Report an Incident
The InfoSec Team takes all information security reports seriously. Whether you are a student, staff, or community member, your vigilance helps protect our entire community. If you are unsure whether something constitutes a security incident, report it anyway. Caution is always better than silence.
For users familiar with our ticketing system who are not reporting a phishing incident, please proceed to the IT Service Portal: https://itshelpdesk.clark.edu/support/home.
Before You Begin
Physical Security
If the situation involves an immediate physical threat (fire, medical emergency, suspicious person), call 911 or contact Physical Security at (360) 992-2133.
What to Report
Examples of reportable incidents include but are not limited to:
-
- Phishing emails: Messages pretending to be from Clark College or trusted partners asking for credentials, payment, or personal information.
- Social engineering: Phone calls, texts, or in-person requests for passwords, MFA codes, or sensitive data from someone claiming to be IT or college leadership.
- Malware or ransomware infections: Pop-ups demanding payment, locked files, unusual system behavior, or antivirus warnings you cannot dismiss.
- Lost or stolen devices: Laptops, tablets, phones, or USB drives that may contain college data or have campus credentials saved.
- Unauthorized access: Suspicious logins, unfamiliar account activity, or someone using your credentials without permission.
- Data exposure: Sensitive information (student records, financial data, research data) sent to the wrong recipient or posted publicly.
Reporting Guidelines
-
- Report early. Speed matters. A report filed within the first hour dramatically improves our ability to contain threats and limit damage.
- Do not investigate on your own. Avoid clicking links again, running unfamiliar tools, or confronting suspected bad actors. Document what you observed and leave the rest to our team.
- Report even if nothing happened. A suspicious email you did not click is still valuable intelligence. Your report may help us identify a larger campaign targeting other community members.
Report Phishing
The following outlines methods for reporting phishing via Outlook Desktop and Outlook Mobile. Staff members should use one of these designated methods. Non-staff users, or those unable to locate the “Report Phishing” button in Outlook, may alternatively forward suspicious emails to phishing@clark.edu or helpdesk@clark.edu.
Report via Outlook Desktop
-
- Right click on the phishing email in the folder view.
- Hover over the “Report” option (it is near the bottom).
- Click on the “Report Phishing” button.
Report via Outlook Mobile
-
- Select the phishing email in the folder view by tapping the profile picture of the email.
- Tap on the three dots (...) near the bottom of the app.
- Tap on the “Report Phishing” button.
Report an Incident
The primary method for reporting an information security incident is by submitting a ticket through the IT Service Portal.
Please gather and compile the following information before proceeding:
-
- Incident Summary: A one-sentence description of what occurred.
- What Happened: Describe the event in plain language.
- When It Happened: Include the date and approximate time; note if the incident is ongoing.
- Where It Happened: Specify the system, application, building, room, or website involved.
- Who Was Involved: List any account names, email addresses, or individuals connected to the incident.
- What You Observed: Describe any error messages, pop-ups, unusual emails, file behavior, or unexpected prompts.
- Actions You Have Taken: Note whether you clicked a link, entered credentials, downloaded a file, changed a password, disconnected a device, or contacted anyone else.
- Attachments:
- Screenshots of suspicious emails, pop-ups, error messages, etc.
- Photos of suspicious devices or physical setups
Once you have gathered the above information, follow these steps:
-
- Access the IT Service Portal: Navigate to Clark College’s IT Service Portal. Log in using your Clark College account credentials and MFA (if applicable).
- Open a New Ticket: From the portal home screen, select ‘Report an issue’.
- Verify Requester Information: Under ‘Requester’, ensure your email is listed. If it is not, add it. If you are
not the primary requester for this incident, enter the appropriate person's email
address. You may also use the ‘Add CC’ button next to the ‘Requester’ field to add
additional contacts.
- Select the Issue Category: Under ‘Issue Category’, select ‘Spam / Virus / Incident Reporting’ from the drop-down
menu. Please note that this option is located near the bottom, so you may need to
scroll down.
- Fill Out the Subject Line: In the ‘Subject’ field, enter “InfoSec Incident” followed by the date and the type
of information security incident.
- Fill Out the Office/Room Number: In the ‘Please enter office and room # for service’ section, provide whatever information
is appropriate. This field is not typically relevant to our team's incident response
efforts unless a desktop or laptop requires physical pickup, but it is a required
field nonetheless.
- Fill Out the Alternate Phone Number: If you believe your account may have been compromised, include an alternate phone
number, as temporarily disabling your account will disable your ability to receive
calls via your Zoom phone number.
- Fill Out the Description: Include all collected details such as the incident summary, what happened, when
it happened, where it happened, who was involved, what you observed, and actions you
have already taken.
- Attach Relevant Files: Attach screenshots of suspicious emails, pop-ups, or error messages, phishing emails
saved as attachments, or photos of suspicious devices or physical setups.
Note: Do not attach files that contain sensitive data or that may be malicious unless instructed by the InfoSec team. If sensitive files are involved, describe them and await further instructions.
- Fill Out Notes: Under ‘Notes’, indicate whether any sensitive data may have been exposed (e.g.,
student records, financial data, login credentials).
- Associate Assets (if applicable): If specific Clark College devices were involved, click the ‘Associate Assets’ button
near the bottom of the form to display your assigned devices. For a different Clark
College device not assigned to you, search for it in the ‘Search Other Assets’ tab
near the top left. Click the ‘Associate’ button once you have selected the asset.
- Verify and Submit: Before submitting, double-check that the information you’ve entered is clear and correct, then click the ‘Submit’ button. Once submitted you will receive an automated confirmation email containing your ticket number. Save this number for reference in all future communications about the incident.
- Access the IT Service Portal: Navigate to Clark College’s IT Service Portal. Log in using your Clark College account credentials and MFA (if applicable).
Reporting Next Steps
First, you will receive an automated confirmation email within minutes of submitting your ticket. This email contains your ticket number and confirms that your report has been received by the InfoSec Team.
Then, a member of the InfoSec Team will review your report and determine the appropriate severity level and response path. From there, you may be contacted for additional information, request access to specific logs or devices, or ask you to take specific preservation actions (such as leaving a computer powered on).
Finally, once the investigation is complete and any necessary remediation has been performed, the InfoSec Team will close your ticket with a summary of findings and actions taken.
Other Ways to Report
While the IT Service Portal is the preferred method, we understand that circumstances may require alternatives.
Report by Email
Send incident details to infosec@clark.edu. Include as much information as possible. An InfoSec Team member will create a ticket on your behalf.
Report by Phone
Call the Tech Hub at (360) 992-2010 during business hours (Monday–Friday, 8am-4pm PST). A Tech Hub technician will help you create an information security incident ticket.
In-Person Reporting
Visit the Tech Hub located in Scarpelli Hall 135 during business hours (Monday–Friday, 8am-4pm). A Tech Hub technician will assist you in filing an information security incident ticket.
Reporting FAQs
Will I get in trouble for reporting an incident?
We prioritize rapid reporting and transparency. If you accidentally clicked a phishing link or exposed data, report it immediately. Our team focuses on remediation, not blame. Prompt self-reporting is viewed positively and reduces overall impact.
Can I update my ticket after submitting?
Yes. Reply to the confirmation email or return to the IT Service Portal and locate your open ticket. Add any new information, screenshots, or observations at any time.
What if the incident happens outside business hours?
The IT Service Portal accepts tickets 24/7.
What if I reported something to the Tech Hub already?
That is fine. Tech Hub technicians will route information security-related tickets to the InfoSec Team. You do not need to submit a duplicate report. Reference your existing ticket number in any follow-up communications.
Additional Resources
Multi-Factor Authentication Guide