assess.one – AI-powered business operations platform

Workflow Template

Phishing Report and Response Workflow

Captures phishing reports from employees, has a security analyst triage and assess maliciousness, and — if malicious — identifies affected users, contains the threat (reset credentials, block sender) and notifies affected users; if benign, notifies the reporter no action is needed. The report is closed in either case.

Employees spot suspicious emails but reports get lost in inboxes, and slow triage lets real threats sit unchecked. This workflow captures every phishing report, routes it to a security analyst for triage, and automatically branches into containment or closure based on the analyst's assessment. Security teams run it end-to-end inside assess.one, with credential resets, sender blocks, and user notifications all tracked in one record.

Business Outcomes

  • Cut average phishing response time from days to hours
  • Zero reports lost or forgotten in email threads
  • Consistent triage and containment steps on every incident
  • Full audit trail from report to closure for compliance reviews
  • Faster containment reduces blast radius of real attacks

Workflow Steps

Steps

  1. 1
    Create Phishing Report Recordcreate record

    Registers the submitted phishing report as a record.

  2. 2
    Set Status to Openupdate record

    Marks the report as open on intake.

  3. 3
    Acknowledge Report Receivedsend email

    Confirms to the reporter that their submission was received.

  4. 4
    Assign Security Analystassign user

    Assigns the report to a security analyst for triage.

  5. 5
    Set Status to Under Triageupdate record

    Marks the report as under triage while the analyst investigates.

  6. 6
    Triage and Assess Reportcreate task

    Analyst reviews the message and sender details and determines if the report is malicious or benign.

  7. 7
    Persist Triage Resultupdate record

    Saves the analyst's triage assessment and notes to the record.

  8. 8
    Route on Triage Assessment

    Branches the workflow depending on whether the report was assessed as malicious or benign.

    triage_assessment: "Malicious"Contain Threat
    triage_assessment: "Benign"Notify Reporter - No Action Needed
    DefaultNotify Reporter - No Action Needed
  9. 9
    Contain Threatcreate task

    Analyst resets affected users' credentials and blocks the malicious sender.

  10. 10
    Persist Containment Resultupdate record

    Saves containment confirmation and notes, and marks the report as contained.

  11. 11
    Notify Analyst to Alert Affected Userscreate task

    Creates a task for the analyst to directly notify each affected user, since their contact details are free text and not individual record fields.

  12. 12
    Close Report - Containedupdate record

    Marks the malicious report as closed after containment and notification.

  13. 13
    Notify Reporter - No Action Neededsend email

    Informs the reporter that the message was assessed as benign and no further action is required.

  14. 14
    Close Report - No Actionupdate record

    Marks the benign report as closed with no action taken.

Fields

  • Reporter Name*
  • Reporter Email*
  • Suspicious Sender Address*
  • Email Subject Line
  • Suspicious Message Content*
  • Screenshot or Email File (.eml/.msg)
  • +8 more fields

Forms

Report a Phishing Email

7 fields

Data Views

All Phishing Reports

phishing_report_ref, reporter_name, suspicious_sender, triage_assessment +1 more

Dashboard Widgets

Report PipelineMalicious vs Benign ReportsRecent Phishing Reports

Recommended integrations

Setup the following integrations to extend workflow capability.

  • Send email in the workflow

    AWS SES logoAWS SES
phishing reportsuspicious emailphishing responsesecurity incidentemail security

Similar Workflows

Similar Categories

FAQs

How do I set up this phishing response workflow?

Publish the template in assess.one and it's live immediately — no setup project needed. Employees can start submitting phishing reports right away while you fine-tune roles and notifications in the background.

What do I need before publishing this workflow?

You need a list of who fills the security analyst role and where notifications should go, like Slack or email. Everything else, including the triage logic and status tracking, is already built into the template.

How long does implementation take?

Publishing takes minutes, not weeks. Once it's live, your security team can start triaging real phishing reports immediately, and you can adjust steps as you learn what works.

Can I customise the triage and containment steps?

Yes. You can edit the triage questions, add extra containment actions, or change who gets assigned as analyst, all directly inside assess.one. Approval logic and notification rules are also editable without any code.

Who needs access to this workflow?

Employees need access to submit reports, and security analysts need access to triage and action them. You control permissions at each step, so reporters only see their own submissions while analysts see the full queue.

What happens if the report is assessed as benign?

The workflow routes to a notification step telling the reporter no action is needed, then closes the report. This keeps the record complete even for false positives, which helps with reporting trends over time.

What happens if the report is malicious?

The workflow moves into containment: resetting credentials, blocking the sender, and notifying affected users. Every containment action is logged before the report closes, so you have a clear record of what was done and when.

Does this workflow support compliance and audit requirements?

Yes. Every status change, triage decision, and containment action is timestamped and stored in the report record. This gives you a ready-made audit trail for security reviews or incident postmortems.

Can I change who gets assigned as the security analyst?

Yes. You can assign a fixed analyst, rotate assignments, or route based on team availability, all configured in assess.one's workflow settings. This can be updated anytime without disrupting reports already in progress.

Ready to use this workflow?

Create a free account and customise this workflow for your business.

Phishing Report & Response Workflow | assess.one