Cybersecurity concern reporting for Scottish businesses

Make it easy to speak up when something looks wrong

A suspicious message, an unexpected sign-in prompt or a file sent to the wrong person should have a clear reporting route. Stratiis helps Scottish organisations turn security awareness into a practical response: staff know what to report, who to contact and what happens next.

What should staff report as a cybersecurity concern?

Report anything that could affect a business account, device, payment or piece of information: suspicious emails, texts or calls; unexpected MFA prompts; unusual sign-ins; a lost device; an unfamiliar payment change; or data shared with the wrong person. Staff do not need to prove an incident has happened. Reporting the facts promptly gives the right team a chance to assess them.

Why it matters

Early reports give your team room to act

A useful reporting process encourages people to raise concerns before a small problem becomes harder to contain.

Faster triage

The right person can check what happened and decide whether action is needed.

Clearer ownership

Staff know the trusted route and who takes the next step.

Less uncertainty

People can report a mistake or a suspicion without having to diagnose it.

Better learning

Patterns in reports can improve training, controls and response plans.

Reporting route

What should a concern reporting process include?

Make the route short enough to remember and reliable when normal systems are unavailable.

Element Question to answer Useful output
Trusted contact How can staff reach the support or security team? A named reporting route that is easy to find.
Backup route What if email or the usual service is affected? An alternative phone or out-of-band channel.
Report details What should the person include? Time, account or device, what happened and any original message.
Triage owner Who reviews the concern and decides its priority? Clear ownership and cover for absences.
Escalation Which situations need immediate attention? Agreed contacts and decision points.
Evidence How should messages, screenshots and logs be handled? Simple preservation guidance without broad forwarding.
Feedback How will the reporter know what to do next? Acknowledgement and a practical next instruction.

The NCSC response and recovery guidance recommends preparing a route to identify, respond to and learn from cyber incidents.

Practical starting points

Which situations should staff recognise?

Use examples from the work your people do, then give each one the same trusted reporting route.

Suspicious message

A message asks someone to open a link, share a code or act urgently in an unusual way.

Unexpected account activity

An MFA prompt, password reset or sign-in alert appears without a known reason.

Payment change

Bank details or payment instructions change unexpectedly, even if the request appears familiar.

Lost device

A business laptop, phone or tablet is missing or may be in someone else’s hands.

Wrong recipient

A file, email or message containing business information reaches the wrong person.

Unusual system behaviour

A device, application or shared service behaves differently and the cause is unclear.

How support starts

Build a reporting habit people will use

The process should be understandable to a new starter and workable during a busy day.

1

Recognise

Show staff practical examples of suspicious activity and mistakes worth reporting.

2

Report

Provide one trusted primary route and a backup if the usual channel is affected.

3

Triage

Review the facts, assess impact and guide the reporter on the next step.

4

Improve

Use lessons from reports to refine instructions, controls and awareness training.

Monitoring and Response connects staff reports with investigation and action.

People and safeguards

Make it safe and simple to report

People are more likely to speak up when the route is clear and the response is constructive.

What Stratiis can help plan

Reporting instructions and realistic staff examples.

Support intake, triage and technical handoff.

Account, device and message investigation routes.

Exercises and updates after lessons learned.

What your organisation owns

Internal contacts, cover and escalation decisions.

A culture that welcomes early reports, including mistakes.

Business, legal and privacy decisions where required.

Communicating the route to every worker.

Useful facts

What information should a report include?

Staff should share what they know through the trusted route without delaying the report to gather every detail.

Concern Useful facts Immediate care
Suspicious email or message Sender, time, subject and what was requested. Keep the original message; avoid forwarding it widely.
Unexpected sign-in or MFA prompt Account, time, device and whether the prompt was approved. Do not approve a prompt you did not initiate.
Lost or stolen device Device type, owner, last known location and time. Report promptly so access and data can be assessed.
Wrong-recipient data What was sent, recipient, time and the system used. Report the facts rather than attempting an uncoordinated fix.
Payment change request Requester, change requested and any related communication. Use an established independent verification route.

Follow your organisation’s incident instructions. The NCSC guidance on identifying an incident explains why early facts and unusual activity matter.

When something looks wrong

Give a useful first response

Staff should know the next safe step without needing to decide whether the event is a confirmed incident.

Use a trusted route

Contact the published support or security channel, especially if the original message may be fraudulent.

Share the facts

Say what happened, when, which account or device was involved and what action was taken.

Keep evidence

Preserve the original message or relevant details as your reporting process directs.

Follow guidance

The response team can advise on account, device, data and communication steps.

Related Stratiis services

Connect awareness to response

Staff guidance works best alongside account controls, technical monitoring and an agreed response process.

Also see Data and Sharing for wrong-recipient and information handling guidance.

Common questions

Reporting Concerns FAQs

Short answers staff and business leaders can use when setting a reporting route.

Should I report something if I am not sure it is a cyber incident?

Yes. Report the facts through your organisation’s trusted route. The response team can decide whether investigation or action is needed.

What if I clicked a suspicious link?

Report it promptly and say what you clicked and whether you entered information or downloaded anything. Follow the response team’s next steps.

What if I entered a password into a suspicious page?

Contact the trusted support route immediately, identify the account and explain what happened. The team can guide account protection and check for unusual activity.

Should I delete a suspicious email before reporting it?

Follow your organisation’s reporting instructions. The original message can help investigation, so avoid deleting or forwarding it widely before you receive guidance.

How should people report outside office hours?

The organisation should publish an out-of-hours or backup route for urgent concerns and explain which situations need it.

What if a phone or laptop is lost?

Report the device, owner, last known location and time promptly. The support team can assess access and the information on it.

What if information was sent to the wrong person?

Report what was sent, who received it and when. The organisation can assess the impact and decide what follow-up is required.

What happens after I report?

A designated person should acknowledge the report, check the facts, assess priority and tell you what to do next. The process should feed lessons back into guidance and controls.

Talk to Stratiis

Give your team a clear route to raise concerns

Tell us how staff currently report suspicious activity and mistakes. We can help make the route practical, supported and easy to remember.

Contact Stratiis →