A convincing phishing email can reach an employee, capture a password, and begin sending fraudulent messages from a trusted account in minutes. A phishing response plan template gives your business a clear set of decisions to follow before confusion turns a single click into account compromise, payment fraud, or extended downtime.

For small and medium-sized businesses, the goal is not to create a lengthy document that sits unread in a shared folder. The goal is a practical plan that tells the right people what to do, who has authority to act, and how to return systems to normal with confidence.

Why a phishing response plan matters

Phishing remains effective because it targets everyday business processes: invoices, shared documents, password resets, payroll changes, and requests that appear to come from executives or suppliers. Even staff who are careful can be caught by a well-timed message, particularly during busy periods.

The first hour after a report matters most. If an employee has only received a suspicious email, the response may be as simple as reporting, blocking, and checking whether other inboxes received it. If they entered credentials or opened a malicious attachment, your team may need to reset access, revoke active sessions, review mailbox rules, and investigate whether sensitive information was accessed.

A documented response plan reduces hesitation. It also prevents a common problem in smaller organizations: several people trying to fix the issue at once, without preserving evidence or knowing whether the threat has actually been contained.

Phishing response plan template

Adapt the following template to your business, technology environment, and internal responsibilities. Keep a current copy where managers and your IT support provider can access it during an incident.

1. Define the incident and assign severity

Incident name: [Example: Suspected Microsoft 365 credential phishing]

Date and time reported: [Insert date, time, and time zone]

Reported by: [Employee name and contact details]

Incident owner: [IT manager, operations lead, or managed IT provider]

Severity level: Low, medium, high, or critical.

A low-severity incident is a suspicious email that was reported but not opened or acted on. Medium severity may include a clicked link with no known credential entry. High severity applies when credentials were entered, malware may have run, or a mailbox was used to send suspicious messages. Critical incidents involve confirmed financial fraud, widespread account compromise, ransomware, or exposure of sensitive customer information.

Severity should guide urgency, but do not wait for perfect certainty before taking protective action. It is usually better to temporarily restrict a potentially compromised account than to leave it active while the investigation continues.

2. Contain the threat immediately

First actions to take:

Containment is different for every incident. A suspicious email reported early may require only a mailbox search and user notification. A compromised Microsoft 365 account may require password resets, multifactor authentication checks, review of inbox forwarding rules, and a check for unauthorized access to SharePoint, OneDrive, or other cloud services.

Record every action, the person who completed it, and the time. This creates an accurate incident timeline and avoids duplicated effort when responsibility shifts between internal staff and outside support.

3. Protect accounts, devices, and business data

After immediate containment, investigate what the attacker may have gained. Review sign-in logs for unfamiliar locations, devices, IP addresses, or repeated failed login attempts. Check whether the account created mailbox rules that forward messages externally, deleted emails, changed recovery details, or sent messages to customers and suppliers.

Where a user entered credentials, reset passwords for related systems if password reuse is possible. Ensure multifactor authentication is enabled and confirm the registered authentication methods have not been changed. If the user approved an unexpected multifactor prompt, treat it seriously. Attackers may use repeated prompts to pressure users into approving access.

For a potentially affected device, run security scans and review installed applications, browser extensions, recent downloads, and endpoint security alerts. Do not assume that a computer is safe simply because it appears to be running normally. The right level of investigation depends on what was opened, the protections in place, and whether there are signs of unusual behavior.

4. Communicate with the right people

Your plan should identify who needs to know and when. Not every phishing email requires a company-wide announcement, but silence can create risk when the same message is circulating across the business.

Internal notification owner: [Name or role]

Executive contact for high or critical incidents: [Name or role]

IT support escalation contact: [Name, provider, and after-hours process]

Finance contact: [Name or role for payment-related incidents]

Customer or supplier communication owner: [Name or role]

If a compromised mailbox sent fraudulent messages, alert likely recipients quickly and plainly. Explain that the message should not be opened, that any payment or banking-detail changes must be verified through an established phone contact, and that your team is investigating. Avoid sharing technical speculation before facts are confirmed.

Finance teams deserve special attention. Business email compromise frequently involves fake invoices, changed bank details, or urgent payment requests. Any request to alter payment details should be independently verified using a known phone number, not the contact information included in the email.

5. Eradicate, recover, and verify

Once the immediate threat is contained, remove the mechanism that allowed it to persist. Delete malicious inbox rules, block confirmed malicious domains or senders, remove unauthorized applications, and remediate affected devices. If malware is confirmed, rebuild or restore the device where appropriate rather than relying only on a quick cleanup.

Recovery means more than restoring access. Confirm that passwords are secure, multifactor authentication is working, mail flow is normal, backups are available, and no unauthorized forwarding, delegation, or administrator changes remain. Review logs after the initial response as well, since attackers may attempt to regain access after a password reset.

Recovery approval: [Name or role]

Date and time systems returned to normal operation: [Insert details]

Outstanding risks or follow-up tasks: [List owners and due dates]

For higher-severity incidents, consider whether legal, insurance, contractual, or privacy obligations apply. The answer depends on the information involved, your industry, and where your customers are located. Your IT partner can provide technical evidence, while legal or compliance advisors can guide notification obligations.

Build prevention into the response process

A phishing response plan works best when it connects to everyday security practices. Staff should know exactly how to report a suspicious message, without worrying that they will be blamed for raising a false alarm. Fast reporting is a security control.

Technical controls also matter. Multifactor authentication, email filtering, endpoint protection, managed updates, least-privilege access, and tested backups each reduce the damage a single phishing message can cause. None eliminates risk on its own. Together, they give your business more time and more options when an incident occurs.

Run a short tabletop exercise at least once a year. Present a realistic scenario, such as an employee entering Microsoft 365 credentials after receiving a fake shared-document alert. Walk through who reports it, who resets access, who checks email rules, who informs finance, and how managers decide whether customers need notice. The exercise often reveals missing contact details or unclear responsibilities before a real event exposes them.

Keep the plan current and usable

Review your phishing response plan whenever you change email platforms, introduce new cloud applications, change IT providers, or reorganize key roles. Contact lists and escalation instructions age quickly, especially in growing businesses.

The best plan is short enough to use under pressure, specific enough to guide action, and supported by people who understand your systems. For Auckland businesses without a dedicated internal IT team, a managed IT partner can help tailor the plan, monitor for threats, and provide responsive assistance when a suspicious email becomes something more serious.

A well-prepared response does not make phishing disappear. It gives your people a calm, accountable way to protect the business when the next convincing message arrives.