps

In CyberWatch AI, any employee can check a suspicious link or message and report it to their security team in one step, and administrators see reported threats in one place. Simulations let staff practise the whole sequence, from spotting the message to reporting it, so the first real click is handled calmly and quickly.

Share this article
LinkedIn WhatsApp X
For organizations

Your people get these messages at work too.

CyberWatch AI sends your staff realistic practice attacks, trains the gaps it finds, and shows management exactly where the organization stands.