CloudSketch AI Logo
FeaturesTemplatesPricingEnterpriseAboutContactLog in
πŸŒ™β˜€οΈ
Log inStart free
Home/Templates/Cybersecurity

πŸ” Cybersecurity Β· Flowchart

Phishing Email Response Workflow

What the security team does when an employee reports a phishing email: analyse, contain, clean up and learn.

More Cybersecurity templates

Drawing diagram…

What this diagram shows

  • The report button sends the email and headers to the SOC
  • Similar emails are removed from every mailbox
  • Anyone who clicked gets a password reset and device scan

Prompt used

Phishing response workflow: an employee clicks 'Report phishing'. The SOC analyses headers, links and attachments in a sandbox. If it is benign, the employee is thanked. If malicious, the team searches all mailboxes and purges copies, blocks the sender and URLs, and checks proxy logs for anyone who clicked. Clicked users get a forced password reset and EDR scan; if credentials were used, an incident is opened. Lessons feed awareness training.

Mermaid code
flowchart TD
  A[Employee reports phishing] --> B[SOC analyses headers, links, attachments]
  B --> C{Malicious?}
  C -->|No| D[Thank employee, close]
  C -->|Yes| E[Purge similar emails from all mailboxes]
  E --> F[Block sender, domains and URLs]
  F --> G{Anyone clicked or entered password?}
  G -->|No| K[Close and share lesson]
  G -->|Yes| H[Force password reset and revoke sessions]
  H --> I[EDR scan of device]
  I --> J{Signs of compromise?}
  J -->|Yes| L[Open security incident]
  J -->|No| K
  L --> K

Related templates

C4 ArchitectureProCybersecurity

Zero Trust Architecture

A zero trust access model: every request to an internal app is checked for user identity, device health and policy, whether it comes from the office or home.

FlowchartCybersecurity

Security Incident Response Workflow

A security incident response process based on the NIST lifecycle: detect, triage, contain, eradicate, recover and learn.

Data FlowCybersecurity

SIEM Log Pipeline

How security logs from across an organisation reach the SIEM: collection, parsing, enrichment, detection rules and alerts for the SOC.

SequenceCybersecurity

SAML Single Sign-On Login

How SAML single sign-on works when an employee opens a SaaS app: redirect to the company identity provider, MFA and a signed assertion.

NetworkCybersecurity

DMZ Network Architecture

A classic secure network layout: internet-facing services in a DMZ between two firewalls, with internal systems and databases never exposed directly.

MindmapCybersecurity

Threat Model Mindmap (STRIDE)

A STRIDE threat model for a web application, listing example threats in each category with the main mitigations.