Identity compromise
Identity compromise response and readiness guide
Identity compromise response should invalidate active sessions, secure recovery methods, contain privilege, preserve sign-in evidence and identify the attacker’s persistence path. Password reset alone is rarely sufficient because tokens, forwarding rules, delegated applications and recovery channels can remain usable.
Control checklist
What to verify first.
Use evidence from the real environment. A written policy without current configuration, ownership or testing is not enough.
Maintain a current inventory of privileged, shared, service and emergency accounts.
Use phishing-resistant authentication for administrators wherever supported.
Alert on risky sign-ins, impossible travel, new authentication methods and privilege changes.
Document how to revoke sessions, reset credentials and remove malicious authentication methods.
Check mailbox rules, delegated access, OAuth grants and application credentials after compromise.
Preserve sign-in, audit and endpoint evidence before routine retention removes it.
Define who can disable a high-impact account and who approves restoration.
Exercise one realistic identity-compromise scenario at least annually.
Decision flow
Move from uncertainty to evidence.
The sequence keeps discovery, control changes and proof connected.
- 01
Verify
Confirm the signal and establish the affected identity, sessions and devices.
- 02
Contain
Revoke sessions, restrict access and protect unaffected administrator paths.
- 03
Remove
Delete persistence through rules, grants, credentials and recovery methods.
- 04
Recover
Restore controlled access, monitor recurrence and record improvement actions.
Assessment template
Record control status and evidence.
Use the blank fields in a workshop or print this page. Mark a control evidenced only when the supporting record is current and attributable.
Related service
Cloud & Identity Security
Reduce account compromise risk and establish a clear containment and recovery process across cloud identity providers.
Official sources
Continue with primary guidance.
Requirements and platform capabilities change. Confirm time-sensitive decisions against the current source.
Related analysis
Apply the guide to current risks.
Healthcare cyber incidents: operational lessons from July 2026
Recent healthcare incidents show how cyber extortion can disrupt medical operations. These are the containment and resilience lessons for care providers.
Read insight ↗
Dolphin X: the rise of AI-driven behavioral profiling in malware
Researchers report that Dolphin X is marketed with AI-assisted profiling designed to prioritize high-value targets. Here is what defenders should take from the claim.
Read insight ↗