Imagine this:
• An employee receives a convincing phishing email
• They click the link
• They enter their credentials
• A few minutes later, something doesn't feel right
• They think their account may have been compromised.
What happens next?
This is where the difference between having security technology and having an effective security process becomes clear. The reality is that no organisation can prevent every compromise.
The question is whether you can detect it, contain it and understand what happened quickly.
The first few minutes matter
When someone thinks they have been compromised, there shouldn't be uncertainty about what to do.
They shouldn't be wondering:
• Who do I tell?
• Should I change my password?
• Can I keep working?
• Is my session still active?
• Has anyone accessed my files?
• Has someone sent emails from my account?
• What else could they have accessed?
The response should already be understood. The sooner an organisation can move from suspicion to investigation and containment, the better chance it has of limiting the impact.
Can you revalidate the user?
A compromised account creates a difficult problem.
The system may still recognise the person as a legitimate user. The credentials may be correct. The account may still be active, but the person using those credentials may no longer be the legitimate user.
This is why identity can't just be about authentication at the point of login. It needs to be continuously checked and if something changes, the organisation needs to be able to respond.
That could mean:
• Requiring additional verification
• Restricting access
• Revoking active sessions
• Resetting credentials
• Suspending the account while it is investigated.
The technology needs to support this process rather than leave the IT team trying to work out what to do in the middle of an incident.
Microsoft 365 and Google Workspace already give you some of the tools
For many organisations, Microsoft 365 or Google Workspace sits at the centre of how people work. Email, documents, collaboration, identity and business applications are all connected.
Both platforms also provide capabilities that can help organisations respond when an account is suspected of being compromised.
The challenge isn't necessarily whether those capabilities exist, it's whether they are being used effectively.
• Are they configured correctly?
• Are alerts being monitored?
• Does someone know what action to take?
• Can access be revoked quickly?
• Can you see what the account has been doing?
• And does the response form part of a wider security process?
Having the capability is one thing. Being ready to use it is another.
What did the account actually do?
Stopping access is only part of the response. You also need to understand what happened.
• What did the account access?
• Which applications were used?
• What files were opened or downloaded?
• Were emails sent?
• Were permissions changed?
• Did the account try to access other systems?
• Was the activity consistent with the user's normal behaviour?
This is where auditability becomes important. You need to be able to go back and understand what happened, rather than simply knowing that someone logged in from somewhere unusual.
Imagine this scenario:
• An employee receives a phishing email
• They enter their credentials
• An attacker logs into Microsoft 365
• They access SharePoint
• They start downloading files
• They send an email to a supplier
• They then try to access another application.
Individually, each event may not look particularly serious. Together, they tell a very different story. You need to be able to see that story.
Don't just respond to the alert
A security alert is only useful if something happens next. This is one of the gaps we often see in security environments. An organisation may have security products generating alerts, but the process for responding to those alerts isn't always as mature.
Someone needs to know:
• Who investigates?
• Who makes the decision to restrict access?
• How is the user revalidated?
• How are active sessions revoked?
• What needs to be investigated?
• When can the user safely get back to work?
These shouldn't be questions that are answered for the first time during an incident. They should already be part of the process.
What if the user hasn't actually been compromised?
There is another side to this. Not every unusual login means an account has been compromised. A user might be travelling or working from a different location or have a new device. They might legitimately need access to an application they haven't used before.
This is why context matters.
Security needs to be able to distinguish between something unusual and something genuinely risky. That is where behavioural analysis, identity signals and information from across the technology environment can become valuable.
One unusual event may not mean much. Several unusual events happening together may warrant action.
Where Com-X can help
At Com-X, we look beyond the individual security alert. We look at how identity, endpoint, digital workspace, cloud applications and data security work together. Because the compromise might start with an email, but it doesn't necessarily stay there.
The attacker could move from identity into Microsoft 365, into a collaboration platform, into files or into another application. If those systems aren't connected from a security perspective, it can be difficult to see the bigger picture.
We can help organisations understand what technology they already have, what it is capable of and where the gaps are. Sometimes the problem isn't that you need another security product. It's that the technology you already have isn't working together effectively.
Be ready before someone says, ‘I think I've been hacked’
A user saying they think they've been compromised shouldn't be the moment your organisation starts working out what to do.
You should already know:
• How they report it
• Who responds
• How their identity is checked
• How access can be restricted
• How sessions can be revoked
• What activity needs to be investigated
• How you safely restore access.
The technology is important, so is the process around it. Because when an account is compromised, every minute matters.
Where Com-X can help
Com-X can help you review your current security environment and identify the gaps in your ability to detect, investigate and respond to compromised accounts.
We can look across identity, Microsoft 365, Google Workspace, digital workspace, endpoint, cloud and data security to understand how your existing technology works together – and where it doesn't.




