Cybersecurity concern reporting for Scottish businesses
Make it easy to speak up when something looks wrong
A suspicious message, an unexpected sign-in prompt or a file sent to the wrong person should have a clear reporting route. Stratiis helps Scottish organisations turn security awareness into a practical response: staff know what to report, who to contact and what happens next.
What should staff report as a cybersecurity concern?
Report anything that could affect a business account, device, payment or piece of information: suspicious emails, texts or calls; unexpected MFA prompts; unusual sign-ins; a lost device; an unfamiliar payment change; or data shared with the wrong person. Staff do not need to prove an incident has happened. Reporting the facts promptly gives the right team a chance to assess them.
Why it matters
Early reports give your team room to act
A useful reporting process encourages people to raise concerns before a small problem becomes harder to contain.
Faster triage
The right person can check what happened and decide whether action is needed.
Clearer ownership
Staff know the trusted route and who takes the next step.
Less uncertainty
People can report a mistake or a suspicion without having to diagnose it.
Better learning
Patterns in reports can improve training, controls and response plans.
Reporting route
What should a concern reporting process include?
Make the route short enough to remember and reliable when normal systems are unavailable.
| Element | Question to answer | Useful output |
|---|---|---|
| Trusted contact | How can staff reach the support or security team? | A named reporting route that is easy to find. |
| Backup route | What if email or the usual service is affected? | An alternative phone or out-of-band channel. |
| Report details | What should the person include? | Time, account or device, what happened and any original message. |
| Triage owner | Who reviews the concern and decides its priority? | Clear ownership and cover for absences. |
| Escalation | Which situations need immediate attention? | Agreed contacts and decision points. |
| Evidence | How should messages, screenshots and logs be handled? | Simple preservation guidance without broad forwarding. |
| Feedback | How will the reporter know what to do next? | Acknowledgement and a practical next instruction. |
The NCSC response and recovery guidance recommends preparing a route to identify, respond to and learn from cyber incidents.
Practical starting points
Which situations should staff recognise?
Use examples from the work your people do, then give each one the same trusted reporting route.
Suspicious message
A message asks someone to open a link, share a code or act urgently in an unusual way.
Unexpected account activity
An MFA prompt, password reset or sign-in alert appears without a known reason.
Payment change
Bank details or payment instructions change unexpectedly, even if the request appears familiar.
Lost device
A business laptop, phone or tablet is missing or may be in someone else’s hands.
Wrong recipient
A file, email or message containing business information reaches the wrong person.
Unusual system behaviour
A device, application or shared service behaves differently and the cause is unclear.
How support starts
Build a reporting habit people will use
The process should be understandable to a new starter and workable during a busy day.
Recognise
Show staff practical examples of suspicious activity and mistakes worth reporting.
Report
Provide one trusted primary route and a backup if the usual channel is affected.
Triage
Review the facts, assess impact and guide the reporter on the next step.
Improve
Use lessons from reports to refine instructions, controls and awareness training.
Monitoring and Response connects staff reports with investigation and action.
People and safeguards
Make it safe and simple to report
People are more likely to speak up when the route is clear and the response is constructive.
What Stratiis can help plan
Reporting instructions and realistic staff examples.
Support intake, triage and technical handoff.
Account, device and message investigation routes.
Exercises and updates after lessons learned.
What your organisation owns
Internal contacts, cover and escalation decisions.
A culture that welcomes early reports, including mistakes.
Business, legal and privacy decisions where required.
Communicating the route to every worker.
Useful facts
What information should a report include?
Staff should share what they know through the trusted route without delaying the report to gather every detail.
| Concern | Useful facts | Immediate care |
|---|---|---|
| Suspicious email or message | Sender, time, subject and what was requested. | Keep the original message; avoid forwarding it widely. |
| Unexpected sign-in or MFA prompt | Account, time, device and whether the prompt was approved. | Do not approve a prompt you did not initiate. |
| Lost or stolen device | Device type, owner, last known location and time. | Report promptly so access and data can be assessed. |
| Wrong-recipient data | What was sent, recipient, time and the system used. | Report the facts rather than attempting an uncoordinated fix. |
| Payment change request | Requester, change requested and any related communication. | Use an established independent verification route. |
Follow your organisation’s incident instructions. The NCSC guidance on identifying an incident explains why early facts and unusual activity matter.
When something looks wrong
Give a useful first response
Staff should know the next safe step without needing to decide whether the event is a confirmed incident.
Use a trusted route
Contact the published support or security channel, especially if the original message may be fraudulent.
Share the facts
Say what happened, when, which account or device was involved and what action was taken.
Keep evidence
Preserve the original message or relevant details as your reporting process directs.
Follow guidance
The response team can advise on account, device, data and communication steps.
Related Stratiis services
Connect awareness to response
Staff guidance works best alongside account controls, technical monitoring and an agreed response process.
Also see Data and Sharing for wrong-recipient and information handling guidance.
Common questions
Reporting Concerns FAQs
Short answers staff and business leaders can use when setting a reporting route.
Should I report something if I am not sure it is a cyber incident?
Yes. Report the facts through your organisation’s trusted route. The response team can decide whether investigation or action is needed.
What if I clicked a suspicious link?
Report it promptly and say what you clicked and whether you entered information or downloaded anything. Follow the response team’s next steps.
What if I entered a password into a suspicious page?
Contact the trusted support route immediately, identify the account and explain what happened. The team can guide account protection and check for unusual activity.
Should I delete a suspicious email before reporting it?
Follow your organisation’s reporting instructions. The original message can help investigation, so avoid deleting or forwarding it widely before you receive guidance.
How should people report outside office hours?
The organisation should publish an out-of-hours or backup route for urgent concerns and explain which situations need it.
What if a phone or laptop is lost?
Report the device, owner, last known location and time promptly. The support team can assess access and the information on it.
What if information was sent to the wrong person?
Report what was sent, who received it and when. The organisation can assess the impact and decide what follow-up is required.
What happens after I report?
A designated person should acknowledge the report, check the facts, assess priority and tell you what to do next. The process should feed lessons back into guidance and controls.
Talk to Stratiis
Give your team a clear route to raise concerns
Tell us how staff currently report suspicious activity and mistakes. We can help make the route practical, supported and easy to remember.


