Their Microsoft 365 account had been compromised for weeks. Nobody knew.

The importance of Microsoft 365 Security Monitoring: The account had been compromised for weeks. Nobody knew.

The obvious sign of this incident was more than 300 attempted emails from a customer’s Microsoft 365 account.

 

Our helpdesk responded immediately, blocking the account, revoking active sessions and putting controls in place to deal with the outstanding messages.

 

Within 7 to 10 minutes of detection, access to the compromised account had been contained.

 

But the investigation afterwards uncovered something more concerning.

 

Suspicious successful access to the account had been taking place for nearly a month before anybody knew there was a problem.

 

The activity was visible retrospectively in Microsoft’s logs. The challenge was knowing at the time that there was something that needed investigating.

 

And that is the part of this incident businesses should pay attention to.

 

Not every attack makes noise

An attacker may gain access to a legitimate Microsoft 365 account and remain quiet, observing activity before deciding when and how to act.

 

Because they are using a genuine company identity, they could potentially impersonate an employee, contact customers or suppliers, request payment changes, send malicious links or target other people within the organisation.

 

The longer suspicious activity goes undetected, the more opportunity there may be for further damage.

 

That’s why Microsoft 365 security monitoring is about more than knowing whether an account has been compromised.

 

It is about identifying activity that may warrant investigation and responding when it matters.

 

If someone gained access to one of your Microsoft 365 accounts today, how quickly would you know?

 

47,942 Microsoft 365 events in less than four days

Following the incident, enhanced Microsoft 365 security monitoring was enabled for the customer.

 

In less than four days, the service analysed:

47,942

Microsoft 365 events.

 

Two signals were identified for assessment. Neither was ultimately considered suspicious or required further investigation.

 

Most Microsoft 365 activity is completely legitimate. The challenge is identifying the handful of events that may matter amongst tens of thousands of normal ones.

 

Having security information available is not the same as having somebody continuously analysing it.

 

Attackers don’t work 9 to 5

This incident happened outside normal business hours.

 

Your employees may notice something unusual during the working day. But what happens at night, over a weekend or during a bank holiday?

 

Attackers don’t need to follow your working hours.

 

This is where 24/7 Microsoft 365 security monitoring, detection and response can make a difference.

 

In this incident, once the compromise was identified, access to the account was contained within 7 to 10 minutes.

 

The suspicious activity may have existed for weeks. The response after detection took minutes.

 

That’s the gap continuous monitoring is designed to reduce.

 

What happens when prevention fails?

Good cybersecurity isn’t about promising that a business will never be compromised.

 

It’s about reducing the likelihood of compromise and, if somebody does get through, reducing the time and opportunity they have to cause further damage.

 

Our managed security service provides 24/7 Microsoft 365 security monitoring, detection and response, designed to identify indicators of compromise and enable rapid investigation and containment when significant threats are detected.

 

For less than the price of a coffee and a pastry, your business can significantly reduce the risk of a cyber attack for a month.

 

Because detecting a potential threat is only the beginning. Response is what helps limit the opportunity for an attacker to cause further damage.

 

So, how quickly would you know?

This incident started with a compromised Microsoft 365 account.

 

The obvious warning came when more than 300 emails were attempted.

 

But the investigation revealed the more important part:

Suspicious successful access had been taking place for nearly a month before anybody knew there was a problem.

 

Once the compromise was identified, the account was contained within 7 to 10 minutes.

 

Prevention is important. But knowing quickly when prevention has failed can be just as important.

 

If you are an Amshire customer and aren’t sure whether Microsoft 365 security monitoring is included in your current service, speak to your account manager.

 

Not an Amshire customer? Find out what your current IT provider is doing to monitor your Microsoft 365 environment.

 

What could your business be leaving behind?

Our Digital Security Report provides a non-intrusive look at your organisation’s external digital footprint and highlights areas that may warrant further investigation.

 

Find out what your business could be leaving behind.