Compliance Scenario · Security & Speak-Up
She Realizes the Login Page Was Fake. It’s 8:58 on a Monday.
The click already happened. The only thing anyone still controls is the next five minutes — and the careful-sounding option is the expensive one.
Quick Answer
Should I report a suspected phishing attack before I’m sure?
Yes. The reporting threshold is “something is off,” not “I have proof.” Confirming what happened is the security team’s job, and handing it to them early is the professional move rather than the panicked one. An early false alarm costs a few minutes; a late confirmed compromise costs considerably more.
Report first through your organization’s official channel, then follow the instructions you’re given. Don’t try to fix it yourself first, and don’t quietly ask a colleague to check — both spend the only thing that cannot be recovered, which is time.
Pressure Type: Proof Before Speaking
Everywhere else in her job, raising an unverified number is the mistake. Checking first is what a careful professional does, and it is what she has been rewarded for since the day she was hired. This pressure works because the instinct is genuinely correct almost everywhere — and because the one place it inverts is the place where the delay costs the most.
The Situation
Monday, 8:37 AM. Month-end close is Wednesday. Tess works in accounts payable and has done so for four years.
An email lands in an existing thread with a supplier she pays monthly. It cites the correct open invoice number and asks her to sign in to the vendor portal and clear a hold before Wednesday’s payment run. She clicks. The sign-in page looks exactly right. It errors the first time; she signs in again; the invoice page opens. She goes back to her reconciliation.
8:57 AM. Something nags at her about that first error page. She goes back to the email and hovers over the link. The domain is one letter off.
Nothing looks wrong. Her inbox is normal. Her account works. And she is holding three facts she wishes she weren’t: she scored 100 percent on last quarter’s phishing training, her team’s click rate is on the dashboard her manager presents Thursday, and she is fairly sure that reporting this means losing her laptop during close week. It is 8:58. What does she do in the next five minutes?
Three Ways People Respond
A. Fix it at the source, now.
Change the password, run the self-service scan, watch the account through the morning. Four minutes, no ticket, no queue — and no chance an ordinary mistake becomes a Thursday dashboard story. Why it falls short: a self-directed fix cannot confirm containment, and it cannot find changes made during the twenty minutes that have already passed. Only the security team can establish what actually happened. Every minute spent cleaning up is a minute they don’t have.
B. Report it now, at eighty percent sure.
Use the official reporting channel immediately, state plainly what happened and when, and follow any instructions you receive. Don’t fix it first. Don’t recruit anyone to check it first. Why it works: see below.
C. Verify it first, then escalate with facts.
She’s eighty percent sure, not certain. Legitimate portals throw errors every day. Call the supplier’s AP contact and ask whether they sent it; ask the colleague two desks over to glance at the header. If it’s real, no harm done. If it’s fake, she reports with facts instead of a feeling. Why it falls short: this is the correct instinct from everywhere else in her job, applied to the one situation where the cost runs the other way. Each verification step spends time that cannot be recovered — and asking a colleague turns one person’s exposure into two people’s knowledge and nobody’s report.
The Right Call
For Tess: Choice B — report it now, through the official channel, at eighty percent sure.
She is not deciding whether it was phishing. She is deciding who gets the next twenty minutes — her or the security team. That is the whole question, and it is the only part of the morning she controls.
A complete, honest report is shorter than people expect: “I clicked at 8:37, realized at 8:57, and I’m calling now.” The delay between clicking and recognizing is normal, and everyone receiving that report already knows it.
Why It’s Harder Than It Looks
Verifying first is correct almost everywhere else.
In finance, escalating an unconfirmed number is an error. Tess has spent four years learning to check before she speaks. Nothing in her training tells her that this one situation runs the other way.
Nothing looks wrong — which is the point.
A quiet inbox and a working account feel like evidence that nothing happened. They are not. Silence is what the situation is designed to produce.
The scorecard is doing work nobody intended.
A click-rate metric on a dashboard is meant to improve awareness. If it also makes a person hesitate for five minutes before reporting, it has quietly become a reporting suppressor — and that is a finding about the organization, not about Tess.
Delay converts a no-fault event into a choice.
Being phished is an ordinary thing that happens to careful people; her recognition system worked, twenty minutes late, which is typical. What changes the character of the event is the gap between knowing and reporting.
“I’d report it immediately. Obviously.”
Most people say that, and most people mean it. But notice what the sentence assumes: that you would be certain. Tess isn’t — she’s eighty percent sure, on a close week, with a dashboard on Thursday and a laptop she can’t afford to lose. The question isn’t whether you’d report a confirmed compromise. It’s whether you’d raise an alarm you might turn out to be wrong about, in front of people whose morning it would cost.
Frequently Asked Questions
Should I report a suspected phish before I’m certain?
Yes. The threshold is “something is off,” not “I have proof.” Confirming what happened is the security team’s job. An early report that turns out to be nothing costs a few minutes; a late report on something real costs a great deal more.
I already changed my password. Doesn’t that fix it?
Not necessarily. A password change may not end access that someone already has, and it will not surface changes made during the window before you noticed. Only your security team can confirm containment. Report it anyway, and tell them what you already did.
Will I get in trouble for clicking?
Many organizations treat the click itself as a no-fault event and focus on how quickly it was reported — but policies differ, so check how yours handles it. What is consistent everywhere is that prompt reporting helps, and delay does not.
What if I report it and it turns out to be legitimate?
Then it cost a few minutes. Security teams would rather receive early maybes than late certainties — a steady stream of unconfirmed reports is what a healthy program looks like from their side of the desk.
How to Use This in Training
Run it in 15 minutes with any team that has an inbox. Take a private vote before revealing anything, then ask the question that finds the gap: “Who do you call, right now, from this chair — and what actually happens to your laptop when you do?”
If nobody can name the reporting channel in thirty seconds, that is the finding, and it is not a participant failure. Available as a manager-led Xcelus Decision Brief™ with a facilitator guide and an Insights Log.
Where This Goes Next
This is a speak-up decision wearing security clothing — the psychology that delays the report here is the same psychology that delays every other kind of report. One level up, the question shifts from whether an employee reports to whether a known risk reaches the people who need it: Keep It Off the Dashboard.
More Scenarios
Cluster Hub
Browse all compliance scenarios →
Could your team name the reporting channel in thirty seconds?
Run this scenario as a 15-minute manager-led discussion, and find out before someone needs it.
Developed by Xcelus under the direction of Todd R. Corbett, MBA, Founder.
© 2005–2026 Xcelus LLC. All rights reserved. This scenario is fictional and for training and discussion only; it does not depict any real company, person, or event, and it is not legal, security, or compliance advice. Technical behavior varies by system and configuration. Follow your organization’s current reporting process and confirm with your security or compliance team.
© 2005–2026 Xcelus LLC. All rights reserved. This content is for training and discussion only and is not legal advice; consult qualified counsel about your organization’s specific obligations.