cyber&
Back to Resources

What to do after a security mistake

Take proportionate first steps after a suspicious click, credential disclosure, mistaken share, or unexpected MFA approval.

Start with the situation

A mistake is easier to contain when it is reported early. The right response depends on whether credentials, information, a device, or an approval may be affected.

The decision to make

Stop further exposure, preserve useful details, and get the right person involved before taking destructive action.

A practical sequence

  1. Stop the conversation, repeated login, further approval, download, or sharing.
  2. Note what happened, when, which account or file was involved, and what you clicked, entered, approved, opened, or installed. Keep the original message.
  3. For exposed credentials, use a known-good device and the official service to change them and review or revoke sessions. For mistaken sharing, restrict or revoke access if safe.
  4. Contact IT, security, your manager, the service provider, or the designated incident route promptly and follow their instructions.
  5. Watch for unexpected sign-ins, messages, transactions, forwarding rules, or further prompts.

Real-world examples

  • Credentials entered on a lookalike site: stop, use the real site from a trusted device, secure the account, and report.
  • Sensitive file sent to the wrong person: attempt an approved access revocation and report the recipient and file.
  • Suspicious program opened: stop using the device for sensitive work and contact support; do not improvise a cleanup.

Common mistakes

  • Hiding the event because it seems embarrassing or minor.
  • Deleting messages, wiping a device, or running unapproved cleanup that may remove useful evidence.
  • Using the same potentially affected device to reset every important account without guidance.

What to do next

Follow the organization or service-specific response. Account compromise, data exposure, malware suspicion, mistaken sharing, and MFA abuse may require different actions.

Report facts early. A fast, honest report gives responders more options.

Trusted official references

  • CISA

    Report a Cyber Issue

    Official routes and context for reporting cyber incidents and vulnerabilities.

    View official source
  • UK NCSC

    Small Business Guide: Response & Recovery

    A practical framework for preparing, identifying, resolving, reporting, and learning from incidents.

    View official source