Skip to main content

Extortion via AI playbook

This playbook has technical guidance for responding to a business email compromise incident. It is not a standalone resource: use it alongside your incident management plan to make sure it works for your school.

Evidencing

All communication must be catalogued by your designated safeguarding lead. All evidence should be held securely and noted in an incident log. If there has been a financial impact, record this alongside clear evidence and include:

  • URL links
  • usernames
  • platform, app, social media or website
  • all information communicated including any images, video and/or audio

Create an incident review report with all actions taken, from incident discovery to resulting mitigations. You can use this to:

  • present to stakeholders and authorities
  • determine additional actions to be taken
  • influence future process improvements