A teachable moment happened here

Oh.... Now what?

Maybe you let someone through a secured door. Maybe an unknown device was connected. Maybe you clicked a link, answered a convincing phone call, or approved something you should have questioned. The useful part is what happens next.

It's about Education, not exploitation. Improvement, over Incident.

1. STOP Do not keep interacting with the suspicious person, message, device, or request.
2. VERIFY Use a trusted, independent method to confirm who or what you are dealing with.
3. REPORT Tell your security, IT, help desk, manager, or physical-security team promptly.
4. RESET Follow your organization’s instructions to recover, then use the lesson next time.
Important: If you are not sure this was an authorized exercise, treat it as a real security event and follow your organization’s normal incident-reporting process.

Find your teachable moment

What happened, what should you do now, and what should you do differently next time?

🔌

An unknown person connected a device

You allowed an unverified person to plug in a USB drive, cable, adapter, keyboard like device, network device, or other hardware or you connected an unknown device yourself.

What to do now

  • Stop using the device or computer for the questionable activity.
  • Contact your IT or security team and explain exactly what was connected, where, and when.
  • Do not erase, destroy, reformat, or “investigate” the unknown device yourself.
  • Follow your organization’s instructions before disconnecting equipment if evidence may need to be preserved.

Next time

  • Verify the person’s identity and authorization before allowing any connection.
  • Do not connect found, gifted, mailed, or unknown USB devices or cables.
  • Use only organization-approved equipment and media.
  • If someone says “IT sent me,” verify with IT through a contact method you already trust.
🚪

An unknown person followed you through a secured door

Someone entered an access controlled area using your access instead of their own badge, escort, visitor process, or other approved authorization.

What to do now

  • Do not put yourself in physical danger or escalate a confrontation.
  • Notify physical security, reception, your manager, or the designated security contact.
  • Note the location, approximate time, description, and direction of travel while it is fresh in your mind.
  • If appropriate under your policy, move to a secure location while security handles the situation.

Next time

  • Access controlled doors are one person one authorization unless your policy says otherwise.
  • Politely direct visitors to reception, security, or the proper check in process.
  • Uniforms, packages, tools, confidence, and a convincing story are not proof of authorization.
  • It is okay to be helpful without surrendering a security control.
✉️

You clicked a phishing link or opened a suspicious attachment

The message may have looked urgent, familiar, important, or routine. That is exactly why phishing works.

What to do now

  • Stop interacting with the message, attachment, website, or login prompt.
  • Report the message using your organization’s phishing report button or security process.
  • If you entered credentials, contact IT/security and change them using a known good route not a link from the suspicious message.
  • If you approved an unexpected MFA request, report that immediately as well.
  • Do not delete evidence unless your security team tells you to.

Next time

  • Slow down when a message creates urgency, fear, secrecy, or unusual pressure.
  • Check the real sender address and destination of links.
  • Open important services from a bookmark or known address instead of an email link.
  • Verify unusual requests through a separate trusted channel.
☎️

You trusted a convincing phone call

A caller claimed to be IT, a bank, a coworker, an executive, a vendor, law enforcement, or another trusted party and persuaded you to provide information or take an action.

What to do now

  • End the call if you are still connected.
  • Contact the claimed organization using a phone number or channel you already know is legitimate.
  • Report what you shared or did including passwords, codes, MFA approvals, payment details, or remote access actions.
  • If financial information or a payment was involved, follow your organization’s financial-fraud process immediately.

Next time

  • Caller ID is not proof of identity.
  • Never provide passwords or one time authentication codes to an inbound caller.
  • Hang up and call back using a trusted directory, known number, or internal contact.
  • A legitimate request can survive verification.

You received an unexpected MFA, login, or password reset prompt

An unexpected authentication request may mean someone already has part of what they need and is waiting for you to complete the login.

What to do now

  • Deny unexpected authentication prompts.
  • Report repeated or suspicious prompts to IT/security.
  • If you approved one accidentally, report it immediately and follow account recovery instructions.
  • Change affected credentials from a known-good device or path if your security team directs you to.

Next time

  • Only approve authentication you personally initiated.
  • Read number matching, location, and application details instead of reflexively approving.
  • Treat repeated prompts as a warning, not an annoyance.
👤

You helped someone before verifying who they were

Helpful employees are valuable. Attackers know that and often turn normal courtesy into an access path.

What to do now

  • Report what information, access, directions, equipment, or assistance you provided.
  • Give security the person’s description, claimed identity, destination, and stated reason for being there.
  • Do not try to “fix” the situation quietly; early reporting gives defenders more options.

Next time

  • Help people reach the correct verification process instead of bypassing it for them.
  • Ask the uncomfortable but necessary question: “Who are you here to see?”
  • When something feels unusual, verify first and help second.

The Silver Lining

Recognizing it afterward still matters.

Security is not about expecting people to be perfect. It is about helping people notice sooner, verify more often, report faster, and recover well.

NOTICE → VERIFY → REPORT → IMPROVE

The goal of a Silver Teaming exercise is not to embarrass you for a mistake. The goal is to make the next attacker’s job harder.

One habit to take with you

Give unusual requests a verification step.

Before granting access, connecting a device, clicking a link, sharing information, approving MFA, or acting on an urgent request, ask yourself: “How do I know this person, message, device, or request is really what it claims to be?”

Every Teachable Moment should have a Silver Lining

Learn from this one. Catch the next one.

Silver-Team.org/nowwhat

Learn about Silver Teaming