Skip to content
Incident response

Phishing Incident Response

Someone at your company clicked a phishing link. Call 088 SECDESK (7323375). A senior Dutch incident responder picks up, and starts containment within two hours.

Two-hour SLA · Dutch senior responders

We have handled AiTM phishing compromises for Dutch fintechs, professional-services firms, and a regional healthcare provider.

Someone clicked. Here is what to do in the next hour.

  1. 01

    Do not delete the email or reset the password yet

    The phishing message, its headers, and the session logs are the evidence. They tell us whether credentials were stolen, whether a session token was hijacked, and whether the attacker is already inside. Do not forward the mail around the office. Do not move it to a shared folder. Keep the original. Do not force a password reset before we revoke active sessions: a plain reset leaves existing refresh tokens usable by the attacker.

  2. 02

    Disable the affected account or sign it out of all sessions

    In Microsoft 365, open the admin center, find the user, and choose Sign out of all sessions. In Google Workspace, reset sign-in cookies. This revokes active tokens without destroying the audit trail. If you cannot tell which account clicked, start with the person who reported it and any shared mailbox they access.

  3. 03

    Call 088 SECDESK (7323375)

    A senior incident responder answers. We ask what happened, when, and which systems are involved. If you are seeing active signs (unusual sign-ins from abroad, forwarding rules you did not create, password resets on other accounts), we start containment on the call.

How SecDesk handles a phishing incident

  1. Triage and scope, first 30 minutes

    We determine whether credentials were entered, whether MFA was approved, and whether a session token was handed over through AiTM (adversary-in-the-middle) phishing or an OAuth consent phish. We pull Azure AD sign-in logs and the Unified Audit Log, and we check for impossible-travel sign-ins and new device registrations.

  2. Containment, first two to four hours

    We revoke refresh tokens, disable the account if needed, remove any OAuth applications the attacker consented to, and delete mailbox forwarding or auto-delete rules. For MFA fatigue attacks, we unregister attacker-added authenticators and tighten conditional access so the attacker cannot simply re-enroll.

  3. Investigation

    We trace what the attacker did inside. Did they read mail, download the mailbox via eDiscovery, forward invoices to finance, access SharePoint, or set up Power Automate flows? We check every second account in the tenant for signs of the same campaign, because phishing waves rarely hit one person.

  4. Remediation and hardening

    Credentials reset with session revocation, attacker-registered MFA devices removed, conditional access re-evaluated, and anti-phishing policy tuned in Microsoft Defender for Office 365. If the phish abused a conditional access gap, we close it. If it came through a lookalike domain, we flag it in your mail flow and with your registrar.

  5. Reporting and lessons learned

    You get a written report in plain language: timeline, scope, affected data, actions taken, specific recommendations. If personal data was touched, the report contains what the Autoriteit Persoonsgegevens needs for the 72-hour meldplicht datalekken. We then schedule a lessons-learned call. No upsell, just an honest read on what let the attacker in.

What to expect when you call

Senior responder on the line

No triage desk, no queue. The person answering the phone is an experienced incident responder who stays on your case from first call to final report.

Dutch regulatory context

We know the AVG, the meldplicht datalekken, and how to coordinate with the Autoriteit Persoonsgegevens and NCSC-NL. Reports are written to satisfy the 72-hour notification requirement.

Phishing types we see most often

AiTM phishing, OAuth consent phishing, MFA fatigue, quishing (QR code phishing), and credential stuffing that follows a prior leak. We have a playbook for each.

Two-hour response

Weekends and nights included. Active containment inside the first two hours of contact, written report within days of closure, lessons-learned call afterwards.

Frequently asked questions

An employee clicked a phishing link but did not enter credentials. Is the company still at risk?

Possibly. A click alone can fingerprint the browser, drop an infostealer, or trigger an AiTM session hijack if the link led to a spoofed login page that the user was already signed into. We investigate the page, the browser state, and the sign-in logs before declaring it clean.

Do we need to notify the Autoriteit Persoonsgegevens?

If personal data was accessed, or was likely accessed, the AVG gives you 72 hours to notify. We help assess whether notification is required, and our report contains what the AP asks for: nature of the breach, categories of data subjects, measures taken.

How do we know the attacker is fully out?

We verify it. Active sessions revoked, no unexpected devices registered, no attacker-added MFA methods, no surviving OAuth grants, no mailbox rules, no Power Automate flows. We also watch sign-in logs for a period after remediation to catch attempted re-entry.

Will our cyber insurance cover this?

Most Dutch cyber policies cover incident response costs, and many require you to engage an approved responder. Call your broker early. Our reports are structured for insurer review, with a clean timeline and evidence chain.

Does this incident have to become public?

Not automatically. Disclosure obligations depend on whether personal data was compromised, what kind, and how many people are affected. The AP decides whether individual notification is required. We walk you through that decision with your legal team.

How much does phishing incident response cost?

It depends on scope. A contained single-account phish often closes within a day or two of billable time. A broader compromise takes longer. We discuss an estimate on the first call and bill on time and materials, no retainer lock-in.

Call 088 SECDESK

A senior incident responder picks up. Containment begins within two hours.

  • Two-hour SLA
  • Dutch senior responders

Emergency form

Two-hour response.

Is this urgent? Call us.

088 SECDESK (7323375)

Cannot wait? Call 088 SECDESK (7323375) now

Emergency line088 SECDESK
Call now