Guide
How to respond to a phishing email in a small business
The value in phishing response is speed, not sophistication. If someone entered their credentials on a fake page, an attacker may already be in the mailbox setting up rules. The first hour matters more than the investigation that follows.
What you'll see
- A member of staff reports clicking a link and entering their password
- Colleagues receive odd emails apparently from an internal address
- Sent items contain messages the user did not write, or replies reference conversations they never had
The procedure
Step by step
Step 01
Contain the account immediately
Reset the password, revoke all sessions and require MFA re-registration on the affected account. Do this before investigating anything — every minute of access is another minute the attacker can use to establish persistence.
Step 02
Hunt for inbox rules and forwarding
Check for new inbox rules, especially ones that move mail to Archive, RSS Feeds or a rarely used folder, and check for external forwarding on the mailbox. This is the most common persistence trick in business email compromise and it survives a password reset.
Step 03
Review sign-in and audit logs
In Entra ID, review recent sign-ins for unfamiliar locations, IP addresses or clients, and check whether any MFA prompts were approved. In the audit log, look for consent grants to third-party applications, which is a quieter persistence route.
Step 04
Assess what was exposed
Work out what the account could reach: mailbox contents, SharePoint and OneDrive files, Teams chats, and any SaaS tool that uses Microsoft sign-in. If payroll, bank details or personal data were reachable, that changes your reporting obligations.
Step 05
Warn the people who need to know
Tell colleagues not to act on recent messages from the account, and warn any customer or supplier who received mail from it — invoice fraud follows business email compromise closely. Report the incident internally, and to the ICO within 72 hours if personal data was likely accessed.
Step 06
Close the gap
Confirm MFA is enforced for every account, not just this one, and review conditional access policies for gaps such as legacy authentication or unmanaged devices. Brief the team on what the message looked like — a real example teaches more than an annual training module.
When to stop and escalate
Escalate to specialist incident response if finance data was touched, if a payment has already been diverted, if multiple accounts are affected, or if you find persistence you cannot fully remove. Preserve logs before making further changes.
How AlwaysOnIT handles it
AlwaysOnIT handles phishing triage in chat at any hour: containment first, then rule and forwarding checks, sign-in log review and a written timeline you can hand to your insurer or your auditor.
Get started
Open a chat. The AI picks up before the second ring — every time.
No onboarding calls. No sales process. Connect your devices and start raising tickets in under ten minutes.