Module 6 of StartCloud's Cyber Hygiene for Staff learning pathway, in five short units with a knowledge check: why speed beats embarrassment, a scenario-by-scenario playbook for the first five minutes (phished password, dodgy attachment, lost device, fake invoice), how to report an incident well, and where Australia's official help lives (ReportCyber, Scamwatch, IDCARE).
Something Looks Off: What to Do in the First Five Minutes
Speed beats embarrassment
Let us get one thing sorted before anything else. Everyone clicks something eventually. IT professionals do it. Security trainers do it. People who write cyber training modules have done it, and more than once. Modern scams are well made, they arrive on your busiest day, and falling for one does not make you careless. It makes you a person with an inbox.
So this module is not about never making a mistake. It is about the only part that actually decides how bad a mistake gets: how quickly someone says something. The gap between a five-minute fix and a five-week disaster is almost never the click itself.
The password is changed before anyone gets to use it. The machine comes off the network before anything spreads. The bank recalls the payment while it is still recallable. IT sorts it before lunch, and the whole thing becomes a story for the Christmas party.
The attacker has had days inside the account. Emails have gone out under your name. The payment cleared long ago into an account that no longer exists. Now it is investigations, awkward customer phone calls and very late nights, and none of it needed to happen.
If a workmate tells you they clicked something dodgy, the only correct response is thank you. They just handed the business a head start most attackers never allow. Blame teaches people to stay quiet, and honestly, staying quiet is the only genuine mistake in this whole module. Everything else is fixable.