Skip to main content
Employee clicking phishing email link and immediate cybersecurity response

1. Our employee clicked a phishing link but says they didn't enter any information. Are we still at risk?

Possibly. Some phishing links trigger drive-by downloads or session tracking without requiring any input. The device should still be isolated and reviewed by IT even if no credentials were entered.

2. How long do we have before a phishing attack causes serious damage?

In credential harvesting scenarios, attackers often act within minutes of receiving stolen credentials, setting up mail forwarding rules, exporting contacts, or attempting lateral movement. Speed of response is the primary variable you control.

3. Does our cyber insurance cover phishing incidents?

Most cyber policies do, but many require prompt notification to the carrier as a condition of coverage. Notify your insurer as soon as the incident is confirmed, delay can jeopardize the claim.

4. What if the phishing email came from a real vendor's address?

This is business email compromise (BEC) and is increasingly common. Notify the vendor immediately so they can contain their own breach. Treat any actions taken based on that email (wire transfers, credential entries, file downloads) as potentially compromised.

5. We reset the affected account's password. Is that enough?

No. Password reset without MFA enablement still leaves the account vulnerable. Additionally, check for forwarding rules, connected apps, and active sessions that may persist even after a password change.