What to do after a security mistake
Take proportionate first steps after a suspicious click, credential disclosure, mistaken share, or unexpected MFA approval.
Start with the situation
A mistake is easier to contain when it is reported early. The right response depends on whether credentials, information, a device, or an approval may be affected.
The decision to make
Stop further exposure, preserve useful details, and get the right person involved before taking destructive action.
A practical sequence
- Stop the conversation, repeated login, further approval, download, or sharing.
- Note what happened, when, which account or file was involved, and what you clicked, entered, approved, opened, or installed. Keep the original message.
- For exposed credentials, use a known-good device and the official service to change them and review or revoke sessions. For mistaken sharing, restrict or revoke access if safe.
- Contact IT, security, your manager, the service provider, or the designated incident route promptly and follow their instructions.
- Watch for unexpected sign-ins, messages, transactions, forwarding rules, or further prompts.
Real-world examples
- Credentials entered on a lookalike site: stop, use the real site from a trusted device, secure the account, and report.
- Sensitive file sent to the wrong person: attempt an approved access revocation and report the recipient and file.
- Suspicious program opened: stop using the device for sensitive work and contact support; do not improvise a cleanup.
Common mistakes
- Hiding the event because it seems embarrassing or minor.
- Deleting messages, wiping a device, or running unapproved cleanup that may remove useful evidence.
- Using the same potentially affected device to reset every important account without guidance.
What to do next
Follow the organization or service-specific response. Account compromise, data exposure, malware suspicion, mistaken sharing, and MFA abuse may require different actions.
Report facts early. A fast, honest report gives responders more options.
Trusted official references
- CISA
Report a Cyber Issue
Official routes and context for reporting cyber incidents and vulnerabilities.
View official source - UK NCSC
Small Business Guide: Response & Recovery
A practical framework for preparing, identifying, resolving, reporting, and learning from incidents.
View official source
