High School BeginnerModule B9Lesson 6 of 7

B9.6 Reporting Workflows and Trusted Help

Learn how to stop interaction, preserve safe evidence, write a clear report, choose the right trusted contact, and support containment and recovery after a phishing event.

Lesson Progress

Reporting Workflows and Trusted Help

High School BeginnerB9: Phishing and Social Engineering Defense • Lesson 6 of 7

86% complete

Readiness Check

Before You Start

0/3 ready

Professional Hook

A Strong Report Helps Defenders Act Faster

Technology staff cannot respond effectively to “something looked weird” alone. A clear report explains what happened, when it happened, what the sender requested, which warning signs appeared, what the user did, and whether any account or device changes followed.

Safety reminder: all reports, accounts, devices, messages, files, senders, and support contacts in this lesson are fictional.

Learning Objective

Preserve safe evidence without interacting with or spreading suspicious content.

Learning Objective

Write a clear report that includes timeline, sender, request, warning signs, actions, and impact.

Learning Objective

Choose the correct trusted contact and support containment and recovery.

Why This Matters

Silence and Delay Can Increase the Impact

People sometimes hide a click, reply, payment, or login because they feel embarrassed. Fast reporting gives trusted responders a better chance to protect accounts, devices, files, money, privacy, and other users.

Visual Diagram

The Reporting and Trusted-Help Workflow

Strong reporting stops interaction, preserves safe facts, reaches the correct trusted person, and supports containment and recovery.

1

Stop interaction

Do not click, reply, call, pay, approve, download, open, forward, upload, or test suspicious content.

2

Record safe facts

Note the time, sender, subject, channel, displayed domain, filename, request, and warning signs.

3

Report to the right person

Use the approved school, family, workplace, service, or technology-support reporting path.

4

Secure and follow up

Contain account or device risk, complete trusted recovery steps, and monitor for additional signs.

Defender rule: reporting quickly and honestly is safer than hiding a mistake or continuing to investigate.

Core Concept

Report Facts, Not Secrets

A useful report describes the event clearly without including passwords, MFA codes, recovery codes, private data, or dangerous content. The goal is to give trusted responders enough information to act safely.

Key Vocabulary

Terms for Reporting and Trusted Response

Incident report

A clear record of what happened, what evidence was observed, what actions were taken, and who was notified.

Trusted contact

A verified adult, teacher, guardian, supervisor, administrator, or technology professional who can help handle a security concern.

Escalation

Moving a serious or unclear security issue to someone with the authority, tools, or responsibility to respond.

Evidence preservation

Keeping useful safe details such as time, sender, subject, displayed domain, filename, and account alert without opening or spreading suspicious content.

Containment

Immediate defensive action that limits possible harm, such as denying prompts, removing unknown sessions, or stopping device use.

Recovery action

A trusted step used after containment, such as replacing credentials, reviewing MFA, restoring settings, or using an approved backup.

Technical Breakdown

Reporting and Escalation Board

A strong report helps the right person understand the event and choose the next defensive action quickly.

Safe evidence

Review question

What can be recorded without exposing secrets or interacting with suspicious content?

Safer choice

Record time, sender, channel, subject, displayed domain, filename, request, and observed behavior.

Correct contact

Review question

Who has the authority or responsibility to help with this account, device, school, family, or service?

Safer choice

Use the official reporting path, trusted adult, administrator, or technology team.

Immediate containment

Review question

Is there current unauthorized access, repeated MFA activity, suspicious file behavior, or an exposed credential?

Safer choice

Deny prompts, remove unknown sessions, stop risky interaction, and secure the affected account or device.

Follow-up recovery

Review question

What approved steps are needed after the immediate risk is contained?

Safer choice

Replace credentials, review MFA and recovery, update systems, monitor activity, and use trusted backups if needed.

Fake Dashboard

Reporting Workflow Review Panel

This fictional panel connects common phishing evidence with the correct reporting, escalation, containment, and recovery route.

Fake Data

Suspicious school email

Unknown sender requests a password and MFA code

Do not reply. Report through the school phishing process and contact technology staff through the official directory.

Unexpected login prompt

MFA request appears when the student is not signing in

Deny it, review official account activity, remove unknown sessions, and tell a trusted adult or support team.

Possible device issue

Files change names after a suspicious download

Stop using the device and report immediately to trusted technology staff.

Fake support call

Caller requests a recovery code

End the call, preserve safe details, and contact the organization through a known official number.

Suspicious social request

Copied profile asks for emergency money

Do not pay. Verify the person through another known channel and report the profile if needed.

Fake Dashboard

Fake Phishing Reporting Dashboard

Training dashboard using fictional reports, escalation paths, containment actions, and recovery results.

Reports reviewed

18

Fictional email, text, phone, social, account, and device incidents.

Reports with clear timelines

14

Included time, channel, sender, request, action, and observed impact.

Escalated correctly

12

Reached trusted adults, official support, or technology staff.

Fake SOC Alert

Suspicious Link Click Followed by Unknown Login

Source: Fake School Incident Training • Time: 2:23 PM

High Severity
A fictional student clicked an email link, entered a password, then received an unexpected MFA prompt and saw an unknown browser session.
Defensive recommendation: Deny prompts, remove the unknown session, replace the exposed credential, review MFA and recovery, and report the event to school technology staff immediately.

Fake Log Panel

Fake Reporting Workflow Log

training-log-viewer.log
14:08:17 MESSAGE channel='email' sender='unknown_address' request='account_login'
14:10:41 INTERACTION link_opened='true' password_entered='true'
14:12:09 MFA_PROMPT expected='false' action='denied'
14:14:33 SESSION browser='unknown' status='removed'
14:18:26 REPORT recipient='school_technology_staff' safe_facts='included'
14:23:02 RECOVERY credential_replaced='true' mfa_reviewed='true' monitoring='enabled'

Training note: this is fake data for defensive analysis practice only.

Analyze the Evidence

What Should This Report Include?

A fictional student clicked a suspicious link at 2:10 PM.
The student entered a password but denied the MFA prompt.
An unknown browser session appeared and was removed.
The student has not shared any password or code with technology staff.

Which report is most useful and safe?

Common Mistakes

Mistakes That Weaken Reporting and Recovery

Deleting useful evidence before a trusted person can review it.
Forwarding suspicious links, attachments, or messages to classmates.
Including real passwords, MFA codes, recovery codes, or private information in a report.
Waiting too long because the user feels embarrassed about clicking or replying.
Trying to solve a serious account or device incident alone.
Reporting only that something feels wrong without including safe facts such as time, sender, request, and observed changes.

Safe Defensive Lab

Build a Fictional Phishing Incident Report

Fake Incident File

SchoolCloud Account Report

A fictional student receives a fake support email, clicks a login link, enters a password, denies an MFA prompt, and notices an unknown session.

Report Sections

  • Incident date, time, and communication channel.
  • Claimed sender and requested action.
  • Warning signs and safe evidence.
  • Actions already taken by the student.
  • Trusted contact, containment, recovery, and monitoring steps.

Scenario Decision Lab

A Student Clicked a Suspicious Login Link

A fictional student clicked a link, entered a password, and then realized the page was not the official school portal.

Scenario Decision Lab

Files Change After an Unexpected Download

A fictional student opens an unverified attachment, and several files soon change names and cannot be opened.

Defender Habits

Reporting Workflows and Trusted Help Checklist

Check Your Understanding

B9.6 Mini Quiz: Reporting Workflows and Trusted Help

Choose your answers first. Explanations appear only after submission.

1. What should a useful phishing report include?

2. Why should serious incidents be escalated?

3. What is the safest response after an unexpected MFA prompt?

4. Why should suspicious files not be forwarded with a report?

5. What should happen if a student clicked a suspicious link?

Portfolio Prompt

Portfolio Prompt

Create a one-page fictional phishing incident report. Include the timeline, channel, sender, requested action, warning signs, safe evidence, actions taken, trusted contact, containment, recovery, and follow-up.

Use fictional accounts, messages, senders, devices, links, files, and organizations only.
Do not include real passwords, codes, private information, or suspicious attachments.
Write the report so a trusted responder can understand the event quickly.

Key Takeaways

What You Should Remember

1.Fast, honest reporting can reduce the impact of phishing and account incidents.
2.Useful reports include clear safe facts without exposing secrets.
3.Suspicious links and attachments should be described, not forwarded or tested.
4.Serious or unclear incidents should be escalated to trusted adults or technology staff.
5.Containment and recovery may include denying prompts, removing sessions, replacing credentials, reviewing MFA and recovery, and monitoring activity.

Navigation

Continue Module B9