B9.6 Reporting Workflows and Trusted Help
Learn how to stop interaction, preserve safe evidence, write a clear report, choose the right trusted contact, and support containment and recovery after a phishing event.
Lesson Progress
Reporting Workflows and Trusted Help
High School Beginner • B9: Phishing and Social Engineering Defense • Lesson 6 of 7
Readiness Check
Before You Start
0/3 ready
Professional Hook
A Strong Report Helps Defenders Act Faster
Technology staff cannot respond effectively to “something looked weird” alone. A clear report explains what happened, when it happened, what the sender requested, which warning signs appeared, what the user did, and whether any account or device changes followed.
Learning Objective
Preserve safe evidence without interacting with or spreading suspicious content.
Learning Objective
Write a clear report that includes timeline, sender, request, warning signs, actions, and impact.
Learning Objective
Choose the correct trusted contact and support containment and recovery.
Why This Matters
Silence and Delay Can Increase the Impact
People sometimes hide a click, reply, payment, or login because they feel embarrassed. Fast reporting gives trusted responders a better chance to protect accounts, devices, files, money, privacy, and other users.
Visual Diagram
The Reporting and Trusted-Help Workflow
Strong reporting stops interaction, preserves safe facts, reaches the correct trusted person, and supports containment and recovery.
Stop interaction
Do not click, reply, call, pay, approve, download, open, forward, upload, or test suspicious content.
Record safe facts
Note the time, sender, subject, channel, displayed domain, filename, request, and warning signs.
Report to the right person
Use the approved school, family, workplace, service, or technology-support reporting path.
Secure and follow up
Contain account or device risk, complete trusted recovery steps, and monitor for additional signs.
Core Concept
Report Facts, Not Secrets
A useful report describes the event clearly without including passwords, MFA codes, recovery codes, private data, or dangerous content. The goal is to give trusted responders enough information to act safely.
Key Vocabulary
Terms for Reporting and Trusted Response
Incident report
A clear record of what happened, what evidence was observed, what actions were taken, and who was notified.
Trusted contact
A verified adult, teacher, guardian, supervisor, administrator, or technology professional who can help handle a security concern.
Escalation
Moving a serious or unclear security issue to someone with the authority, tools, or responsibility to respond.
Evidence preservation
Keeping useful safe details such as time, sender, subject, displayed domain, filename, and account alert without opening or spreading suspicious content.
Containment
Immediate defensive action that limits possible harm, such as denying prompts, removing unknown sessions, or stopping device use.
Recovery action
A trusted step used after containment, such as replacing credentials, reviewing MFA, restoring settings, or using an approved backup.
Technical Breakdown
Reporting and Escalation Board
A strong report helps the right person understand the event and choose the next defensive action quickly.
Safe evidence
Review question
What can be recorded without exposing secrets or interacting with suspicious content?
Safer choice
Record time, sender, channel, subject, displayed domain, filename, request, and observed behavior.
Correct contact
Review question
Who has the authority or responsibility to help with this account, device, school, family, or service?
Safer choice
Use the official reporting path, trusted adult, administrator, or technology team.
Immediate containment
Review question
Is there current unauthorized access, repeated MFA activity, suspicious file behavior, or an exposed credential?
Safer choice
Deny prompts, remove unknown sessions, stop risky interaction, and secure the affected account or device.
Follow-up recovery
Review question
What approved steps are needed after the immediate risk is contained?
Safer choice
Replace credentials, review MFA and recovery, update systems, monitor activity, and use trusted backups if needed.
Fake Dashboard
Reporting Workflow Review Panel
This fictional panel connects common phishing evidence with the correct reporting, escalation, containment, and recovery route.
Suspicious school email
Unknown sender requests a password and MFA code
Do not reply. Report through the school phishing process and contact technology staff through the official directory.
Unexpected login prompt
MFA request appears when the student is not signing in
Deny it, review official account activity, remove unknown sessions, and tell a trusted adult or support team.
Possible device issue
Files change names after a suspicious download
Stop using the device and report immediately to trusted technology staff.
Fake support call
Caller requests a recovery code
End the call, preserve safe details, and contact the organization through a known official number.
Suspicious social request
Copied profile asks for emergency money
Do not pay. Verify the person through another known channel and report the profile if needed.
Fake Dashboard
Fake Phishing Reporting Dashboard
Training dashboard using fictional reports, escalation paths, containment actions, and recovery results.
Reports reviewed
18
Fictional email, text, phone, social, account, and device incidents.
Reports with clear timelines
14
Included time, channel, sender, request, action, and observed impact.
Escalated correctly
12
Reached trusted adults, official support, or technology staff.
Fake SOC Alert
Suspicious Link Click Followed by Unknown Login
Source: Fake School Incident Training • Time: 2:23 PM
Fake Log Panel
Fake Reporting Workflow Log
14:08:17 MESSAGE channel='email' sender='unknown_address' request='account_login' 14:10:41 INTERACTION link_opened='true' password_entered='true' 14:12:09 MFA_PROMPT expected='false' action='denied' 14:14:33 SESSION browser='unknown' status='removed' 14:18:26 REPORT recipient='school_technology_staff' safe_facts='included' 14:23:02 RECOVERY credential_replaced='true' mfa_reviewed='true' monitoring='enabled'
Training note: this is fake data for defensive analysis practice only.
Analyze the Evidence
What Should This Report Include?
Which report is most useful and safe?
Common Mistakes
Mistakes That Weaken Reporting and Recovery
Safe Defensive Lab
Build a Fictional Phishing Incident Report
Fake Incident File
SchoolCloud Account Report
A fictional student receives a fake support email, clicks a login link, enters a password, denies an MFA prompt, and notices an unknown session.
Report Sections
- Incident date, time, and communication channel.
- Claimed sender and requested action.
- Warning signs and safe evidence.
- Actions already taken by the student.
- Trusted contact, containment, recovery, and monitoring steps.
Scenario Decision Lab
A Student Clicked a Suspicious Login Link
A fictional student clicked a link, entered a password, and then realized the page was not the official school portal.
Scenario Decision Lab
Files Change After an Unexpected Download
A fictional student opens an unverified attachment, and several files soon change names and cannot be opened.
Defender Habits
Reporting Workflows and Trusted Help Checklist
Check Your Understanding
B9.6 Mini Quiz: Reporting Workflows and Trusted Help
Choose your answers first. Explanations appear only after submission.
1. What should a useful phishing report include?
2. Why should serious incidents be escalated?
3. What is the safest response after an unexpected MFA prompt?
4. Why should suspicious files not be forwarded with a report?
5. What should happen if a student clicked a suspicious link?
Portfolio Prompt
Portfolio Prompt
Create a one-page fictional phishing incident report. Include the timeline, channel, sender, requested action, warning signs, safe evidence, actions taken, trusted contact, containment, recovery, and follow-up.
Key Takeaways
What You Should Remember
Navigation