Incident response

What to do in the first hour after a phishing click (UK SME guide)

A plain-English containment checklist for UK SME owners: contain the device, reset what was exposed, tell the right people, then harden.

Someone on your team clicked a link that looked like Microsoft, HMRC, a courier, or a supplier invoice. Or they opened an attachment and something felt wrong. The next sixty minutes matter more than the perfect post-mortem.

This guide is for UK owner-managers with roughly 5 to 50 people and no dedicated security team. It is a containment checklist, not fear theatre and not a promise that following it makes you safe. If money has already moved, or customer personal data is clearly exposed at scale, call your bank and get specialist help in parallel with these steps.

Stop. Name the incident in one sentence

Before you rewrite passwords for the whole company, write one line: who clicked, what they clicked (or opened), on which device, and roughly when. Example: "Sam opened an invoice PDF from a fake supplier email on her Windows laptop at 10:12."

That sentence stops panic-shopping and keeps everyone working the same incident. If you do not know yet, say what you do know and what is still unknown.

Minute 0–10: contain the device and the session

  • Disconnect that laptop or phone from Wi-Fi and unplug Ethernet. Do not keep "just finishing an email" on the same machine.
  • If the person is still logged into Microsoft 365 / Google Workspace on that device, have an admin revoke sessions / sign them out everywhere for that account from the admin centre (or ask them to sign out of all sessions if you have no admin yet).
  • Do not power-wash the laptop yet unless you already have a spare machine and a known-good backup path. Contain first; rebuild later if needed.
  • If they typed a password into a fake login page, treat that password (and any reuse of it) as stolen even if nothing happened on screen.
  • If the click was only a web page and they entered nothing, you still treat the browser session as hostile until you clear it. If they entered banking or Microsoft credentials, escalate speed: bank first if money is at risk, then identity reset.

Minute 10–25: reset the identity that was exposed

Order of reset for a typical UK SME:

  1. The account they typed into (often Microsoft 365 or Google Workspace). New unique password from a password manager. Revoke other sessions again after the reset.
  2. Turn MFA on for that account if it was off. Prefer an authenticator app or security key over SMS where the product allows it. Store backup codes in the company vault, not in WhatsApp.
  3. Any account that reused the same password. This is where password managers earn their keep: you can see reuse and rotate without guessing.
  4. Shared mailboxes and "office@" style logins if that person knew them. Shared passwords are a liability; rotate and move them into the vault with a named owner.
  5. Domain registrar, hosting, banking portals, Xero/FreeAgent, and payment tools if those credentials lived on the same device or in the same browser profile.

Do not announce the new passwords in a group chat. Put them in the company password manager and invite only the people who need them.

Minute 25–40: check for the quiet damage

Phishing is often a foot in the door for inbox rules, app permissions, and invoice fraud rather than loud ransomware.

  • Mailbox rules and forwarding: look for rules that auto-forward or hide mail from "invoice", "payment", or specific customers. Delete unknown rules.
  • OAuth / connected apps: revoke anything the user does not recognise on Microsoft or Google.
  • Recent sent items: odd "please pay to this new bank account" threads.
  • Bank and payment platforms: check payee changes and pending payments. Call the bank on a number from your card or known statement, not from the phishing email.

If ransomware symptoms appear (files renaming, ransom note), disconnect remaining machines on the same network and restore from backups you have tested. Do not pay as a first plan; get advice.

Endpoint protection helps after the fact only if it is installed, updating, and visible in a console. If you have Microsoft Defender for Business or a similar SME product, open the console and see whether the device is healthy or flagged. If you have nothing company-managed, note that as a follow-up, not a reason to freeze the hour.

Minute 40–55: tell the right people (short and factual)

Inside the firm: tell leadership and anyone who can approve payments. One channel only (Teams/Slack call or a short all-hands note). Script:

"We had a suspected phishing click on [name/device] at about [time]. We have disconnected the device and are resetting accounts. Pause unusual payment requests until [named person] confirms. Do not click links in emails about this incident."

Outside, only if needed in the first hour:

  • Bank / card issuer if money or new payees are involved.
  • Your IT provider or MSP if you have one on retainer.
  • Customers or suppliers only if you already see fraudulent messages sent as you. Keep it factual; do not over-claim.

UK data-protection reporting to the ICO is a judgement about personal data risk and timelines, not something every phishing click triggers in hour one. If customer or staff personal data may have left the building, note the clock and get proper advice the same day. This article is not ICO guidance.

Minute 55–60: write the follow-ups while memory is fresh

  • Preserve evidence lightly: screenshot the email headers if you can, note the From address and time, do not forward the live malware to half the company.
  • Diary the rebuild or malware scan of the device for today or tomorrow.
  • Add MFA and password-manager gaps to a one-week harden list (see below).
  • If Cyber Essentials or insurance questionnaires are in play, record what happened and what you changed. Certificates and policies have their own rules; do not invent claims.

What not to do in the first hour

  • Do not run random "PC cleaner" tools from ad results.
  • Do not pay a caller who phones claiming to be Microsoft or your bank about this incident.
  • Do not blast a new temporary password to the whole company by SMS.
  • Do not pretend nothing happened because "the page looked off so we closed it". Treat entered credentials as compromised.
  • Do not start a three-vendor bake-off while the mailbox still has a forwarding rule.

After the hour: a one-week harden list

Containment buys time. Prevention is boring and cheaper than the next click:

  • Company password manager for everyone; kill password reuse (see OwnerSec's reuse and shared-login guides).
  • MFA on Microsoft 365 / Google Workspace for every human account.
  • Company-managed endpoint protection with a console you can open (Defender for Business if you are on Microsoft 365 Business Premium is often the cheapest sensible start). See the endpoint guide.
  • Shared mailboxes instead of shared passwords for info@ / office@.
  • A two-line payment rule: no bank-detail changes from email alone; verify on a known number.
  • One restore test of your backups this month.

Quick checklist you can copy

  • One-sentence incident note (who / what / device / when)
  • Device off the network
  • Sessions revoked for the affected cloud account
  • Password reset + MFA on; rotate reuse and shared secrets via vault
  • Mailbox rules, forwarding, and OAuth apps checked
  • Bank / payments checked if relevant; call on a known number
  • Internal payment freeze message sent
  • Evidence noted; device rebuild or scan booked
  • One-week harden list started

FAQ

Is every phishing click a full breach?
No. Many are noisy and go nowhere. You still assume credential theft if anything was typed, and you still check mailbox rules.
Should we tell all customers immediately?
Only if you have evidence their data or conversations were misused, or a regulator or contract requires it. Panic emails without facts create a second incident.
Can antivirus undo the click?
It can catch some malware after the fact. It does not reset stolen passwords or remove a silent forwarding rule.
Do we need Cyber Essentials before we can respond?
No. Response is operational. Certification is a separate scheme with defined controls.

Written for UK SME owners. More guides · How we make money