Phishing Incident Response Checklist Template

Most reported phishing emails are dealt with in minutes. The expensive ones are the cases where someone also typed a password, approved an MFA prompt or paid an invoice, and nobody asked them.

A phishing report usually lands with whoever is on the service desk or security queue that day, and what happens next depends on how experienced that person is. One analyst deletes the email and closes the ticket. Another checks who else received it, finds two people who clicked, and discovers a forwarding rule quietly copying the finance director’s mail to an outside address. This free phishing incident response checklist makes the second outcome the normal one. It takes a reported phishing email from triage to closure: analysing the message and scoping who received, clicked, entered credentials, opened attachments or approved MFA prompts, purging it from mailboxes, then branching into credential compromise, business email compromise or malware only when the scoping answers say so. It runs as a sub-playbook of the Cybersecurity Incident Response Checklist and hands over to it when a phish turns out to be the start of something larger.

Use This Template Free See Live Example
No Credit Card Required

A Reported Phish Is Not Always a Closed Ticket

Most phishing reports are the easy kind: the email arrived, the person who reported it did not click, and the job is to remove it from everyone else’s inbox and block the sender. A general incident response plan is too heavy for that, and a service desk ticket is too light for the cases that are not easy. The difficulty is that you cannot tell which kind you have until you have asked the right questions. Did anyone else click? Did anyone enter a password on the fake sign-in page? Did anyone approve an MFA prompt they did not start? Was a payment or a change of bank details requested, and was it actioned?

Those answers decide everything that follows. A stolen password with a stolen session token is an account takeover, and resetting the password alone does not end it: the attacker may still hold a valid session, may have registered their own MFA method, created an inbox rule to hide replies, or granted a malicious app access to the mailbox. A changed bank detail is a fraud with a deadline measured in hours, because recovery depends on the bank acting before the money moves on. An opened attachment is a possible malware infection on an endpoint. Each of those is a short, specific branch, and this checklist only shows the branches the scoping answers call for.

Service desk ticket

Fine for the simple case

Covers: deleting the email and blocking the sender.

Misses: other recipients, clicks, credential use, inbox rules and payment requests.

Record: usually a one-line resolution note.

Phishing playbook

Scopes first, then branches

Covers: triage, scoping, purge, and the credential, payment fraud and malware branches when they apply.

Owner: the security analyst, with finance and the identity team pulled in by name.

Record: who received, who clicked and what was done, with times.

Full incident response

When the phish was the way in

Covers: lateral movement, data access, ransomware and regulatory reporting.

Trigger: evidence that the attacker used access beyond one mailbox or device.

Record: the incident timeline, opened from this checklist.

If the scoping shows the attacker read mailboxes holding personal data, the Data Breach Response Checklist takes over the notification decisions. If the payload was ransomware, the Ransomware Response Checklist takes over containment.

What the Phishing Incident Response Checklist Covers

Seven phases take a reported phishing email from triage to closure. Phases 3, 4 and 5 appear only when the scoping answers in Phase 2 call for them.

Phase 1

Phase 1: Triage the Report

Owned by the on-duty security or service desk analyst.

  • Acknowledge the reporter and record the time of the report — thank them, and ask them not to forward the email or click anything else
  • Capture the original message as an attachment with full headers — a screenshot loses the routing and authentication data you need
  • Analyse sender, headers, links and attachments — SPF, DKIM and DMARC results, lookalike domains, and URLs or files checked in a sandbox, never on a normal workstation
  • Classify the message — credential phishing, business email compromise, malware delivery, spam or a simulated test; record a false positive and close if it is legitimate
  • Ask the reporter what they did — opened, clicked, entered a password, opened an attachment, approved an MFA prompt or replied
Phase 2

Phase 2: Scope & Purge

Each answer in task 4 is a required Yes/No DropDown. Those answers decide whether Phases 3, 4 and 5 appear.

  • Search mail logs for every copy — same sender, subject, URL or attachment hash; record how many recipients and which mailboxes
  • Find who clicked or replied — URL click logs from the email filter, web proxy or DNS logs, and sent items; attach the list
  • Purge the message from all mailboxes — for example Threat Explorer or a Purview search and purge in Microsoft 365, or the security investigation tool in Google Workspace where your edition includes it
  • Record the scoping answers — credentials entered or MFA approved; payment or bank detail change requested; attachment opened or file run
  • Block the sender, domain, URLs and file hashes — at the email gateway, web filter and endpoint tool; note any block that could affect a real supplier
  • Warn staff if the campaign is still arriving — a short message describing the email, without links, and how to report copies
Phase 3

Phase 3: Contain Compromised Accounts

Appears only when Phase 2 records credentials entered or an MFA prompt approved. Assigned to the identity administrator.

  • Reset the password and revoke all sessions and refresh tokens — Revoke sessions in Microsoft Entra ID, or reset sign-in cookies in the Google Admin console; a reset alone leaves stolen sessions working
  • Review registered MFA methods and remove any the user does not recognise — attackers often add their own phone or authenticator app
  • Check inbox rules, forwarding and mailbox delegates — rules that forward, delete or move mail to obscure folders are a classic sign of takeover
  • Review OAuth app consents for the account — revoke any app the user did not knowingly grant access to mail or files
  • Review sign-in and mailbox audit logs for the exposure window — locations, devices, mail items accessed and messages sent; attach the export
  • Check whether the account sent phishing internally or to customers — and warn recipients if it did
Phase 4

Phase 4: Business Email Compromise & Payment Fraud

Appears only when Phase 2 records a payment or bank detail change request. Tasks are assigned to the finance lead, not IT.

  • Stop any pending payment and confirm whether money has already left — check the payment run, the amount, the date and the receiving account
  • If money was sent, call your bank’s fraud team immediately and ask for a recall — recovery depends on the receiving bank freezing funds before they move on
  • Report the fraud — the FBI’s IC3 in the US, Report Fraud (formerly Action Fraud) in England, Wales and Northern Ireland, or Police Scotland on 101
  • Verify the request with the real supplier or executive on a known phone number — never the number or email in the suspicious message
  • Check for other changed bank details and pending invoices from the same supplier — and tell the supplier, whose mailbox may be the compromised one
Phase 5

Phase 5: Contain Malware

Appears only when Phase 2 records an attachment opened or a file run. Assigned to the endpoint team.

  • Isolate the device from the network — through the endpoint tool where possible, leaving it powered on for investigation
  • Collect the file and the endpoint tool’s findings — process tree, network connections and any persistence it created
  • Hunt for the same file hash and indicators across other devices — and confirm the block in Phase 2 covers them
  • Clean or reimage the device and reset any credentials used on it — based on what the investigation found
Phase 6

Phase 6: Escalate & Hand Over

The escalation decision is an approval step for the security lead.

  • Decide whether this is now a security incident — attacker activity beyond one mailbox or device, data accessed, or more than one account taken over
  • Open the full incident response record where it is — and link this checklist so the timeline is not rebuilt from memory
  • Start the data breach response checklist if mailboxes or files holding personal data were accessed — the regulator clock may already be running
  • Notify the cyber insurer where a payment was lost or the policy requires notice — record the claim reference
Phase 7

Phase 7: Close the Loop

Closure needs approval from the security lead.

  • Give the reporter feedback — what the email was, what was done, and thanks; people who hear back keep reporting
  • Report the phishing site or email to the authorities where useful — for example the UK NCSC’s Suspicious Email Reporting Service at report@phishing.gov.uk
  • Feed the lesson into awareness training — the lure, the warning signs it carried and how it was spotted, for the next training cycle
  • Tune filters and controls — new detection rules, lookalike domain blocks, external sender banners or phishing-resistant MFA for the targeted group
  • Approve closure — scoping, purge, containment and any hand-over confirmed, with evidence attached

One Report, Four Possible Paths

The scoping answers recorded in Phase 2 decide the shape of the response. A clean report moves straight from purge to closure in a few minutes. A report where someone typed a password and a supplier’s bank details changed pulls in the identity administrator and the finance lead, each with their own tasks, without anyone having to remember to call them.

What Phase 2 recordsWhat appearsFirst actionOwner
Received only, nobody clickedPhases 6 and 7 onlyPurge, block, give the reporter feedbackAnalyst
Clicked, no credentials enteredPhases 6 and 7, with the click list attachedCheck the site and any download, then purgeAnalyst
Credentials entered on a fake pagePhase 3: Contain compromised accountsReset password and revoke sessionsIdentity administrator
Unexpected MFA prompt approvedPhase 3: Contain compromised accountsRevoke sessions, then review registered MFA methodsIdentity administrator
Payment or bank detail change requestedPhase 4: Business email compromiseHold the payment and verify on a known numberFinance lead
Payment already sentPhase 4: Business email compromiseCall the bank’s fraud team to request a recallFinance lead
Attachment opened or file runPhase 5: Contain malwareIsolate the deviceEndpoint team

Business email compromise is where speed matters most. The FBI’s Internet Crime Complaint Center recorded more than $3 billion in reported business email compromise losses in 2025, from almost 25,000 complaints, in its annual report published in April 2026. The IC3’s Recovery Asset Team works with banks through the Financial Fraud Kill Chain to freeze domestic transfers, and the FBI’s consistent advice is to contact your bank and file a complaint as quickly as possible. In the UK, Report Fraud replaced Action Fraud as the national reporting service for fraud and cyber crime in England, Wales and Northern Ireland from December 2025.

Session revocation is the step most often missed. Modern phishing kits capture the session cookie as well as the password, which lets an attacker bypass MFA without ever needing the code again. That is why Phase 3 revokes sessions and checks MFA methods, rules and app consents rather than stopping at a password reset, and why phishing-resistant authenticators such as passkeys and security keys appear among the improvement actions. NIST SP 800-63-4, finalised in 2025, requires verifiers at AAL2 to offer a phishing-resistant option.

Why Run Phishing Response in CheckFlow?

1

The branches find the right people

Answer yes to “payment requested” and the fraud tasks appear assigned to the finance lead, not to the analyst who has never spoken to the bank. Answer no to everything and the checklist stays short. Nobody has to remember the right people to call at 4pm on a Friday.

2

The scope is written down

Recipient lists, click lists and audit log exports are attached to the task that produced them. When a regulator or insurer later asks who clicked and what the attacker could read, the answer is in the record with a name and a time against it.

3

Lessons reach the training plan

The closure phase asks for the lure and the warning signs, which gives the awareness programme real examples from your own inbox. Tags on each run make it easy to find every report from the same campaign or targeting the same team.

CheckFlow is not an email security gateway, SIEM or EDR tool, and it does not detect or remove phishing. It runs the human side of the response around those tools: who checks what, who calls the bank, and what was decided. For the wider set of security and compliance routines that sit around incident handling, CheckFlow’s compliance checklist software keeps owners, evidence and approvals in one place.

The cheapest phishing incident is the one that gets reported quickly. The Security Awareness Training Checklist runs the programme that teaches people to spot and report a lure, and the User Access Review Checklist removes the dormant and over-privileged accounts that make a stolen password more valuable. To rehearse the payment fraud branch with finance, use the Incident Response Tabletop Exercise Checklist.

Frequently Asked Questions

What should you do when an employee reports a phishing email?

+

Thank them, capture the original email with its headers, and ask what they did with it. Then search for every other copy, find out who else clicked or replied, purge it from all mailboxes and block the sender and links. If anyone entered a password, approved an MFA prompt, opened an attachment or acted on a payment request, follow the matching branch. Finally, tell the reporter what happened, which is what keeps people reporting.

What should you do if someone clicked a phishing link?

+

Find out what happened after the click. If the page asked for a password and they entered it, treat the account as compromised: reset the password, revoke all sessions, and check MFA methods, inbox rules and app consents. If a file downloaded or ran, isolate the device. If they only opened the page and closed it, check the site and the proxy logs, record the outcome and close. Asking the user directly, without blame, is usually the fastest way to find out.

Is resetting the password enough after credentials are phished?

+

No. Many phishing kits steal the session cookie along with the password, so the attacker may stay signed in after a reset. Revoke all sessions and refresh tokens, remove any MFA method the user does not recognise, delete suspicious inbox rules and forwarding, revoke unfamiliar app consents, and review the audit logs to see what the attacker read or sent while they had access.

What should we do if we paid a fraudulent invoice?

+

Call your bank’s fraud team straight away and ask them to recall the payment; the chance of recovery falls quickly as the money moves between accounts. In the US, file a complaint with the FBI’s IC3; in England, Wales and Northern Ireland, report to Report Fraud, which replaced Action Fraud. Then verify any other payment requests from that supplier on a known phone number, tell the supplier in case their mailbox is the one compromised, and notify your insurer if your policy covers social engineering fraud.

Should employees be disciplined for clicking a phishing link?

+

Generally not for a single click. Phishing is designed to fool careful people, and staff who expect blame report later or not at all, which turns a five-minute purge into an account takeover. Reward fast reporting, use real examples in training, and keep disciplinary routes for deliberate policy breaches. A repeat pattern is better handled with targeted coaching and stronger controls for that person’s role.

Is CheckFlow free for this template?

+

14-day free trial, no card required. The Business plan is $10 per user per month after the trial. Full details at checkflow.io/pricing.

Turn Every Reported Phish Into a Finished Response

Free trial — no credit card required.