
π Cybersecurity Β· Flowchart
What the security team does when an employee reports a phishing email: analyse, contain, clean up and learn.
Drawing diagramβ¦
Phishing response workflow: an employee clicks 'Report phishing'. The SOC analyses headers, links and attachments in a sandbox. If it is benign, the employee is thanked. If malicious, the team searches all mailboxes and purges copies, blocks the sender and URLs, and checks proxy logs for anyone who clicked. Clicked users get a forced password reset and EDR scan; if credentials were used, an incident is opened. Lessons feed awareness training.
flowchart TD
A[Employee reports phishing] --> B[SOC analyses headers, links, attachments]
B --> C{Malicious?}
C -->|No| D[Thank employee, close]
C -->|Yes| E[Purge similar emails from all mailboxes]
E --> F[Block sender, domains and URLs]
F --> G{Anyone clicked or entered password?}
G -->|No| K[Close and share lesson]
G -->|Yes| H[Force password reset and revoke sessions]
H --> I[EDR scan of device]
I --> J{Signs of compromise?}
J -->|Yes| L[Open security incident]
J -->|No| K
L --> KA zero trust access model: every request to an internal app is checked for user identity, device health and policy, whether it comes from the office or home.
A security incident response process based on the NIST lifecycle: detect, triage, contain, eradicate, recover and learn.
How security logs from across an organisation reach the SIEM: collection, parsing, enrichment, detection rules and alerts for the SOC.
How SAML single sign-on works when an employee opens a SaaS app: redirect to the company identity provider, MFA and a signed assertion.
A classic secure network layout: internet-facing services in a DMZ between two firewalls, with internal systems and databases never exposed directly.
A STRIDE threat model for a web application, listing example threats in each category with the main mitigations.