Phishing response

Automatic response to phishing

Phishing emails are fake emails designed to trick the recipient into disclosing sensitive information, such as usernames and passwords, credit card information, or other personal data. They may also contain malicious software that can infect devices or networks.

Microsoft's email filters do not catch all phishing attacks. Companies are constantly exposed to phishing attacks, and these are time-consuming to respond to – while they can also lead to compromised users – and be the first stage of larger attacks.

Phishing emails are fake emails designed to trick the recipient into disclosing sensitive information, such as usernames and passwords, credit card information, or other personal data. They may also contain malicious software that can infect devices or networks.

Microsoft's email filters do not catch all phishing attacks. Companies are constantly exposed to phishing attacks, and these are time-consuming to respond to – while they can also lead to compromised users – and be the first stage of larger attacks.

How does phishing response work?

1

Bedriftens ansatte varsler phishing-forsøk ved å bruke "Report Message"-knappen i Outlook.

2

Netsecurity mottar eposten som en alarm, og undersøker hvorvidt eposten er skadelig med automasjon og manuell analyse.

3

Vi sjekker om andre i bedriften har mottatt samme epost, hvilke ansatte som har besøkt epostens lenker samt hvem som har lastet ned eventuelle vedlegg.

4

Eposten slettes fra alle mottakeres innboks, vedlegg slettes, endepunkt scannes for skadevare og brukere kan bli logget ut samt få passordet sitt resatt.

How does phishing response work?

number-circle-one-fill-2

The company's employees report phishing attempts by using the "Report Message" button in Outlook.

number-circle-two-fill-2

Netsecurity receives the email as an alert and investigates whether the email is malicious using automation and manual analysis.

number-circle-three-fill-2

We check whether others in the company have received the same email, which employees have visited the links in the email, as well as who has downloaded any attachments.

number-circle-four-fill-2

The email is deleted from all recipients' inboxes, attachments are deleted, endpoints are scanned for malware, and users may be logged out and have their passwords reset.

If one or more users report the email as phishing in the user's email client, the email will be sent to our security monitoring team (NSOC) for analysis and automatic response  - that is, deletion of the email and attachments from all recipients as well as user response for users who have visited suspicious links from the email.