WHAT TO EXPECT
Clear action.
No runaround.
Do not keep using the suspected account to discuss the incident. Call or text from a separate device if possible.
Start with one problem. You work directly with the senior person diagnosing it and doing the work.
01What I do first
Reset the compromised password, revoke active sessions and app tokens, enforce MFA, inspect sign-in activity, remove malicious inbox and forwarding rules, and check whether other accounts were targeted. The goal is containment before cleanup.
02What attackers commonly change
Business email attackers often create hidden forwarding rules, register their own authentication method, authorize a malicious application, delete security alerts, or quietly monitor invoice conversations. A password reset alone may not remove that access.
03What happens after containment
I review mail flow and audit evidence, correct SPF, DKIM, and DMARC where needed, secure administrator accounts, document the incident, and give the owner a plain-English explanation of what happened and what should change next.
04When money or invoices are involved
Contact the bank immediately using a known number, preserve messages and transaction details, and notify appropriate insurers or counsel. I can help preserve technical evidence, but financial recovery and legal reporting should begin without waiting for the IT cleanup.