← Email & Phishing

runbook

Build a Phishing Reporting Workflow People Will Use

Build a safe, low-friction workflow for reporting suspicious messages, acknowledging reports, escalating uncertainty, giving feedback, and learning without blame.

For

An owner or operations lead whose team lacks a clear, low-friction route for reporting suspicious messages and receiving feedback.

Not for

Live forensics, malware analysis, account recovery, containment, legal notification, provider-specific report-button instructions, or active-incident handling.

Failure addressed

An unclear or punitive process suppresses reporting, spreads unsafe content, or delays escalation after user interaction.

A useful phishing-reporting workflow does not begin by asking a colleague to investigate a suspicious message. It gives them a safe, easy route to raise concern, confirms that someone owns the next step, and tells them enough to stop unsafe improvisation.

This guide builds that workflow for a small team. It does not decide whether a message is safe or malicious, and it does not replace qualified incident response.

Keep eight workflow concepts separate

A report is a signal of concern. An acknowledgement confirms receipt. Known interaction facts record only what the reporter already knows they did. Triage is a bounded preliminary assessment by an authorized owner. Escalation routes uncertainty or a trigger to qualified help. An incident handoff ends this routine workflow. Feedback tells the reporter what they can safely know. Closure and learning record what finished, what remains unresolved, and what the process should improve.

Reporting, acknowledgement, known facts, triage, escalation, incident handoff, feedback, and closure cannot be reduced to one resolved checkbox.

The reporter is never required to decide whether a message is safe, malicious, phishing, spam, fraud, or part of an incident.

Use this exact inert reference wherever the workflow needs to point to the original report:

Message reference held in approved system — content not copied

Do not copy, forward, or retransmit the sender, recipient, address, subject, body, headers, links, QR codes, attachments, screenshots, or identifiers into this record. If an approved reporting system retains the original, reference its location generically; do not reproduce its contents.

Evidence informs the workflow but does not define it

CISA advises people not to interact with suspicious links or attachments and to report suspected phishing. NIST advises notifying appropriate people internally and following the organization’s incident-response plan after suspected victimization. NCSC recommends a clear, simple reporting process, quick feedback, and a supportive culture rather than relying on users to identify every phish.

The eight stages, nine states, escalation model, acknowledgement pattern, fields, closure criteria, and review moments below are PlainFort editorial judgment. They are not CISA, NIST, or NCSC requirements, an incident-response standard, a service-level guarantee, proof of correct triage, or a universal workflow.

Build the workflow in eight stages

1. Prepare the safe route and ownership

Name an internally accountable owner, an authorized triage owner, a real backup with access and authority, and an escalation destination. Define an accessible primary route and an alternate route for when the primary channel is unavailable or itself suspected.

A provider may operate intake or triage, but it does not become the team’s implicit internal owner. Treat provider buttons, retention, automation, and investigation behavior as volatile until current primary documentation confirms them.

2. Receive an inert report

Ask only for the reporter’s role, a received time band, the approved route used, the inert reference, and a category-level interaction state. Never ask the reporter to forward the message, open an attachment, follow or hover over a link, scan a QR code, reply, contact the apparent sender, or inspect technical details.

3. Acknowledge receipt

Confirm that the report entered the workflow. Name the next responsible role and repeat what the reporter should not do. Acknowledgement is not a triage conclusion and never implies that the message is safe.

4. Record known facts and uncertainty

Record only known categories: no interaction reported, link followed, attachment opened, QR scanned, information entered, payment information disclosed, or unknown. Do not collect the content itself. Missing information becomes Unknown — follow up through approved route, not a demand for unsafe evidence.

5. Apply bounded triage and escalation states

The authorized triage owner records a preliminary workflow state and compares known facts with the escalation triggers. The reporter does not make this assessment. This guide provides no message analysis, severity score, or live response procedure.

6. Hand off when the routine workflow stops

A payment-change concern routes to EP-14, which owns independent verification and authorization before money moves. Suspected mailbox compromise routes to EP-15 and qualified response. Preserve ownership and a non-sensitive evidence-location reference, but do not reproduce either guide’s steps here.

7. Give safe feedback without blame

Tell the reporter that the report was received, routed, or closed at the appropriate level. Do not disclose sensitive findings or rank the reporter. Feedback should encourage future reporting, including after a click or mistake, rather than reward silence or certainty.

8. Close, learn, and review

Record closure evidence, unresolved risk, reporter feedback, a process-learning note, and the next review trigger. Closure does not prove the message safe, the triage correct, the account uncompromised, or the incident contained.

Use workflow states, not verdicts

  • Reported
  • Acknowledged
  • Triage pending
  • Escalated
  • Incident handoff required
  • Closed with feedback
  • Unknown — follow up through approved route
  • Blocked — qualified help required
  • Deferred — owner and review trigger required

These states describe workflow position, not a message verdict, risk score, severity rating, security maturity, or response success. Closed with feedback does not mean safe, benign, false positive, contained, or no incident.

Do not close a report merely to meet a metric when evidence is incomplete, authority is absent, the triage owner is unavailable, the safe route failed, or an escalation trigger exists.

Stop at escalation triggers

Stop this routine workflow when a link was followed; an attachment or QR code was opened or scanned; credentials, payment information, or business data may have been entered or disclosed; a payment or account-change request is involved; mailbox compromise is suspected; multiple recipients, a privileged mailbox, a malware indication, or wider impact may exist; or ownership, evidence authority, legal, privacy, records, or incident status is unclear.

These are escalation triggers only. Do not use this guide to reset a password, revoke a session, inspect a mailbox or header, isolate a device, delete a message, contact an apparent sender, notify affected parties, recover funds, preserve forensic evidence, or perform containment, recovery, or investigation.

Create the 16-field reporting and closure record

Use a vertical record rather than a wide table or message repository:

  1. Received time band: A non-precise operational time window.
  2. Reporter role: A generic role, not a person’s identity.
  3. Safe contact route category: The approved intake category and alternate if needed.
  4. Non-sensitive message reference: Message reference held in approved system — content not copied.
  5. Known interaction state: A category already known to the reporter, or Unknown — follow up through approved route.
  6. Affected account or system category: A generic category only.
  7. Acknowledgement owner and state: Who acknowledges and whether it is complete.
  8. Triage owner: The authorized internal role or named operating role.
  9. Preliminary workflow state: One of the approved non-scoring states.
  10. Non-sensitive evidence-location reference: Where authorized evidence is held, without copying it.
  11. Escalation threshold and result: The trigger checked and the route taken.
  12. Incident or dedicated-guide handoff: EP-14, EP-15, qualified response, or not currently triggered.
  13. Reporter feedback state: Pending, delivered safely, blocked, or deferred with ownership.
  14. Closure state and evidence: What closed and what evidence was inspected.
  15. Unresolved risk: What remains unknown, blocked, deferred, or outside this workflow.
  16. Review and learning trigger: What should cause the workflow or this record to be revisited.

Completion means every field is truthful or visibly unknown, blocked, or deferred. It does not prove correct triage, message safety, containment, or absence of compromise.

Work through a fictional example

Fictional example — do not copy as a completed email-security record. This example contains no message sample, address, domain, person, account, link, attachment, identifier, payment detail, or incident fact.

  1. Received time band: Current business period.
  2. Reporter role: Operations team member.
  3. Safe contact route category: Approved internal reporting route; alternate owner route available.
  4. Non-sensitive message reference: Message reference held in approved system — content not copied.
  5. Known interaction state: Unknown — follow up through approved route.
  6. Affected account or system category: Business mailbox category.
  7. Acknowledgement owner and state: Operations backup; Acknowledged.
  8. Triage owner: Authorized operations lead.
  9. Preliminary workflow state: Triage pending.
  10. Non-sensitive evidence-location reference: Approved system reference only; content not copied.
  11. Escalation threshold and result: Interaction remains unknown; Escalated for qualified review.
  12. Incident or dedicated-guide handoff: Incident handoff required if compromise is suspected; EP-15 boundary recorded.
  13. Reporter feedback state: Receipt confirmed without a safety verdict.
  14. Closure state and evidence: Not closed; evidence review pending.
  15. Unresolved risk: Interaction and wider impact remain unknown.
  16. Review and learning trigger: Revisit after qualified handoff, route failure, ownership change, or recurring reporting friction.

Review the workflow without blaming reporters

Review when ownership changes, the primary route fails, a backup cannot act, reports repeatedly lack acknowledgement, handoffs remain unresolved, provider behavior changes, or people avoid the route. Useful process measures can expose acknowledgement coverage, missing ownership, overdue handoffs, and review debt. They cannot prove security or individual competence.

The workflow is ready for local editorial review when its owners and backups are real, the route and alternate are accessible, every state has a responsible next step, the handoff boundaries are understood, and the fictional record can be completed without copying sensitive content. Public use remains a separate decision.