LThe Life Starter
0 of 6 complete0%
Lesson 6 of 6
Digital · Guided lesson

Prepare for an incident

Make the first hour of an account takeover or lost device calmer and faster.

About 21 minutes Finish with a concrete deliverable
Cybersecurity and Infrastructure Security AgencySecure Our WorldYouTube
Course primer

Secure Our World

From Cybersecurity and Infrastructure Security Agency. Watch here or open it on YouTube .

Turn the playlist's protective actions into a one-page incident checklist with provider-specific recovery links and an order you can follow under stress.
Before you begin

What this lesson is really solving.

Write the response while calm: disconnect affected devices when appropriate, preserve evidence, change credentials from a clean device, revoke sessions, contact providers through official channels, monitor financial or identity misuse, and document actions. Sequence depends on the incident.

Why this works

Understand the idea before touching the steps.

Contain, regain control, preserve evidence, recover, then learn.

Do this

Follow these steps in order.

Take the action in each step; then use the deliverable below to prove the lesson is finished.

  1. 1

    Write the order of operations: secure email, reset affected credentials, revoke sessions, contact providers, and freeze financial exposure.

  2. 2

    Keep account numbers, device identifiers, insurer contacts, and official fraud-reporting resources offline.

  3. 3

    If compromise occurs, use a known-clean device and official URLs; document times, messages, transactions, and case numbers.

  4. 4

    After recovery, identify the entry point and update controls rather than only changing one password.

Worked example

See the standard in context.

After an unexpected email-login alert, Sam uses a clean phone to open the provider directly, changes the password, revokes sessions and app tokens, inspects forwarding rules, confirms recovery methods, checks related accounts, saves alert details, and warns contacts if messages were sent.

Quality check

Inspect before you move on.

  • Official recovery and fraud contact routes are available without the compromised device.
  • The checklist distinguishes lost device, stolen account, payment fraud, and malware.
  • Actions, times, confirmation numbers, and evidence are recorded.
Make it real

Your deliverable

A one-page incident card that can be used even when your main phone and email are unavailable.

Common mistake

Watch for this

Responding through the same compromised email thread or device without first securing the master account.

You’re ready when

Prove it—don’t just recognize it.

You can name the first five actions for a lost phone, stolen email, or suspicious bank transfer.

Objective evidence · 3 questions

Quick knowledge check

Answer from the lesson—not from confidence alone. Score at least 2 of 3 to unlock completion.

Not yet passed

This curriculum-aligned check is scored automatically and stored with your account when signed in. It is an objective learning signal, but it has not yet been independently validated as a standardized assessment.

1Which action belongs in the recommended process for “Prepare for an incident”?
2Which result is the clearest evidence that this lesson’s work is complete?
3Which choice matches the failure this lesson specifically warns against?
0 of 3 answeredEach question measures the action, evidence, or failure condition taught above.
Useful for this course

Tools, templates, and references

The Life Starter toolkitReusable planners and trackers for practical projects.
Check current detailsReferences reviewed September 9, 2026. Lesson exercises are editorial synthesis; official rules come from the linked sources.
CISA — Secure Our WorldNIST — Small business cybersecurity
6
One check remains

Pass the knowledge check above first.

Completion unlocks after a score of 2 out of 3. Then confirm that you produced the lesson deliverable.

Go to the knowledge check