Direct Answer
If you clicked a phishing link, report it to your IT contact immediately and work out whether you entered a password, downloaded a file, or nothing visible happened. If you entered a password, change it from a different device and have IT sign you out of all active sessions; if a file downloaded, disconnect the device from the network but leave it powered on. Then document what happened, because GDPR and NIS2 notification deadlines may apply.
Key Takeaways
Report the click right away, from your phone if the laptop is already offline.
Then work out what happened: you entered credentials, approved a login or an app, downloaded a file, or nothing visible happened. Each case needs a different response.
If you entered credentials, resetting the password and signing out every active session matters more than any virus scan, because stolen logins are often used within hours.
If a file downloaded, isolate the device but leave it powered on so IT can investigate.
If personal data was likely exposed, the GDPR gives you 72 hours from becoming aware to notify your supervisory authority. Companies in scope of NIS2 owe the BSI an early warning within 24 hours.
A phishing email only needs one distracted moment. Someone on your team is between meetings, sees a message that looks like a shared invoice or a password expiry warning, and clicks. Then comes the pause that does the real damage: should I tell anyone, or will this blow over?
Phishing is a fraud technique in which an attacker impersonates a service, a supplier, or a colleague to get you to hand over credentials, approve a login, or open a malicious file. What happens after the click depends far less on the click itself than on the next hour. This guide walks through that hour, step by step, for growing companies without an in-house IT department.
What you'll need before an incident happens
Response speed comes from preparation, not from courage in the moment. Make sure these five things exist and that someone can reach them on a bad Friday afternoon:
Admin access to your identity provider, meaning the Microsoft 365 or Google Workspace admin console.
A device management console that can lock, wipe, or isolate a laptop remotely.
A password manager, so resets don't turn into an hour of guessing which accounts shared a password.
One named contact, internal or external, who is allowed to disable accounts without waiting for approval.
A simple incident note template: what happened, when, which accounts, what was done.
If you can't name that contact today, start there. Our guide to security without an IT department covers how small teams assign this responsibility without hiring.
Step 1: Report the click right away
Reporting comes before everything else, including your own troubleshooting. Your IT lead or IT partner can check whether the same message landed in other inboxes, pull it from those mailboxes, and block the sender domain before anyone else clicks.
Say what you clicked, what the page asked for, and whether you typed anything. Guessing wastes minutes. If your laptop is already offline, report from your phone or call. Don't wait until the device is back online.
One cultural note for founders and office managers: never punish the person who reports. Teams that treat a click as a mistake to hide lose hours, which is exactly why security awareness training for employees focuses as much on reporting as on spotting.
Step 2: Isolate the device if anything downloaded
Turn off Wi-Fi, unplug the ethernet cable, or switch a phone to airplane mode. If anything was downloaded, cutting the network stops it from reaching the attacker's command-and-control server, exfiltrating files, or spreading to shared drives. If you only entered credentials and nothing downloaded, you can skip this step, because the attack is happening in your cloud accounts, not on the laptop.
Leave the machine powered on. A running system keeps evidence in memory that disappears on shutdown, and a specialist may need it later. If your company uses managed endpoint protection, IT can usually isolate the device remotely. That blocks all network traffic except the connection to the security tool, so the device stays contained while IT investigates.
Step 3: Work out what happened
The correct follow-up depends entirely on what the link did. Work out which of these four cases applies:
You entered credentials on a fake page. This is the most common outcome. Assume the attacker already has a working login and go straight to Step 4.
You approved a sign-in prompt or granted an app access to your account. Treat this like stolen credentials, with one difference: a password reset doesn't remove an app's permissions, so IT has to revoke the app's access too.
A file downloaded or an attachment opened. Drive-by downloads can install keyloggers or ransomware with no further clicks. This is the malware path, so make sure the device is isolated as described in Step 2.
Nothing visible happened. The page may have been dead, or your browser or DNS filter blocked it. The risk is low, but document it anyway.
Tell your IT contact which case applies, because it decides whether the priority is your accounts or your hardware.
Step 4: Reset passwords and sign out all sessions
What you do: Use a different, clean device for this. Go directly to the official site by typing the address, never through a link in the suspicious email. Change the password for the affected account first, then every other account that shared it.
What IT does: Then comes the part most people skip, which is signing the user out of all active sessions in the Microsoft 365 or Google Workspace admin console. A stolen session token lets an attacker stay logged in even after a password change, and multi-factor authentication won't stop a session that is already open. In Microsoft 365, some access can stay valid for up to about an hour after sessions are revoked, so if you see active misuse, block the user's sign-in first. IT should also remove any MFA methods or devices the attacker registered, because that's how attackers get back in after a reset.
In Verizon's 2026 Data Breach Investigations Report, phishing and stolen credentials together were the way in for 32% of breaches (Verizon), which is why this step outranks the virus scan.
Step 5: Check for signs of attacker access
Don't reconnect the device to scan it yourself. IT can run a full scan remotely through the endpoint protection tool while the device stays isolated, and a quick scan isn't enough. If anything is flagged, a specialist decides whether to clean or reinstall the device.
On the account side, open the recent activity log for the affected user and look for sign-ins from unfamiliar locations or devices. Check the mailbox for new forwarding rules, new inbox rules, and newly authorized third-party apps. Attackers set up quiet forwarding so they can read invoices and payment threads long after the password has been changed. Look through Sent Items for phishing emails the attacker sent from the account, and warn those recipients if any went out. If money was sent or bank details were changed, call your bank immediately, because the window to recall a transfer is short.
Step 6: Document, notify and close the gap
Write down the timeline while it's fresh: when the email arrived, when it was clicked, when it was reported, which accounts were touched, and what you did in response. This record is what auditors and insurers ask for, and it's the same evidence trail that supports ISO 27001, GDPR and NIS2 requirements.
Under GDPR Article 33, you must report a personal data breach to your supervisory authority within 72 hours of becoming aware of it, unless the breach is unlikely to put people's rights and freedoms at risk. If the risk is high, Article 34 also requires you to inform the affected people directly. The clock starts at awareness, not at the click. Even when no report is required, you still document the incident and the reasoning behind that decision.
If your company falls under NIS2, German law has required an early warning to the BSI within 24 hours of a significant incident since December 2025. Check your cyber insurance policy too, because many insurers require prompt notification and some expect you to call their incident hotline before you hire outside forensics.
Finally, fix what let it through. Turn on MFA wherever it was missing, review the anti-phishing settings in Microsoft 365 under Threat Policies, or apply the equivalent Google Workspace phishing protections. Both are quick wins with visible effect.
What can an attacker do after a phishing click?
With a working login, an attacker can read and send email as the employee, set up forwarding rules to watch payment threads, open shared drives and the CRM, and use the account to phish colleagues and customers. If malware was installed, they can log keystrokes, steal passwords saved in the browser, or encrypt files across shared drives. That's why first-response guidance from Germany's BSI and the US agency CISA both put fast reporting first.
Troubleshooting: what if the response stalls?
"I can't get into the admin console." Use a break-glass admin account or call your IT partner. Every company should have a second admin that isn't tied to one person's laptop.
"The scan found nothing, but the device behaves strangely." A clean scan is not proof. Keep the device off the network and get a professional to look deeper before it goes back into daily use.
"We don't know what data was on the machine." That uncertainty is itself the finding. The same problem shows up when a company device is lost or stolen, and it argues for enforced disk encryption and a current device inventory.
"An enterprise client is asking what happened." Answer with your documented timeline. It's the same material you'd use for an ISO 27001 audit evidence check or a customer security questionnaire.
How do you recognize a phishing link before you click?
Check the domain, not the display text. Hover over the link on a desktop, or press and hold on mobile, and read the domain, which is the part just before the first single slash after https://. A message from "Microsoft" pointing to login-microsoft-secure.co is fake, however convincing the logo looks. QR codes in emails and PDFs hide the link entirely, so treat any QR code that leads to a login page with the same suspicion.
Beyond the URL, three signals do most of the work: unexpected urgency ("your account will be locked today"), a login prompt that appears after clicking rather than because you went looking for one, and a request to move money or change bank details. Spelling mistakes used to be the giveaway, but AI-generated phishing has largely removed that tell.
Prevention is where the economics favor you. IBM's 2026 Cost of a Data Breach Report found that phishing was the most common initial attack vector for the fourth year in a row, and the global average cost of a breach reached a record USD 4.99 million (IBM). A practical baseline for a small company looks like this:
MFA on every account, starting with email. Where your provider supports them, use phishing-resistant methods like passkeys, because many phishing kits now capture push and SMS codes along with the session. Add role-based access so a single compromised login reaches less, and set it up at hire, as covered in our notes on onboarding security risks.
Managed endpoint protection and automated patching on every laptop, the core of any layered small business security strategy.
Full disk encryption with stored recovery keys, which also protects remote staff. See our secure home office checklist.
Tested backups following the 3-2-1 rule, explained in this backup and recovery guide for SMBs.
deeploi, the All-in-One IT Management Platform for SMBs, bundles device management, encryption enforcement, access control and endpoint protection into one console, with expert support included. That keeps these controls switched on instead of depending on someone's memory.
FAQ
What happens if I ignore a phishing click and do nothing?
Attackers rarely wait. With valid credentials they can read email, add forwarding rules, reach shared drives and your CRM, and impersonate the employee to reroute an invoice, often within hours. Doing nothing also destroys the timeline you'd need later to show regulators or customers that you acted with care.
Does every phishing click have to be reported to the data protection authority?
No. You must notify the authority when personal data was affected, unless the breach is unlikely to put people at risk. A blocked link with no credential entry usually stays internal. You should still record it, because Article 33(5) requires you to document every personal data breach, including the ones you don't report. When in doubt, ask your data protection officer quickly.
Can clicking a link infect a device without downloading anything?
It's possible but uncommon on an updated system. Drive-by downloads exploit unpatched browser vulnerabilities, which is why automated patching matters more than most people assume. On a current browser, the realistic risk from a single click is a credential harvesting page, not silent infection.
Am I liable if I clicked a phishing link at work?
Usually not. In Germany, employees are generally fully liable only for intent or gross negligence, and an ordinary click on a convincing phishing email rarely meets that bar. Hiding the click is a different matter, because a delayed report can make the damage much worse. This isn't legal advice, so check specific cases with an employment lawyer.
What if I clicked the link on my phone?
The same steps apply. Report it, switch the phone to airplane mode if anything downloaded, and change your password from a different device. If it's a managed company iPhone, IT can check it remotely through device management.
Is MFA enough to protect us?
MFA stops most password-only attacks, but not all phishing. Modern phishing kits can capture a push or SMS code along with the session itself, and some trick users into approving a prompt. Phishing-resistant methods like passkeys or security keys close that gap, because they only work on the real site.
Next steps
Print the six steps above, put them somewhere your team can find them, and rehearse the first two once. The reporting habit and the offline reflex are what separate a five-minute incident from a three-week one. Everything after that is process, and process is easier when your devices, accounts and security policies sit in one managed place instead of six.
Note: This article is for general information only and does not constitute legal advice. Notification duties under the GDPR and NIS2, as well as questions of employee liability, depend on your specific situation and jurisdiction. For a binding assessment, consult your data protection officer or a qualified lawyer.
%25402x.png)









