TL;DR Cybersecurity incident reporting means promptly telling the appropriate person when something looks suspicious, even when you are unsure whether it is a real threat. Reporting a questionable email, lost device, unfamiliar visitor, or accidental click gives your company time to investigate and limit potential damage.
Cybersecurity awareness is not only about recognizing threats. Employees also need to know what to do when they notice something unusual.
A suspicious email may be harmless. An unfamiliar person in the office may be an authorized visitor. Clicking a link may not lead to an immediate compromise. However, employees should not be expected to investigate these situations themselves. Their responsibility is to report what happened so the appropriate person can determine whether action is necessary.
That is the practical meaning of “see something, say something” in cybersecurity.
What Is Cybersecurity Incident Reporting?
Cybersecurity incident reporting is the process of notifying your manager, internal IT team, or managed IT provider about suspicious activity, security concerns, or mistakes that could affect company systems or information.
An incident does not need to be a confirmed cyberattack before it is reported. Reporting can be as simple as asking:
- “I have never seen that person before. Are they authorized to be in this area?”
- “I found a USB drive in the parking lot. What should I do with it?”
- “I clicked a link in an email, but nothing happened. Is that normal?”
- “My phone with company email is missing. Who should I notify?”
- “A vendor sent new payment instructions. Can someone verify them?”
Employees are not wasting anyone’s time by asking these questions. They are providing information that may help the business identify a threat before it develops into a larger incident.
Why Does Prompt Reporting Matter?
Security teams can respond most effectively when they learn about a problem early.
If an employee reports a suspicious link immediately, IT may be able to reset the employee’s password, revoke active sessions, isolate the computer, block the malicious website, and search for similar messages in other inboxes.
If the employee waits several days because nothing obvious happened, an attacker may have more time to use stolen credentials, access email, review financial conversations, or impersonate the employee.
The same principle applies to lost equipment, unusual login prompts, unexpected multifactor authentication requests, and suspicious people in restricted areas. Early reporting creates more options. Delayed reporting allows uncertainty and potential damage to grow.
Did You Know? Approximately 60% of breaches examined in Verizon’s 2025 Data Breach Investigations Report involved a human element. This includes social engineering, mistakes, and misuse. The statistic is a reminder that employee decisions remain an important part of business security. [Source: Verizon 2025 DBIR]
What Types of Incidents Should Employees Report?
Suspicious Emails and Social Engineering
Employees should report unexpected password-reset messages, unusual file-sharing invitations, requests for sensitive information, and messages that create urgency around payments or account access.
Modern phishing messages may look professional and may appear to come from a manager, vendor, client, or technology provider. Employees should be encouraged to report messages that feel unusual, even when they cannot identify a specific red flag.
For a closer look at these tactics, read Phishing vs. Spear Phishing vs. BEC: Know the Difference.
Accidental Clicks and Disclosures
An employee who clicks a questionable link should report it immediately, even if the website did not load or nothing appeared to happen.
The same applies if someone entered a password on an unfamiliar page, approved an unexpected multifactor authentication request, sent information to the wrong recipient, or downloaded an unexpected attachment.
Employees sometimes hide mistakes because they fear embarrassment or disciplinary action. That reaction increases the company’s risk. A healthy reporting culture focuses first on containing the incident and learning what happened.
Lost or Stolen Devices
Lost laptops, phones, tablets, security keys, and removable storage devices should be reported promptly. Even when a device is encrypted or password-protected, IT may need to disable access, remotely secure the device, revoke active sessions, or document the loss.
Employees should not wait several days hoping that the device will turn up.
Unknown USB Drives
An unidentified USB drive should never be plugged into a company computer to determine what it contains. It could carry malicious software designed to run when connected.
Employees should leave the device alone when possible and notify the person responsible for IT or security. This is particularly important when a drive is found in a parking lot, reception area, shared workspace, or near an office entrance.
Unusual People or Physical Behavior
Cybersecurity also includes physical access to equipment and information.
An unfamiliar person walking through a restricted office, photographing equipment, looking through paperwork, or attempting to enter a server or network room should be reported. Employees do not need to confront the person. They should follow the company’s safety and visitor procedures.
Unexpected Account Activity
Employees should report unusual password-reset notifications, login alerts from unfamiliar locations, unexplained sent messages, missing files, or repeated multifactor authentication prompts.
These events may indicate that someone is attempting to access the employee’s account. Rejecting an unexpected prompt is important, but reporting it allows IT to investigate the cause.
What Should an Employee Include in a Report?
A useful report explains what happened, when it happened, and which device or account was involved.
Whenever possible, the employee should preserve the original message and provide a screenshot. However, they should not forward suspicious attachments or links to coworkers. The company should have an approved reporting method, such as a phishing-report button, help desk ticket, dedicated email address, or telephone number.
Employees should avoid conducting their own investigation. Reopening a suspicious link, contacting a suspected attacker, or plugging in an unknown device can create additional risk.
CISA recommends that businesses teach employees how and where to report phishing and respond quickly to those reports. [Source: CISA, Teach Employees to Avoid Phishing]
How Can Businesses Build a Strong Reporting Culture?
A reporting policy will not work if employees believe they will be punished for raising a concern or admitting a mistake.
Managers should thank employees for reporting suspicious activity, even when the investigation determines that nothing harmful occurred. The goal is not to reward false alarms. It is to reinforce the behavior the company needs when a real incident occurs.
Businesses should also give employees clear instructions:
- What should be reported?
- Who should receive the report?
- How should urgent incidents be reported?
- What should an employee do after clicking a suspicious link?
- Who should be contacted outside normal business hours?
These instructions should be covered during onboarding and reinforced through ongoing security awareness training and phishing simulations.
Learn more in The Complete Guide to Phishing Security Awareness Training and review these real phishing examples with your team.
Cybersecurity Incident Reporting for Small Businesses
Small businesses may not have a dedicated security department, but they still need a defined reporting process.
Employees should know whether to contact an office manager, company owner, internal IT employee, or managed service provider. A printed emergency contact list can be valuable when email or company systems are unavailable.
The business should also establish an internal escalation process. A routine spam message and a suspected compromised administrator account do not require the same response. Clear priorities help ensure that urgent incidents receive immediate attention.
Frequently Asked Questions
Should employees report something even if they are unsure?
Yes. Employees should report suspicious activity and allow the appropriate person to evaluate it. A report is a request for review, not a declaration that a breach has occurred.
What should someone do after clicking a phishing link?
The employee should stop interacting with the message and contact IT immediately. They should explain what they clicked and whether they entered a password, approved a login, downloaded a file, or provided information.
Can an employee simply delete a suspicious email?
The message should be reported before it is deleted. Reporting gives IT an opportunity to investigate and remove similar messages from other employee inboxes.
Should an unknown USB drive be turned in?
Employees should follow the company’s reporting procedure without connecting the drive to any device. IT or security personnel can determine how it should be handled safely.
Does reporting a mistake automatically mean disciplinary action?
A company’s policies determine how incidents are handled, but honest and prompt reporting should be encouraged. Concealing an incident can significantly increase the potential harm.
About Professional Computer Concepts
Professional Computer Concepts (PCC) is a trusted managed IT and cybersecurity provider serving the Bay Area for over 20 years. We help small and midsize businesses simplify their IT, strengthen security, and modernize operations. Explore our Managed IT Services, Cybersecurity, and Cloud Solutions.
From PCC’s Desk
Employees should not have to determine whether something is serious before speaking up. Their job is to notice, pause, and report. Your IT or security team can take it from there.
If your employees do not know whom to contact or what to report, that is a process problem worth correcting. Let’s talk about creating a clearer cybersecurity reporting and awareness program for your business.
