Cyber Security
Nobody hacked your computer. They just logged in.
Every Microsoft 365 security alert we have raised this year has been about an account, not a virus - and the quietest one on the list is usually the worst.

Ask most people to picture a cyber attack on a small business and they picture a virus. Something that arrives as an attachment, sets off an alarm, and gets cleaned off the machine.
That is not what we see.
Looking back over the security alerts raised across the Microsoft 365 accounts we monitor this year, every single one has been about an account, not a machine.
What those alerts actually looked like
| Alert | What it means |
|---|---|
| Unexpected sign-in | An account signing in from somewhere it never normally does. |
| Impossible travel | The same account appearing in two countries closer together than a flight would allow. |
| Unusual sending | A mailbox quietly sending far more than it normally does. |
| New inbox rule | A rule created from an IP address nobody recognises. |
Not one was a virus. They were all logins.
Why that matters more than it sounds
A virus is noisy. It breaks something, or it trips an alarm, and you know you have a problem.
Someone signing in with a real username and a real password is not noisy at all. As far as the system is concerned, that is just you arriving at work. Nothing is broken. Nothing looks wrong. The attacker does not need to defeat your security — they have been handed a key.
That is why the mailbox rule one is worth understanding properly. It is the quietest thing on the list and it is usually the most serious.
Someone gets into an email account. Before doing anything else, they create a rule that files replies from your finance team, or your bank, or one particular supplier, straight into a folder nobody opens. Then they start a conversation — and the real account owner never sees the answers coming back.
Nothing has crashed. No alert has gone off on anyone's laptop. The account is working perfectly. It is just also working for somebody else.
Most alerts turn out to be nothing — and that is the job
Here is the part that gets skipped in most write-ups of this sort: the large majority of the alerts we investigate turn out to be completely benign. Somebody travelled. Somebody used a VPN. Somebody sent a big legitimate mailshot.

That is not a sign the monitoring is useless. It is the entire job. Each of those has to be looked at by someone who can tell the difference, because the small number that are not routine look identical until somebody checks.
An alert nobody reads is not security. It is a log file.
The other thing worth knowing: almost all of these land in the middle of the working day, not at three in the morning. The mental image of the hooded figure working overnight does not match what actually happens. These are business-hours events, because they usually start with a real person at a real desk clicking a real link.
What actually helps
If nearly every incident starts with a login, then the defences worth paying for are the ones that sit around logins.
Multi-factor authentication on every account, without exceptions
The exceptions are where this goes wrong — the shared mailbox, the director who finds it annoying, the old service account nobody owns. A stolen password on its own should not be enough to get in.
Somebody watching the sign-ins
Microsoft 365 will tell you about an impossible-travel login or a suspicious sign-in. It will tell the tenant, at three in the afternoon, whether or not anyone is looking.
Check for mailbox rules you did not create
Genuinely worth doing today, in your own mailbox, before you finish reading this. It takes a minute and it is the single most common thing we find left behind.
Know who still has an account
Leavers who were never fully disabled are a standing open door, and they are easy to miss when someone left eighteen months ago and nobody closed the loop.
Cyber Essentials as a floor, not a finish line
It forces the basics — access control, MFA, patching — into a form somebody has to actually sign off.
The honest version
None of this is exotic. There is no clever product at the end of this article that makes the problem go away.
The businesses that come off worst are almost never the ones that got outsmarted by something sophisticated. They are the ones where an account had no MFA, nobody was reading the alerts, and a mailbox rule sat there for a fortnight doing its job perfectly.
Worth ten minutes of somebody's attention this week.
If you would like someone to look at how your Microsoft 365 accounts are actually secured — and who is watching them — get in touch. That is the sort of thing we do.
Need help with your IT?
Get practical advice from the Graphite IT team.


