One of your Microsoft 365 accounts has been taken over. What happens next?
Why an account, and not encrypted files
Ransomware is the incident everyone pictures. For a company of twenty to a hundred people running Microsoft 365, a taken-over account is the one that actually happens — and it rarely announces itself.
Someone answers a convincing sign-in prompt. For a fortnight nothing looks wrong. A supplier's invoice comes back with different banking details, a rule quietly forwards a mailbox to an outside address, and files shared with the whole company walk out through an account nobody thought to check.
It is also the incident that tells you the most. Every question we ask in the session lands on something concrete: whether multi-factor is on for everyone, who holds administrator rights, what is shared and with whom, whether a restore has ever been tested, and whether the logs that would answer any of it are switched on.
The six questions
We walk them in the order the incident would. Most teams answer two or three with confidence.
- 01
Whose account was it, and what could it reach?
Administrator rights nobody remembers granting, and access that outlived a role change.
- 02
How would you even know?
Whether audit logging is on, how far back it goes, and who reads it.
- 03
Can you lock it out right now — at four on a Friday?
Multi-factor coverage, conditional access, and who can actually revoke a session out of hours.
- 04
What did it have access to, and what left with it?
Sharing defaults, standing links, and files open to everyone in the tenant.
- 05
Can you get back what was deleted?
Whether a backup exists outside the tenant, and whether a restore has ever been tested.
- 06
Who do you have to tell, and how soon?
Loi 25 obligations, your cyber insurer's notification window, and the clients in the affected files.
What you leave with
- A written summary of what held and what did not, sent within five business days.
- The gaps ranked, with what each one would cost to close.
- Whatever you already do well, stated plainly — most teams have more than they expect.
What this is not
- Not a simulation. Nothing is sent, nothing is phished, and no account is actually compromised.
- Not a penetration test. We do not attack anything, here or anywhere else.
- Not incident response. If an account is compromised right now, stop reading and call us — that is a different conversation.
The gaps it finds are the Microsoft 365 work
Multi-factor coverage, administrator accounts, sharing, a backup that has been restored from, and logs that are actually on. The drill shows you where you stand; the Microsoft 365 engagement is where it gets fixed.
Book the drill
Ninety minutes, CA$1,500, and a written summary within five business days. Most teams book it before a cyber insurance renewal or after a near miss.