When something is compromised.
WHAT TO RECOGNISE
Reports of unexpected messages sent from a user's account Credentials entered on a suspicious site Ransom messages or encrypted files Unexpected software or behaviour Multiple users reporting the same odd thing
WHAT TO DO IMMEDIATELY
Treat it as an incident, not an ordinary fault
Contain: disconnect the device from the network
Do not power it off without considering evidence Escalate, per your process
WHAT TO DO ABOUT CREDENTIALS
Assume they are compromised, and reset them from a clean device.
WHAT ELSE TO DO
End active sessions Check for mail rules or forwarding the user did not create
WHY THAT LAST ONE
It is the classic sign of a compromised mailbox, and it persists after a password change.
WHAT TO RECORD
Times, what was observed, what was done.
WHY TIMES
Notification obligations frequently run from when you became aware.
WHAT NOT TO DO
Investigate alone beyond your authority Delay reporting Blame the user
WHY THAT LAST ONE
It ensures the next incident is concealed.
WHAT TO TELL THE USER
That reporting was the right action.