Small-Business Security Guide
Business email security response guide
A compromised Microsoft 365 or business email account can lead to fraudulent invoices, stolen information, and a loss of trust. The first steps matter—move quickly, but do not guess or erase evidence.
If you suspect an employee’s business email account has been accessed by someone else, treat it as a security incident. A strange forwarding rule, unexpected MFA prompt, sent messages the user did not write, or a supplier reporting an unusual payment request are all reasons to act.
Start here: contain the account
- Reset the password using a known-clean device and make sure it is unique.
- Revoke active sessions so an attacker cannot continue using an existing browser or token.
- Confirm multi-factor authentication is enabled and remove unfamiliar authentication methods.
- Preserve useful evidence such as suspicious messages, times, and reported payment requests before cleanup.
Check the places attackers commonly change
Changing the password alone may not remove every way back in. An administrator should review the affected mailbox and Microsoft 365 account for:
- Inbox rules or forwarding rules that send copies of mail outside the company
- Unexpected delegates, shared-mailbox permissions, or forwarding addresses
- Unrecognized sign-ins, devices, registered applications, and MFA methods
- Messages sent from the account, especially invoice or bank-detail changes
- Deleted items and mail flow activity that may show what was accessed
Protect people who may have received a fake message
If fraudulent mail was sent, notify affected customers, vendors, and staff promptly through a known channel. Keep the message simple: explain that the email account was compromised, identify the date or subject line if known, and ask recipients not to act on payment or credential requests from the suspicious message. Do not send sensitive information in the notification.
Look beyond the mailbox
Email compromise sometimes begins with a phishing link, reused password, or a device problem. Check the employee’s device for recent alerts and make sure security updates, endpoint protection, and Microsoft 365 security controls are working. If the account has access to financial systems, customer data, or administrator roles, expand the review accordingly.
When to bring in help
Get qualified IT or security help immediately if money was redirected, an administrator account may be involved, multiple accounts show suspicious activity, or you cannot confidently identify what changed. Quick containment and a clear review are more useful than a rushed, incomplete cleanup.
Not sure what to check first?
RD Computer Solutions helps South Sound small businesses assess Microsoft 365, account security, devices, backups, and practical next steps.
Request Your Free IT Risk & Security ReviewFrequently asked questions
Should we delete suspicious messages?
Preserve enough information to investigate first, then remove malicious messages from affected mailboxes as part of the cleanup. Your IT provider can help determine what needs to be retained.
Can an attacker keep access after a password reset?
Yes. Existing sessions, mailbox rules, unfamiliar MFA methods, and malicious app permissions can remain, which is why a broader account review is important.
Does Microsoft 365 include security tools for this?
Microsoft 365 includes security and audit capabilities, but the appropriate steps depend on the license level, account permissions, and what occurred. The important part is reviewing the account methodically and documenting the response.
Leave a Reply