Cyber security
A practical Microsoft 365 business email compromise response plan
What an Australian small or medium-sized business should contain, preserve, check and recover after a Microsoft 365 account compromise.
First response
Treat suspected business email compromise as both an identity incident and a business-process incident. Containing the account is necessary, but payment instructions, mailbox rules, sessions, delegated access, application consent and affected contacts also need investigation. Preserve evidence before routine clean-up makes the sequence harder to understand.
Work through it in this order
- 01
Activate the decision path
Name the incident lead, finance contact and technical responder. Record the time, reporter and suspected accounts.
- 02
Contain identity access
Disable or restrict affected access, revoke sessions, reset credentials safely, review multi-factor authentication (MFA) methods and protect privileged accounts.
- 03
Preserve and inspect
Retain relevant audit, sign-in and message information; review forwarding, inbox rules, delegates, application consent and unusual administrative changes.
- 04
Protect money and relationships
Call the bank promptly when payment may be affected. Verify recent supplier and payroll changes using trusted details and notify affected parties carefully.
- 05
Recover and learn
Remove persistence, re-enable access in a controlled way, monitor for recurrence and repair approval, verification and administrative processes.
From day-to-day administration
Details worth settling early
Investigate the identity and the mailbox
For a smaller Microsoft 365 tenant, a useful order is sign-in activity and active sessions, registered multi-factor authentication methods, forwarding and inbox rules, delegates, application consent, then payment and supplier processes. A password reset on its own does not answer how access was obtained or what changed afterwards.
Finance needs a separate workstream
Technical containment does not cancel a fraudulent transfer. Recent bank-detail changes, supplier payments and payroll instructions need verification through contact details that did not come from the affected mailbox.
Keep these points in view
- The Australian Signals Directorate lists email compromise and financially damaging business email compromise among the leading reported cybercrime types for business.
- Use a known-safe channel to verify payment changes; avoid the compromised email thread.
- Recovery is incomplete until the entry path and business-process weakness are addressed.
- Finance, identity and communication decisions need one coordinated incident timeline.
Before closing the issue
- Incident lead named
- Sessions revoked
- MFA and app consent reviewed
- Mailbox rules checked
- Payment risk escalated
- Evidence retained
- Root cause and control changes documented
Easy mistakes under pressure
- Replying inside a potentially compromised thread
- Resetting only the password while leaving sessions or malicious rules active
- Sending broad claims before facts, legal duties and affected parties are understood
Official guidance to keep nearby
- Australian Signals Directorate, Australian Cyber Security Centre — Annual Cyber Threat Report 2024–25
- Australian Signals Directorate, Australian Cyber Security Centre — Business email compromise
- Australian Signals Directorate, Australian Cyber Security Centre — Implementing multi-factor authentication
- Microsoft Learn — Microsoft 365 security solutions
Links and technical details checked 2 September 2026. Corrections can be sent to info@turnstoneai.com.