A suspicious email or hacked account can make people feel exposed and embarrassed. The most important thing to know is simple: asking for help early is always the right move.
Cyber problems are far easier to contain when they’re handled calmly and quickly. Quiet hesitation is what makes a small issue grow.
First rule: stop clicking
If something feels wrong, stop interacting with it. Don’t click more links, don’t download more files, don’t reply to the sender, and don’t keep trying passwords on a page that looks suspicious.
If it’s a work account, let the right person know straight away. It’s better to flag a false alarm than to stay quiet about a real problem.
Capture what happened
Useful details to record:
- the sender address (not just the display name);
- the subject line;
- the time the message arrived;
- whether any link or attachment was opened;
- which account was used;
- whether any password was entered;
- whether any unusual sign-in or payment request followed.
This gives whoever helps you the context they need to assess the risk and decide what to check first.
Change passwords carefully
If an account may be compromised, password changes should happen from a trusted device on a trusted network. If the attacker still has access, changing a password from the wrong place may not actually help.
For business accounts, the password is only one part of the story. Mailbox rules, forwarding, connected apps, sign-in history and multi-factor authentication settings should all be reviewed.
Look at the wider impact
A hacked account isn’t only a password problem. It can reach into customers, staff, invoices, files, calendars and any service that account is connected to.
The useful question is: “What could this account reach?” The answer tells you where to look next.
A simple test
Create a small internal rule: if anyone receives a suspicious email involving payments, passwords, invoices or urgent requests, they pause and verify it through a second channel — usually a phone call to a known number, not a reply.
It’s a 30-second habit that prevents most of the costly mistakes we see.
A calm next step
Don’t treat cyber incidents as personal mistakes. Treat them as process moments. What happened? What did we find? What’s changed now? What still needs attention?
That structure helps the whole team move from stress to action — and it’s the same structure we use on the technical side, too.