SECURITY SUPPORT GUIDE

Security Incident Escalation and Response Workflow

Security troubleshooting guide

Knowledge Base / Security / Security Incident Escalation and Response Workflow

Problem

A user reports unusual email activity, suspicious sign-ins, unexpected device behavior, or a possible compromise that requires an incident response path.

Security incidents must be triaged quickly and escalated through the correct process to prevent wider damage, data exposure, or service disruption.

Symptoms to check

  • User reports unexpected logins, password resets, or unusual mailbox alerts.
  • Multiple users report the same malicious email, suspicious link, or scam message.
  • Endpoints show malware, ransomware, or unauthorized software activity.

Possible causes

  • Compromised account or stolen credentials.
  • Malicious email or social engineering attempt.
  • Malware or unauthorized script execution on a managed device.

Resolution

  1. Capture the report details: user, device, time, evidence, and the exact behavior or message seen. Preserve screenshots or email samples before any cleanup steps.
  2. Check whether the issue is isolated or indicates a broader campaign, such as multiple users receiving the same phishing email or access issue.
  3. Follow the defined security process to isolate the user account, block access, or disconnect the device if risk is confirmed.
  4. Escalate the incident to the security team with the evidence and the impact level. Include whether credentials were entered, files were accessed, or a policy was altered.
  5. Coordinate recovery actions, including password resets, mailbox cleanup, endpoint review, and incident documentation before restoring normal access.

Prevention and preparation

  • Maintain a clear escalation matrix for phishing, malware, and account compromise events.
  • Train staff to report security issues quickly instead of waiting for the problem to spread.
  • Review alerts and take timely action on suspicious sign-ins, unusual forwarding rules, or blocked endpoints.

Related guides

Still not fixed? Escalate immediately if a credential may have been exposed, a mailbox was accessed from an unknown device, or malware was observed on a managed endpoint.

Submit a ticket

Last reviewed: October 2026