Reporting a Security Incident — What Counts, and What to Do in the First Ten Minutes
Three articles on this site tell you to report an incident immediately. This one explains what that actually means.
Read it now rather than when you need it. In the moment, people don’t search — they hesitate, and hesitation is the thing that turns a manageable problem into a serious one.
What counts as an incident
Broader than most people assume. Report any of these:
Something you clicked. A link in an email or message that turned out to be suspicious. A login page that asked for your password. An attachment that opened something unexpected.
Something you sent. An email or file to the wrong recipient. Customer details typed into the wrong record. A message with personal information sent over WhatsApp.
Something you were asked for. A caller asking for your password or an MFA code. Anyone asking you to install software so they can “help.” A request to bypass verification for someone claiming to be a customer.
Something you lost. A phone with the authenticator on it. A company device. A notebook with customer details in it.
Something you saw. Records visible to someone who shouldn’t see them. A colleague’s account left logged in on an unattended machine. A stranger on the floor without an escort. A screen being photographed.
Something odd on your machine. Software you didn’t install. Your mouse moving on its own. Repeated MFA prompts you didn’t trigger — that last one means someone has your password and is standing at the login screen right now.
If you’re weighing up whether something qualifies, it qualifies. Report it.
The first ten minutes
1. Report it. Now. Phone IT and log a ticket at support.invarium.co.zw under the Security category. Phone first if you entered a password or opened an attachment — those are the two where minutes genuinely matter.
2. Don’t try to fix it yourself. Don’t delete the email, don’t clear your browser history, don’t uninstall anything, don’t factory-reset the device. Every one of those destroys the evidence we need to work out what happened and how far it went.
3. Don’t change your password before telling us. It feels like the right instinct. But we need to know which credential was exposed and when, and changing it first makes that harder to establish. We’ll reset it — usually within minutes of you calling.
4. If you opened an attachment, disconnect from the network but leave the machine on. Unplug the network cable or disconnect WiFi. Don’t shut down. A running machine preserves information that a powered-off one loses.
5. Say what actually happened. Not what you think we want to hear. If you entered your password, say so plainly. If you’re not sure whether you did, say that too. Vagueness here costs hours.
6. Then carry on with your shift unless IT tells you otherwise.
Why the speed matters this much
Under Zimbabwe’s Cyber and Data Protection Act, where an incident involves personal data, the company has 24 hours from becoming aware of a breach to notify POTRAZ. If the people affected are at high risk, they must be told within 72 hours.
“Becoming aware” means the moment someone in the company knows. Which means it means the moment you tell us.
Report in ten minutes and we have most of a day to investigate, contain and notify properly. Report at the end of your shift and we’ve lost a third of the window before we’ve started. Report the next morning and we may already be non-compliant regardless of how well we handle the rest.
The commitment
You will not be disciplined for reporting an incident promptly and honestly. That applies even when the incident was your mistake — a click, a wrong recipient, a password given to a convincing caller.
This is a deliberate position, and the reason is simple. In every organisation where people fear the consequences of reporting, incidents get hidden, and hidden incidents become the expensive ones. We would rather know in ten minutes and deal with it than find out in three weeks from a client.
What does carry consequences is concealing an incident, or discovering one and saying nothing.
What happens after you report
We acknowledge and start work immediately. Depending on what happened, that may mean forcing a password reset, isolating a machine, pulling logs, or engaging Black Talon Security for endpoint analysis.
We’ll come back to you with questions. Answer them as precisely as you can, including timings.
Most reports turn out to be nothing. That’s the expected outcome, and it’s fine — a report that turns out to be harmless costs us fifteen minutes. The alternative costs considerably more.
You’ll be told the outcome. If it was a real incident and your quick reporting limited the damage, that gets recognised.
What not to do
Don’t forward a suspicious email to colleagues to ask what they think — use the IRONSCALES report button instead.
Don’t discuss a live incident on the floor or in group chats. Speculation spreads faster than facts and makes the investigation harder.
Don’t post about it anywhere. Not internally, not externally.
Don’t wait to see if it turns into a problem. That’s the whole point.
The one line to remember
If something feels wrong, phone IT and log a ticket. Don’t delete anything, don’t fix anything, don’t wait.
Read next: How to Spot a Phishing Email, and The Cyber and Data Protection Act in Plain English.

