Module 6 of StartCloud's Cyber Hygiene for Staff learning pathway, in five short units with a knowledge check: why speed beats embarrassment, a scenario-by-scenario playbook for the first five minutes (phished password, dodgy attachment, lost device, fake invoice), how to report an incident well, and where Australia's official help lives (ReportCyber, Scamwatch, IDCARE).
Something Looks Off: What to Do in the First Five Minutes
Speed beats embarrassment
Let us get one thing sorted before anything else. Everyone clicks something eventually. IT professionals do it. Security trainers do it. People who write cyber training modules have done it, and more than once. Modern scams are well made, they arrive on your busiest day, and falling for one does not make you careless. It makes you a person with an inbox.
So this module is not about never making a mistake. It is about the only part that actually decides how bad a mistake gets: how quickly someone says something. The gap between a five-minute fix and a five-week disaster is almost never the click itself.
The password is changed before anyone gets to use it. The machine comes off the network before anything spreads. The bank recalls the payment while it is still recallable. IT sorts it before lunch, and the whole thing becomes a story for the Christmas party.
The attacker has had days inside the account. Emails have gone out under your name. The payment cleared long ago into an account that no longer exists. Now it is investigations, awkward customer phone calls and very late nights, and none of it needed to happen.
If a workmate tells you they clicked something dodgy, the only correct response is thank you. They just handed the business a head start most attackers never allow. Blame teaches people to stay quiet, and honestly, staying quiet is the only genuine mistake in this whole module. Everything else is fixable.
No theory in this unit. Four situations, and exactly what to do in each. You will notice the same shape every time: handle the one urgent thing, then tell someone. None of the steps involve fixing it yourself, and that is deliberate.
You clicked a link and typed your password
The page felt wrong the moment you hit enter. Maybe the logo was slightly off, maybe it bounced you somewhere odd, maybe it just asked twice. Treat that password as stolen from this second, because it probably is.
- Change that password now, before anything else
- Then tell IT or your MSP straight away
- Mention anywhere else you use the same password, it needs changing there too
- If sign-in or MFA prompts appear that you did not trigger, deny them and say so
You opened a dodgy attachment, or your machine is acting strangely
The file did nothing visible, or the fans are suddenly working hard, or windows are opening themselves. Either way, your job is to contain it, not to diagnose it.
- Disconnect from the network: unplug the cable or turn off Wi-Fi
- Leave the machine switched on. Powering it off can destroy the evidence IT needs
- Stop using it. No quick email checks, no last-minute saves
- Call IT or your MSP from your phone and describe what you opened
You lost a phone or laptop
Left in a taxi, lifted from a cafe table, vanished somewhere between the airport and home. It happens, and the device itself is the cheap part. The accounts and files on it are not.
- Report it immediately, even at 11pm on a Saturday
- IT can lock the accounts and wipe the device remotely, and the sooner the better
- The awkwardness of the call is nothing next to what an unlocked laptop can reach
- If it turns up again later, hand it to IT before you use it
You approved or paid a suspicious invoice
The bank details had quietly changed, or the supplier turned out not to be the supplier at all. This is the one scenario where IT is not the first phone call.
- Call the bank's fraud line first. Minutes genuinely matter for recalling a payment
- Then tell the boss and IT, together or in quick succession
- Keep the email and the invoice, they are evidence now
- Do not reply to the sender, there is nothing to negotiate
Then you are in the fifth one: something feels off and you cannot quite name it. That still counts. Call IT and describe what you saw. The worst outcome of a call about nothing is a thirty-second chat. The worst outcome of not calling is the kept-quiet-for-five-days column from the last unit.
First, who to tell: whoever your business has named for exactly this. The IT person, your MSP, your manager. If nobody has ever been named, tell your manager and let them find the right person, and maybe raise the gap at the next team meeting. In the moment, speed matters more than getting the org chart right.
Second, what to say. Less than you think. A rough report now is worth far more than a polished one later, because the clock is the whole game.
- A screenshot of what you saw, even a phone photo of the screen
- The time it happened, roughly is fine
- What you clicked, opened or typed in
- The report-phishing button in your mail app, if it has one. It files everything neatly
- Do not forward the suspicious email around the office. That just spreads the bait
- Do not delete anything. The original email and files are evidence
- Do not try to fix it quietly yourself before telling anyone
- Do not sit on it until you can explain it perfectly
"Hi, I think I clicked a phishing link on my laptop about ten minutes ago, screenshot attached." That took fifteen seconds to send and gives IT everything they need to start. A perfect write-up an hour later is worth less than that message right now. Calm, quick, done.
Sometimes an incident is bigger than one inbox, or the business simply does not have a security team on tap. Australia has genuinely good official help, most of it free, and knowing where it lives before you need it is half the value.
Australia's official channel for reporting cybercrime lives at cyber.gov.au, and the hotline, 1300 CYBER1 (1300 292 371), is answered around the clock. This is exactly who your IT person may already be on the phone to.
Run by the National Anti-Scam Centre at scamwatch.gov.au. Report scams of every flavour here, from fake invoices to dodgy texts. Your report also helps warn the next business before they pay.
A free, independent support service at idcare.org for identity theft. If personal details were exposed, their case workers help people figure out what to do next, step by step.
For anything involving payments, the bank comes before all of the above. Save the fraud line number in your phone today, not on the day you need it.
Reporting is not admitting defeat. It gets you practical help, it can get money back, and every report makes the picture clearer for the businesses that get targeted next week. You and the business up the road are on the same side here.
- cyber.gov.au: Report a cybercrime, incident or vulnerability (ReportCyber)
- scamwatch.gov.au: Scamwatch, run by the ACCC
- idcare.org: IDCARE identity theft and cyber support
Details were current at the time of writing (July 2026). Phone numbers and reporting channels do change occasionally, so check the links above for the latest.
Knowledge check
5 quick questions. Get 4 right and the module is yours.
1. You clicked a link and typed your work password on a page that felt wrong. What is your very first move?
2. You opened an attachment from a suspicious email and now your laptop is behaving oddly. What do you do?
3. You realise the invoice you paid this morning was a fake with swapped bank details. Who do you call first?
4. A workmate quietly admits they clicked a phishing link an hour ago. What is the best response?
5. Which of these belongs in a good incident report?