Skip to content

6 min read

American Corners

Reporting an incident

Speaking up early is the whole point

When something feels wrong, a strange login, a link you wish you had not clicked, a payment that looks off, the instinct is often to stay quiet and hope it is nothing. That instinct is the thing to fight. An incident reported in the first minutes can usually be contained. The same incident hidden for a day can spread across accounts and become far harder to undo. Reporting is not admitting failure; it is how the damage gets stopped.

If you think you clicked something

Suppose you clicked a link or opened an attachment, and only then felt uneasy. Do not panic, and do not go quiet. Take these steps in order.

  • Stop. Do not type any more details, do not enter your password, and do not "log in" on the page that opened.
  • Disconnect if it looks serious. Turning off Wi-Fi or unplugging the network cable can stop malicious software from spreading while you get help.
  • Report it right away to whoever handles IT or security. Tell them plainly what happened and what you clicked.
  • Then change the password for that account from a device you trust, and turn on multi-factor authentication (MFA) if it is not already on.

A wrong click is not the disaster. Hiding a wrong click is what turns it into one.

Who to tell

The order is simple: tell the people closest to the problem first, then the ones who handle it formally.

  • At work, that is your IT or security team, or your manager if you are not sure who else. They can check logs, reset access and warn others who got the same message.
  • At home, tell the bank if money or card details are involved, and the real provider of any account that may be affected, reached through their official app or website, not through a link in the suspicious message.
  • In Albania, serious incidents can be reported to the national cyber authority. For businesses that run important services, reporting to the national cyber authority is not just good manners; it can be a legal duty.

Report even when you are not sure

You do not need to be certain, or to understand exactly what happened, before you report. "This message felt like phishing" or "I think I did something silly" is enough to start with. It is always better to raise a false alarm that turns out to be nothing than to stay silent about something real. The people who handle these problems would far rather hear from you early.

Check yourself

Social engineering & account safety

Where this lesson comes from

Built from

  • Workshop 1: Cybersecurity Essentials (participant guide V3.0): incident reporting

You can check these yourself

  • National cyber authority (Albania): incident reporting guidance

alphaPlan courses are built from taught programmes rather than invented for the web. Where a claim rests on an outside standard or a reported case, it is named above so you can check it rather than take our word for it.

shënim: ky material u krijua në kuadër të projektit 'U.S. Cybersecurity Leadership in AI for Albania', financuar nga departamenti i shtetit i shteteve të bashkuara. mendimet, gjetjet dhe përfundimet e paraqitura këtu janë të autorit(ëve) dhe nuk pasqyrojnë domosdoshmërisht ato të departamentit të shtetit të shteteve të bashkuara.

Disclaimer: This material was created on behalf of the 'U.S. Cybersecurity Leadership in AI for Albania' project, funded by the United States Department of State. The opinions, findings, and conclusions stated herein are those of the author(s) and do not necessarily reflect those of the United States Department of State.

Disclaimer

Found something unclear, outdated or improvable? Suggest an improvement