Gold Coast professional services firm
- Challenge
- A security review of the firm's Microsoft 365 environment found that a partner's mailbox had been compromised through an adversary-in-the-middle phishing attack, the kind that captures a live signed-in session rather than just a password. The review also found accounts without multi-factor authentication.
- Solution
- We ran forensics on the affected mailbox to establish what the attacker had done, and removed their access. Then we closed the gaps the attack had walked through: multi-factor authentication enforced across the firm's accounts and conditional access policies to control how and from where people can sign in.
- Result
- The attacker's access was cut off, the firm has a documented record of exactly what happened, and the gaps the attack exploited are closed.
