← Insights and resources

Identity compromise

Identity compromise response and readiness guide

Identity compromise response should invalidate active sessions, secure recovery methods, contain privilege, preserve sign-in evidence and identify the attacker’s persistence path. Password reset alone is rarely sufficient because tokens, forwarding rules, delegated applications and recovery channels can remain usable.

Practical assessment guideReviewed UK organisations

Control checklist

What to verify first.

Use evidence from the real environment. A written policy without current configuration, ownership or testing is not enough.

  1. Maintain a current inventory of privileged, shared, service and emergency accounts.

  2. Use phishing-resistant authentication for administrators wherever supported.

  3. Alert on risky sign-ins, impossible travel, new authentication methods and privilege changes.

  4. Document how to revoke sessions, reset credentials and remove malicious authentication methods.

  5. Check mailbox rules, delegated access, OAuth grants and application credentials after compromise.

  6. Preserve sign-in, audit and endpoint evidence before routine retention removes it.

  7. Define who can disable a high-impact account and who approves restoration.

  8. Exercise one realistic identity-compromise scenario at least annually.

Decision flow

Move from uncertainty to evidence.

The sequence keeps discovery, control changes and proof connected.

  1. 01

    Verify

    Confirm the signal and establish the affected identity, sessions and devices.

  2. 02

    Contain

    Revoke sessions, restrict access and protect unaffected administrator paths.

  3. 03

    Remove

    Delete persistence through rules, grants, credentials and recovery methods.

  4. 04

    Recover

    Restore controlled access, monitor recurrence and record improvement actions.

Assessment template

Record control status and evidence.

Use the blank fields in a workshop or print this page. Mark a control evidenced only when the supporting record is current and attributable.

Control areaEvidence to locateStatusOwner / action
Identity inventory Privileged, service, shared and break-glass account list Gap Partial Evidenced
Authentication strength MFA methods and exceptions by risk group Gap Partial Evidenced
Detection Risk alert routing and out-of-hours ownership Gap Partial Evidenced
Containment Session revocation and access-disable procedure Gap Partial Evidenced
Recovery Restoration approval, monitoring window and lessons review Gap Partial Evidenced

Related service

Cloud & Identity Security

Reduce account compromise risk and establish a clear containment and recovery process across cloud identity providers.

Explore Cloud & Identity SecurityDiscuss this assessment

Official sources

Continue with primary guidance.

Requirements and platform capabilities change. Confirm time-sensitive decisions against the current source.

Related analysis

Apply the guide to current risks.

Start with a conversation

Turn the assessment into an owned plan.

Share the scope, evidence and highest-priority gap. We’ll help define a proportionate next step for your environment.

Talk to an expert