When Something Goes Wrong
Use incident first aid for suspicious clicks, stolen credentials, malware, payments, and lost devices.
In this lesson, you will learn to:
- Choose safe first actions for common incidents.
- Report observations and actions without destroying useful evidence.
When Something Goes Wrong
A recovery-centered lesson that prioritizes safety, fast containment, accurate reporting, and learning without shame.
Stop the action and prevent the next one
If a page asks you to run a command, stop. If a suspicious file begins downloading, do not open it. If you approved an unfamiliar login, deny further prompts and inspect the account from a known route. If malware may be active, disconnecting the affected device from networks can limit communication, but do not erase or reset it before obtaining appropriate guidance when evidence or important data matters.
Match the first action to the incident. A disclosed password needs a clean sign-in route, password change, session review, and MFA inspection. A payment scam needs immediate contact with the financial provider through a known number. A lost phone needs remote-lock or erase decisions, carrier contact where relevant, and account review. In a workplace or school, report early so specialists can coordinate containment.
Preserve facts, not a heroic investigation
Write down when the event happened, what you saw, which account or device was involved, which links or files you used, what information you entered, and what actions you already took. Preserve the original message, transaction reference, or screenshot if doing so is safe. Describe observations separately from conclusions: “I entered my password at 14:10” is more useful than “the hacker owns everything.”
Do not keep clicking to see what happens, contact the suspected attacker, or send live links to friends. Avoid deleting logs and messages in a panic. At work, follow the incident channel; at home, contact the affected service, bank, device provider, or relevant national authority. Honest scope lets responders choose the right actions. Shame and delay give attackers more time.
Recovery ends with a safer next time
Once immediate harm is contained, inspect the path that made the incident possible. Was a password reused? Did a search advertisement replace a known download route? Did urgency prevent a callback? Was recovery dependent on the lost device? Change the weakest step and record the improvement.
Watch for secondary effects. A compromised mailbox may contain reset messages and personal details. Stolen browser sessions can sometimes remain useful even after a password change, so sign out other sessions. Contacts may receive messages from your identity. Financial and identity harm can surface later. Recovery therefore includes monitoring, notification, and follow-up—not only removing one file. The learner’s goal is resilience: notice sooner, limit damage, restore safely, and carry the lesson forward.
Resources
- NIST SP 800-61 Rev. 3 — Use NIST’s final 2025 incident-response guidance as a deeper reference for preparation, detection, response, and improvement.