Cyber fraud reporting in Indonesia has become increasingly important as financial losses caused by digital fraud continue to increase. However, the effectiveness of initial responses remains strongly influenced by the quality and timeliness of initial reports. This study aims to identify bottlenecks in the current cyber fraud reporting pipeline and design a more responsive triage-based reporting flow. The study employs a qualitative approach using process analysis combined with design science research. The research stages begin with mapping the current reporting flow, or as-is condition, followed by bottleneck analysis at each stage of the reporting process, including victim awareness, evidence collection, reporting channels, verification, and routing to administrative or criminal mechanisms. The findings indicate four main issues: delays in the initial phase, heterogeneity of initial reports, fragmentation of reporting entry points and routing weaknesses, and gaps in initial case readiness. Based on these findings, this study proposes a to-be reporting flow that does not alter the downstream administrative or criminal mechanisms, but improves the upstream process through report verification and post-reporting triage. The proposed triage classifies reports into three categories: immediate handling, follow-up handling, and reports requiring further completion. This model is expected to improve the quality of incoming reports, reduce the burden of initial verification, and support more structured and targeted initial responses to cyber fraud cases. The contribution of this research lies in integrating as-is flow mapping, bottleneck identification, and triage flow design into a single conceptual framework for improving cyber fraud reporting.