What should employees do when a cyber incident occurs and every minute counts? Without clear guidance, people may hesitate, improvise or make the situation worse. Yet their first actions can have a real impact on how quickly the incident is contained.

The risk is very real. In 2025, account hacking represented 21% of assistance requests from businesses and associations received by Cybermalveillance.gouv.fr. Ransomware still accounted for 8.1%. A cyber incident response procedure should therefore focus on the essentials: recognizing the problem, reporting it quickly and avoiding actions that could make it worse.

Why prepare a cyber incident procedure before an attack?

When a suspicious message appears or a device starts behaving strangely, uncertainty is often the first problem. Employees may wonder whether they should keep working, contact IT or simply wait. A clear cyber incident response procedure for employees removes that uncertainty by providing instructions before an emergency occurs.

The procedure should also remain simple. Cybermalveillance.gouv.fr reported a 112% increase in requests related to computer hacking among professionals in 2025. A twenty-page document is unlikely to help in a stressful situation. A short, readable and easily accessible guide will usually be far more useful.

How to create a simple and effective cyber incident response procedure

Step 1: explain what should be considered a cyber incident

Not every employee has the same understanding of the word “incident”. Start with concrete examples: a phishing email, a locked account, an unexpected MFA request, a suspicious file or an unknown login. A computer displaying an unusual warning or suddenly inaccessible files should also raise concerns.

Your cyber incident response checklist does not need to cover every possible scenario. A simple rule can already make a difference: if something looks unusual, report it quickly. This prevents employees from waiting for absolute proof before asking for help.

Step 2: make it clear who employees should contact

Employees should never spend several minutes looking for the right person to call. The procedure should clearly display a phone number, email address or dedicated reporting channel. Depending on the organization, this could be the IT helpdesk, IT department, CISO or an external provider.

You should also plan a backup option. If email or Teams becomes unavailable, a phone number can keep the reporting process working. This contact information should be highly visible in your cyber incident action plan, because an effective response begins with a fast alert.

Step 3: define the first actions employees should take

Employees are not expected to resolve the incident themselves. Their main role is to avoid making it worse. Depending on the situation, the first instruction may be to disconnect the device from the network without necessarily shutting it down, then stop using it until IT provides further instructions.

These actions can help limit potential spread while preserving useful information for investigation. However, the exact instructions should match your technical environment. A cybersecurity incident procedure for employees should therefore be developed with the people responsible for your organization’s security.

Would your employees recognize the right cyber reflexes in a real situation?

Test common cybersecurity assumptions and help your teams identify the habits that can expose an organization.

Step 4: explain what employees should not do

A good procedure should also cover the mistakes to avoid. Immediately deleting a suspicious email, repeatedly restarting a computer or downloading a random security tool from the internet can make an investigation more difficult.

Employees should especially avoid hiding a mistake because they are afraid of being blamed. Anyone can click on a convincing malicious link. The sooner the incident is reported, the more time security teams have to respond. A cyber incident reporting procedure should therefore encourage transparency rather than blame.

Step 5: plan how to communicate during the incident

A cyberattack may affect the communication tools employees normally use. In that situation, everyone should know where to find reliable information. The procedure can include an alternative communication channel, an emergency contact list or a dedicated phone number.

This also prevents each department from communicating independently. During a stressful incident, conflicting messages can create even more confusion. Centralized communication helps everyone receive the same instructions and understand what they should do next.

What should an employee cyber incident checklist include?

A good checklist should be understandable within seconds. A simple sequence works well: detect → isolate → report → stop intervening → share useful information. This gives employees an easy framework to remember, even when they are under pressure.

Employees can then provide useful context, such as the time of the incident, the message displayed, the action performed just before it happened or the name of the affected file. This cyber incident checklist for employees can be added to the intranet, displayed near workstations or shared after training. Most importantly, it should always be easy to find.

What if the incident involves personal data?

Not every cyber incident automatically becomes a personal data breach. However, data loss, unauthorized access, alteration or disclosure may fall into this category. The organization must then assess the potential consequences for the people concerned.

The CNIL states that a breach presenting a risk should be reported without undue delay and, where feasible, within 72 hours. It must also be documented internally. Employees are not expected to manage this process themselves. Their responsibility is much simpler: report the incident quickly to the appropriate people.

How can employees be trained to follow a cyber incident procedure?

A written procedure is not always enough. In a stressful situation, people tend to rely on habits they have already practiced. Training scenarios can therefore simulate phishing, a compromised account or a suspicious device, then ask employees to choose the right response.

This makes cyber incident awareness training for employees much more practical. Training can help employees understand why secure configurations, access controls and everyday digital habits matter before an incident occurs.

Good cyber reflexes also depend on a properly secured working environment.

Help employees understand the essential settings and practices that strengthen computer security in everyday work.

Conclusion

Creating an effective cyber incident procedure does not require a complicated document. It mainly needs to answer four questions clearly: what should employees recognize, who should they contact, what should they do and what should they avoid? The procedure must then remain easy to access and simple enough to use without hesitation.

Training helps turn these instructions into real habits. A strong cyber incident response procedure does not replace technical teams. It simply enables every employee to contribute to a faster, more organized response when an incident occurs.

FAQ

1. What should you do first during a cyber incident?

Report the incident immediately through the channel defined by your organization. Then follow the instructions included in the internal response procedure.

2. Should you shut down a computer affected by a cyberattack?

Not necessarily. Depending on the procedure, it may be better to isolate the device from the network without switching it off.

3. Who should employees contact after a cyber incident?

The procedure should clearly identify the IT helpdesk, IT department, CISO or external provider responsible for handling the incident.

4. What should a cybersecurity incident procedure include?

It should define what must be reported, who to contact, the first actions to take, mistakes to avoid and backup communication methods.

5. Why train employees on cyber incident response?

Training helps employees identify problems faster and apply the right actions without improvising when a real incident occurs.