The first hour after someone clicks
Reset, revoke, hunt the rule, tell the right people. Do not start with a lecture.
ITSIGN Administrator · April 30, 2025 · 2 min read
Reset the password. Revoke sessions. Check inbox rules and forwarding. Check sign-in logs. Tell finance if the mailbox can approve payments. Then look at neighbours.
Do not punish the reporter. You want the next person to call you.
If the click became a foothold, that is incident response. If you want fewer clicks, that is awareness training.
Related reading
Email retention, PIPEDA, and the mailbox you never deleted
Keeping everything forever is not a strategy. It is a larger breach waiting for a number.
2 min read
When the phish comes from a vendor you trust
Their tenant, your payment. Callback still wins. So does knowing who is allowed to change details.
2 min read
Turn off IMAP and POP before someone else uses them
Legacy protocols skip modern MFA. They are still on in tenants that were migrated in a hurry.
2 min read
Want this applied to your environment?
A short conversation, an honest assessment of your current setup, and a clear proposal. No obligation and no pressure.
