Workflow Template
Phishing Report and Response Workflow
Captures phishing reports from employees, has a security analyst triage and assess maliciousness, and — if malicious — identifies affected users, contains the threat (reset credentials, block sender) and notifies affected users; if benign, notifies the reporter no action is needed. The report is closed in either case.
Employees spot suspicious emails but reports get lost in inboxes, and slow triage lets real threats sit unchecked. This workflow captures every phishing report, routes it to a security analyst for triage, and automatically branches into containment or closure based on the analyst's assessment. Security teams run it end-to-end inside assess.one, with credential resets, sender blocks, and user notifications all tracked in one record.
Business Outcomes
- Cut average phishing response time from days to hours
- Zero reports lost or forgotten in email threads
- Consistent triage and containment steps on every incident
- Full audit trail from report to closure for compliance reviews
- Faster containment reduces blast radius of real attacks
Workflow Steps
Steps
- 1Create Phishing Report Recordcreate record
Registers the submitted phishing report as a record.
- 2Set Status to Openupdate record
Marks the report as open on intake.
- 3Acknowledge Report Receivedsend email
Confirms to the reporter that their submission was received.
- 4Assign Security Analystassign user
Assigns the report to a security analyst for triage.
- 5Set Status to Under Triageupdate record
Marks the report as under triage while the analyst investigates.
- 6Triage and Assess Reportcreate task
Analyst reviews the message and sender details and determines if the report is malicious or benign.
- 7Persist Triage Resultupdate record
Saves the analyst's triage assessment and notes to the record.
- 8Route on Triage Assessment
Branches the workflow depending on whether the report was assessed as malicious or benign.
triage_assessment: "Malicious"→Contain Threattriage_assessment: "Benign"→Notify Reporter - No Action NeededDefault→Notify Reporter - No Action Needed - 9Contain Threatcreate task
Analyst resets affected users' credentials and blocks the malicious sender.
- 10Persist Containment Resultupdate record
Saves containment confirmation and notes, and marks the report as contained.
- 11Notify Analyst to Alert Affected Userscreate task
Creates a task for the analyst to directly notify each affected user, since their contact details are free text and not individual record fields.
- 12Close Report - Containedupdate record
Marks the malicious report as closed after containment and notification.
- 13Notify Reporter - No Action Neededsend email
Informs the reporter that the message was assessed as benign and no further action is required.
- 14Close Report - No Actionupdate record
Marks the benign report as closed with no action taken.
Fields
- Reporter Name*
- Reporter Email*
- Suspicious Sender Address*
- Email Subject Line
- Suspicious Message Content*
- Screenshot or Email File (.eml/.msg)
- +8 more fields
Forms
Report a Phishing Email
7 fields
Data Views
All Phishing Reports
phishing_report_ref, reporter_name, suspicious_sender, triage_assessment +1 more
Dashboard Widgets
Recommended integrations
Setup the following integrations to extend workflow capability.
Send email in the workflow
AWS SES
Similar Workflows
Similar Categories
FAQs
How do I set up this phishing response workflow?
Publish the template in assess.one and it's live immediately — no setup project needed. Employees can start submitting phishing reports right away while you fine-tune roles and notifications in the background.
What do I need before publishing this workflow?
You need a list of who fills the security analyst role and where notifications should go, like Slack or email. Everything else, including the triage logic and status tracking, is already built into the template.
How long does implementation take?
Publishing takes minutes, not weeks. Once it's live, your security team can start triaging real phishing reports immediately, and you can adjust steps as you learn what works.
Can I customise the triage and containment steps?
Yes. You can edit the triage questions, add extra containment actions, or change who gets assigned as analyst, all directly inside assess.one. Approval logic and notification rules are also editable without any code.
Who needs access to this workflow?
Employees need access to submit reports, and security analysts need access to triage and action them. You control permissions at each step, so reporters only see their own submissions while analysts see the full queue.
What happens if the report is assessed as benign?
The workflow routes to a notification step telling the reporter no action is needed, then closes the report. This keeps the record complete even for false positives, which helps with reporting trends over time.
What happens if the report is malicious?
The workflow moves into containment: resetting credentials, blocking the sender, and notifying affected users. Every containment action is logged before the report closes, so you have a clear record of what was done and when.
Does this workflow support compliance and audit requirements?
Yes. Every status change, triage decision, and containment action is timestamped and stored in the report record. This gives you a ready-made audit trail for security reviews or incident postmortems.
Can I change who gets assigned as the security analyst?
Yes. You can assign a fixed analyst, rotate assignments, or route based on team availability, all configured in assess.one's workflow settings. This can be updated anytime without disrupting reports already in progress.
Ready to use this workflow?
Create a free account and customise this workflow for your business.
