Field Notes – The phishing report that waits until Monday

TL;DR Phishing reporting after hours needs a clear owner, a backup and realistic response times. Test what happens after the report arrives, including what the employee should do while waiting – or mess with the best (us).

I have a fairly, totally unromantic test for a phishing reporting procedure: can it survive the CISO putting their phone down?
That is the loose end I would want closed before the weekend: a shared mailbox can accept messages all Sunday without anyone being responsible for reading them.. geez!

So now, picture a hypothetical Sunday evening: an employee receives an urgent request to share a file, hesitates and reports it through the approved route. An automatic acknowledgement arrives, so does another message from the supposed colleague, asking what is taking so long.

The employee has followed the procedure. They still need to know what to do while waiting, and when to use another contact route.
If the practical answer is “try the CISO”, their personal phone has become the unofficial second page of the procedure – a surprisingly demanding appendix, you may say.

Delivery, acknowledgement and someone accepting responsibility are separate events. A ticket number can confirm that the system received a report without telling us whether anyone has assessed it.

I would give the first report a named duty owner, a backup who knows when to take over, and a response window the team can sustain. The instructions should state coverage hours, when an unanswered report needs escalating and where the employee can find that route. A department name alone leaves too much to interpretation.

Agree which situations need urgent attention and who can provide it and give employees clear instructions to pause the suspicious action while seeking verification – where CLEAR stands for a natural language they can understand and follow along, not the legal-ese style output every GPT spits out. Than, they should be able to ask for help without first diagnosing an incident; also, if the required coverage exceeds the staffing available, that gap needs a management decision.

Then test the handoff during an agreed exercise: record when the report was submitted, when someone accepted responsibility and when the employee received usable guidance. That shows where the wait happens, a reporting rate alone cannot.

Bring that same question to our guys in a Baited demo: after somebody gets suspicious, how can we observe their decision to report? Ask which actions the simulation records and what each event proves. Check where that visibility ends and your own response process begins.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top