Lesson 2: How to React to Security Incidents Immediately
📚 Introduction
Cybersecurity incidents can happen at any moment. The faster you react, the more damage you can prevent. If you hesitate, you may give attackers the chance to control your device or spread malware inside your company.
You must know what to do immediately if something suspicious happens.
🚨 Common Security Incidents You May Face
- Clicking on a suspicious link or file
- Receiving a phishing email
- Downloading unknown software by mistake
- Your device starts working unusually slow or behaves strangely
- Pop-up messages asking you to install updates
✅ What You Must Do Immediately
- Stop working immediately.
- Do not continue typing, clicking, or navigating.
- Disconnect from the internet immediately.
- Turn off Wi-Fi or unplug the internet cable. This can stop attackers from remotely controlling your device.
- Do not shut down your computer unless your IT team tells you to.
- Shutting down can sometimes destroy valuable evidence.
- Call your IT department or security officer immediately.
- Use your phone (not your computer) to contact them.
- Do not try to fix it yourself.
- You can make the situation worse or lose important security information.
📄 Your Immediate Checklist
- ✔️ Disconnect from the internet
- ✔️ Call IT/security immediately
- ✔️ Do not touch the suspicious file again
- ✔️ Do not shut down your computer
- ✔️ Wait for IT’s instructions
- ✔️ Stay available to answer questions
⚠️ What You Should Never Do
- ❌ Do not ignore the problem.
- ❌ Do not try to uninstall unknown software yourself.
- ❌ Do not delete files that you think are suspicious.
- ❌ Do not forward suspicious emails to colleagues.
🏢 Internal Company Protocols You Must Respect
- Always report incidents within 5-10 minutes.
- Use the official reporting channels (email, phone number, or ticket system provided by your company).
- Document what happened:
- What you clicked.
- What file you opened.
- What happened on your screen.
- Cooperate fully with the IT team.
📣 Why Quick Reporting is Important
- Fast reporting can limit the spread of malware.
- It can protect other employees.
- It shows your company you are responsible.
- It can even save your job. Failing to report can be seen as negligence.
✅ Summary
- Act fast → Disconnect → Report.
- Follow your company’s instructions exactly.
- Never try to fix the situation alone.
- Quick reporting can make the difference between a small problem and a big disaster.
📝 Time to Test Your Knowledge!
Let’s see if you remember how to react in a cybersecurity emergency.
This quiz will test your understanding of fast response and company protocols.
✔️ Instant feedback.
✔️ You can retake the quiz if needed.
👉 Good luck! Let’s begin.



