Guide

How to respond to a phishing email in a small business

The value in phishing response is speed, not sophistication. If someone entered their credentials on a fake page, an attacker may already be in the mailbox setting up rules. The first hour matters more than the investigation that follows.

What you'll see

  • A member of staff reports clicking a link and entering their password
  • Colleagues receive odd emails apparently from an internal address
  • Sent items contain messages the user did not write, or replies reference conversations they never had

The procedure

Step by step

  1. Step 01

    Contain the account immediately

    Reset the password, revoke all sessions and require MFA re-registration on the affected account. Do this before investigating anything — every minute of access is another minute the attacker can use to establish persistence.

  2. Step 02

    Hunt for inbox rules and forwarding

    Check for new inbox rules, especially ones that move mail to Archive, RSS Feeds or a rarely used folder, and check for external forwarding on the mailbox. This is the most common persistence trick in business email compromise and it survives a password reset.

  3. Step 03

    Review sign-in and audit logs

    In Entra ID, review recent sign-ins for unfamiliar locations, IP addresses or clients, and check whether any MFA prompts were approved. In the audit log, look for consent grants to third-party applications, which is a quieter persistence route.

  4. Step 04

    Assess what was exposed

    Work out what the account could reach: mailbox contents, SharePoint and OneDrive files, Teams chats, and any SaaS tool that uses Microsoft sign-in. If payroll, bank details or personal data were reachable, that changes your reporting obligations.

  5. Step 05

    Warn the people who need to know

    Tell colleagues not to act on recent messages from the account, and warn any customer or supplier who received mail from it — invoice fraud follows business email compromise closely. Report the incident internally, and to the ICO within 72 hours if personal data was likely accessed.

  6. Step 06

    Close the gap

    Confirm MFA is enforced for every account, not just this one, and review conditional access policies for gaps such as legacy authentication or unmanaged devices. Brief the team on what the message looked like — a real example teaches more than an annual training module.

When to stop and escalate

Escalate to specialist incident response if finance data was touched, if a payment has already been diverted, if multiple accounts are affected, or if you find persistence you cannot fully remove. Preserve logs before making further changes.

How AlwaysOnIT handles it

AlwaysOnIT handles phishing triage in chat at any hour: containment first, then rule and forwarding checks, sign-in log review and a written timeline you can hand to your insurer or your auditor.

More walkthroughs in the guides index, terminology in the glossary.

Get started

Open a chat. The AI picks up before the second ring — every time.

No onboarding calls. No sales process. Connect your devices and start raising tickets in under ten minutes.