Administration
If you suspect someone got in
The first twenty minutes, in order, and who to tell.
The instinctive reaction is to investigate first. It is the wrong one: while you investigate, whoever got in is still inside. The right order is close, then look, and notify in parallel.
The first twenty minutes
- 1
Close that account's sessions
And change its password. It is the only urgent thing; everything else can wait ten minutes.
- 2
Enable or require two-factor
If it was not on, that is how they got in. A stolen password without a second factor opens the whole door.
- 3
Read that account's log
What was opened, what was downloaded and from where. Now it is time to investigate.
- 4
Notify the right people
The affected person, and whoever handles data protection if third-party data was reached.
What to look for in the log
| Signal | What it usually means |
|---|---|
| Bulk downloads | Someone taking information, not a mistake |
| Access from a place or time that does not fit | Check first whether that person was travelling |
| Permission changes | An attempt to keep access after you close it |
| A contact or bank account modified | Fraud in progress: check this before anything else |
Important
If third parties' personal data was reached — payroll, identity documents, client files — there may be notification duties on short deadlines. Tell whoever handles data protection that same day, even before you know the scope.
Watch out
Do not delete anything while investigating, not even to tidy up. The log is what lets you know what happened and prove how you responded.
Worth knowing
The commonest cause is not a sophisticated attack: it is a password reused on another service that leaked. Which is why mandatory two-factor is the measure that returns most for how little it costs.
›Can I see whether they downloaded anything?
Yes, accesses and downloads are logged.
›Do I notify affected clients?
That decision is not only technical. Let data protection make it with your adviser.
›What if it was a false alarm?
All the better. Closing one session too many costs one person a minute.
A real case
The situation
An employee reports an odd access alert on their account.
What you do
- Their sessions are closed and the password changed
- Two-factor is made mandatory for the whole organisation
- Their log is reviewed: nothing was downloaded
What you get
The scare closes in half an hour and the organisation comes out with protection it did not have before.
The situation
Access appears from an unexpected location.
What you do
- Closes the sessions and changes the password
What you get
Access is cut while it is investigated.
The situation
There is a suspicion and nobody knows what was touched.
What you do
- Checks that session's log
What you get
The scope becomes known.
The situation
Raising it is delayed out of uncertainty.
What you do
- Raises it anyway and documents the suspicion
What you get
The response does not wait for certainty.
The situation
The second factor was switched off.
What you do
- Turns it on for everyone after the incident
What you get
The cause is closed.
The situation
There is no record of what was done.
What you do
- Records what was done and when
What you get
The incident can be explained.
This article answers
- i think someone accessed our account
- unauthorised access what do i do
- an employee's password was stolen
- close open sessions