It usually starts with a small flicker of doubt. An employee opened an email that looked like a vendor invoice, a delivery notice from the warehouse, or a quick request from the boss. They clicked the link. Maybe they typed their password into the login page that loaded next. Maybe they only previewed the attachment. Either way, the question on every owner’s mind is the same: how bad is this, and what do we do right now?
The honest answer is that the first hour matters more than almost anything else you will do this week. A click is not always a breach, but it is always a window. The right response in that window can mean the difference between a five-minute password reset and a six-figure incident with insurance, customers, and the bank involved.
This is a working playbook for small and mid-size businesses on the Treasure Coast. It walks through what happens behind the scenes after a click, what to do in the first sixty minutes, how to tell if the attacker is already inside your systems, and when to call in outside help.
What Actually Happens The Second An Employee Clicks?
A phishing click is not one thing. Different campaigns are designed to do different things the moment the link is opened, and the response depends on what was actually triggered. Most of the messages reaching Treasure Coast inboxes today fall into one of three buckets.
The first is a credential capture page. The link opens what looks like a familiar login screen, often a copy of the company’s Microsoft 365 or accounting software sign-in. If the user types their email and password, those credentials are sent to the attacker in real time. Within minutes, automated scripts try those credentials against email, file sharing, banking portals, and any other site reachable from the public web.
The second is a payload delivery. The link or the attached file kicks off a download in the background. Sometimes the file installs a remote access tool that lets the attacker drive the workstation later. Sometimes it drops a credential stealer that scrapes saved browser passwords, cookies, and authentication tokens. The user sees a blank page or a generic error and assumes the message was broken.
The third is a consent grant. The link opens a legitimate Microsoft or Google consent dialog asking the user to allow a new application access to their mailbox or files. A rushed click here gives the attacker a long-lived token that does not depend on the password. Even resetting the password later will not revoke it.
In any of these scenarios, the attacker’s goal is usually the same: stay quiet, watch traffic, and wait for an opportunity to interfere with money or data. Hardening the inbox so fewer phishing scams reach staff in the first place, with strong filtering, sender authentication, and link rewriting, is the upstream half of the problem. The downstream half, which we are about to walk through, is responding well when one slips through.
What Should You Do In The First Hour After A Click?
The first hour is about containment and signal collection, not investigation. Investigation comes later. Right now, the goal is to make sure the attacker cannot do anything with whatever they captured. Six steps, in this order, work for almost every scenario.
Disconnect the device from the network. Unplug the Ethernet cable, turn off Wi-Fi, or have the user step out of range. This stops any in-progress download, breaks active sessions to internal file shares, and prevents lateral movement to other machines. Do not power the machine off yet, because memory and running processes are still useful for later analysis.
Reset the password on every account the user had open in a browser tab that morning, not just the one they typed into. Modern browsers share session cookies across tabs, and a credential stealer pulled in step one may have copied them all. Start with email, then payroll, accounting, and any banking portal the user touches in a normal workweek.
Force a sign-out from every active session. In Microsoft 365 this is the sign-out-everywhere or revoke-sessions action on the user account. In Google Workspace it is the sign out from all sessions toggle. This kicks the attacker out of any token they already have, including refresh tokens that survive a password change.
Re-enroll multi-factor authentication for the affected user. Delete the existing app registration and have them set up a new one. If the click was on a consent prompt, the attacker may have an authentication token that bypasses the password and the original second factor entirely. A fresh enrollment severs that link.
Check the mailbox for new forwarding rules and inbox rules. Attackers create rules that forward incoming invoices and password reset emails to an external address, or that quietly move replies to a hidden folder so the user cannot see them. If you find one you did not create, delete it and write down what it did.
Loop in IT or your managed services partner. Even if you handle most of the steps above in-house, the next phase, deciding whether the breach extended past the original user, calls for someone who can pull sign-in logs, audit OAuth grants, and check for endpoint indicators across the rest of the fleet.
How Do You Tell If The Attacker Already Got In?
A clean response feels boring. Logs look normal, no money moved, the help desk closes the ticket. That is the good outcome. A bad outcome leaves traces in places most owners would never think to look. Here is the short list of indicators to check, in order of how quickly they tend to show up.
Sign-in activity from an unfamiliar location is the most common early signal. In Microsoft 365 the Entra ID sign-in logs will show the IP address and approximate city for every login in the last 30 days. A successful sign-in from a state or country the user does not visit, especially within hours of the click, is a strong indicator that the captured credentials were used.
Mailbox auto-forwarding to an external address is the second signal and the costliest if missed. The attacker sets up a rule that copies every incoming message to an outside mailbox. They sit silently for weeks, learning who pays whom and when, then strike during a wire transfer or vendor change. Review the mailbox rules for every account the user accessed and for any admin account they could have reached.
New OAuth consent grants are the third signal. In Microsoft 365 this is the Enterprise Applications list. In Google Workspace it is the third-party application access view. An app the user did not install, especially one with mailbox or file scopes, almost always means the click was on a consent prompt. Revoke it immediately and note when it was added.
Unexpected MFA prompts on other employees’ phones can be a fourth signal, especially if the attacker has moved from credential capture to MFA fatigue tactics. If two or three users mention odd push notifications in the days after one click, treat it as a connected event, not three coincidences.
Outbound emails the user did not send round out the list. A short scan of the Sent Items folder, the Sent Recoverable Items folder, and the message trace for the affected mailbox usually surfaces anything the attacker sent during the window they had access. If even one phishing message was sent from the compromised account to a customer or vendor, that customer or vendor needs a direct call.
If any of these signals show up, the incident has crossed the line from near miss to breach and the response shifts again. Most Treasure Coast businesses get there faster with managed cybersecurity services than with internal staff, simply because the tooling for sign-in log analysis and OAuth audits is already in place.
When Should You Bring In Outside Help?
Not every click needs an outside incident response team. A user who typed credentials into a fake login, immediately realized it, and let IT reset the password within thirty minutes is usually contained without external help. The bar for bringing in help comes down to four trigger questions.
Was the affected account a global admin, a finance role, or someone with access to client data? Compromise of any of these accounts changes the legal and contractual obligations of the response. A regular help desk reset is not sufficient documentation if a notification obligation kicks in later. An outside team can produce the timeline and evidence package that your cyber insurance carrier and any regulator will want.
Was money moved or attempted? If the attacker placed even one unauthorized payment instruction, requested a vendor banking change, or contacted a customer pretending to be the user, the response moves into a wire recovery and fraud investigation track. Speed matters here. Banks can sometimes recall a fraudulent transfer in the first 24 to 48 hours and almost never after seven days.
Did the user grant OAuth consent or install software? Persistent access through a third-party app or a remote management tool is harder to remove than a captured password. These cases benefit from professional review of every workstation the user touched, not just the obvious one.
Is your cyber insurance policy active? Most policies require notification to the carrier’s incident response panel within a fixed window, sometimes as short as 24 hours, regardless of whether you think the breach is contained. Calling outside help and the carrier at the same time keeps coverage intact and assigns legal privilege correctly.
In every one of these cases, the foundation of a calm response is having an incident response plan written down and rehearsed before the click happens. The plan does not need to be long. It needs to name the decision maker, list the carrier and outside firm to call, and define what gets disconnected, reset, and reviewed first.
Where Should A Small Business Start Tightening Up?
If the only honest answer to what would we do if someone clicked tomorrow is I am not sure, there is room to tighten things up before the next test. Start with the basics. Confirm MFA is enforced on every account, not just optional. Confirm sign-in logs are retained long enough to investigate something noticed three weeks late. Confirm one person, not the whole team, is the named decision maker when an incident is suspected.
Then move to the proactive layer. Quarterly review of mailbox rules and OAuth grants catches attackers who got in months ago and have been quiet. Lightweight tabletop exercises, run for thirty minutes once a quarter, surface the gaps that real incidents always find. A short standing relationship with a local managed IT help desk shortens the time between someone clicked and we know what we are dealing with.
The click itself is rarely the end of the business. It is almost always the start of a decision you would rather make calmly than at 4 p.m. on a Friday.
Frequently Asked Questions
Does clicking a phishing link always lead to a breach?
No. Many clicks open a credential capture page that the user closes without typing anything, or a payload that fails to install because of existing endpoint protection. The risk is not zero, but a fast disconnect-and-reset response usually contains it before any data is touched. The point of the first-hour playbook is to make sure you do not have to guess.
Should I tell the whole team that one employee clicked?
Yes, in a non-blaming way. Other employees almost certainly received the same message and may have clicked too. A short note explaining what happened, what to look for, and who to contact if they think they may have clicked the same link recovers more value than punishing one person. The user who reported it should be thanked, not embarrassed.
Do we need to notify customers or law enforcement right away?
Customer notification depends on whether any of their data was touched. If your investigation finds that the attacker accessed mailboxes containing customer files or pretended to be the user in outbound emails, a direct call to those customers should happen within the same business day. Law enforcement reports through the FBI Internet Crime Complaint Center help recovery in wire transfer cases and are recommended even when the dollar amount is small.
Can I just delete the email and move on?
Only if the user is absolutely certain they did not click the link, type a password, or open an attached file. Even hovering over the link can reveal the user’s IP address and browser, which is harmless on its own but useful intelligence to the attacker. When in doubt, treat it as a click and run the short version of the playbook.
How long should we monitor the affected accounts?
Plan on 60 to 90 days of heightened attention. Many attackers wait several weeks before acting on captured credentials, partly to avoid triggering an obvious connection to the original email. Daily review of sign-in logs and mailbox rules during this window catches almost all delayed activity.
Will our cyber insurance cover the response?
Usually yes, but only if you notify the carrier promptly and use their approved incident response panel. Most policies have a notification window of 24 to 72 hours from discovery. Calling the carrier before doing anything irreversible, such as wiping the workstation, also preserves the forensic evidence the carrier may require.
What change makes the next click less harmful?
Three changes do most of the work. Enforce multi-factor authentication on every account, with phishing-resistant methods like passkeys where possible. Reduce the number of accounts with administrative privileges, since fewer admin accounts means fewer high-value targets. Turn on email link rewriting and attachment sandboxing so the next message that gets through is intercepted before the user can click.