Skip to main content
    Graphite IT
    03300 583007Contact Us
    All articles

    Cyber Security

    Nobody hacked your computer. They just logged in.

    Every Microsoft 365 security alert we have raised this year has been about an account, not a virus - and the quietest one on the list is usually the worst.

    8 October 2026 4 min readBy Claude
    A calm office where a sign-in from an unexpected location is quietly flagged

    Ask most people to picture a cyber attack on a small business and they picture a virus. Something that arrives as an attachment, sets off an alarm, and gets cleaned off the machine.

    That is not what we see.

    Looking back over the security alerts raised across the Microsoft 365 accounts we monitor this year, every single one has been about an account, not a machine.

    What those alerts actually looked like

    AlertWhat it means
    Unexpected sign-inAn account signing in from somewhere it never normally does.
    Impossible travelThe same account appearing in two countries closer together than a flight would allow.
    Unusual sendingA mailbox quietly sending far more than it normally does.
    New inbox ruleA rule created from an IP address nobody recognises.

    Not one was a virus. They were all logins.

    Why that matters more than it sounds

    A virus is noisy. It breaks something, or it trips an alarm, and you know you have a problem.

    Someone signing in with a real username and a real password is not noisy at all. As far as the system is concerned, that is just you arriving at work. Nothing is broken. Nothing looks wrong. The attacker does not need to defeat your security — they have been handed a key.

    That is why the mailbox rule one is worth understanding properly. It is the quietest thing on the list and it is usually the most serious.

    Someone gets into an email account. Before doing anything else, they create a rule that files replies from your finance team, or your bank, or one particular supplier, straight into a folder nobody opens. Then they start a conversation — and the real account owner never sees the answers coming back.

    Nothing has crashed. No alert has gone off on anyone's laptop. The account is working perfectly. It is just also working for somebody else.

    Most alerts turn out to be nothing — and that is the job

    Here is the part that gets skipped in most write-ups of this sort: the large majority of the alerts we investigate turn out to be completely benign. Somebody travelled. Somebody used a VPN. Somebody sent a big legitimate mailshot.

    An IT security analyst reviewing Microsoft 365 sign-in activity with one event flagged
    Most flagged sign-ins are routine. The point is that someone who can tell the difference actually looks.

    That is not a sign the monitoring is useless. It is the entire job. Each of those has to be looked at by someone who can tell the difference, because the small number that are not routine look identical until somebody checks.

    An alert nobody reads is not security. It is a log file.

    The other thing worth knowing: almost all of these land in the middle of the working day, not at three in the morning. The mental image of the hooded figure working overnight does not match what actually happens. These are business-hours events, because they usually start with a real person at a real desk clicking a real link.

    What actually helps

    If nearly every incident starts with a login, then the defences worth paying for are the ones that sit around logins.

    Multi-factor authentication on every account, without exceptions

    The exceptions are where this goes wrong — the shared mailbox, the director who finds it annoying, the old service account nobody owns. A stolen password on its own should not be enough to get in.

    Somebody watching the sign-ins

    Microsoft 365 will tell you about an impossible-travel login or a suspicious sign-in. It will tell the tenant, at three in the afternoon, whether or not anyone is looking.

    Check for mailbox rules you did not create

    Genuinely worth doing today, in your own mailbox, before you finish reading this. It takes a minute and it is the single most common thing we find left behind.

    Know who still has an account

    Leavers who were never fully disabled are a standing open door, and they are easy to miss when someone left eighteen months ago and nobody closed the loop.

    Cyber Essentials as a floor, not a finish line

    It forces the basics — access control, MFA, patching — into a form somebody has to actually sign off.

    The honest version

    None of this is exotic. There is no clever product at the end of this article that makes the problem go away.

    The businesses that come off worst are almost never the ones that got outsmarted by something sophisticated. They are the ones where an account had no MFA, nobody was reading the alerts, and a mailbox rule sat there for a fortnight doing its job perfectly.

    Worth ten minutes of somebody's attention this week.

    If you would like someone to look at how your Microsoft 365 accounts are actually secured — and who is watching them — get in touch. That is the sort of thing we do.

    Need help with your IT?

    Get practical advice from the Graphite IT team.

    Talk to us

    Related Articles

    Phishing is still the front door: a 15-minute check for your team this October
    Cyber Security
    October 2026

    Phishing is still the front door: a 15-minute check for your team this October

    Read More
    The 20 Most Used Passwords in the UK
    Cyber Security
    March 2026

    The 20 Most Used Passwords in the UK

    Read More
    10 Cyber Security Habits Every Employee Should Know
    Cyber Security
    March 2026

    10 Cyber Security Habits Every Employee Should Know

    Read More
    Graphite IT

    South Yorkshire's trusted IT partner. Managed IT support, cyber security, and cloud solutions for UK businesses.

    IT insights, no spam

    graphiteit.io — SaaS Apps

    Services

    • View All Services
    • Managed IT Support
    • Cyber Security
    • Cloud Solutions
    • Microsoft 365
    • Cloud Backup
    • Disaster Recovery
    • IT Procurement
    • SaaS App Platform

    More Services

    • Digital Transformation
    • Connectivity
    • Mobile & Telecom
    • AI in the Workplace
    • Data & Analytics
    • Web Design & Hosting

    Company

    • About Us
    • Industries We Serve
    • Meet the Team
    • Case Studies
    • Blog
    • Careers
    • FAQ
    • Free Tools
    • Compliance Guides
    • Compare IT Options
    • IT Glossary
    • System Status

    IT Support By Area

    • Sheffield
    • Rotherham
    • Doncaster
    • Barnsley
    • Leeds
    • Wakefield
    • Chesterfield
    • All locations →

    Pricing

    • View Pricing
    • IT Assessment
    • Get a Quote

    Contact

    03300 583007 hello@graphiteit.com
    South Yorkshire, UK
    Cyber Essentials Certified
    GDPR Compliant
    ISO 27001 Aligned
    24/7 Emergency Support
    © 2026 Graphite IT. All rights reserved.·Co. Reg. 15462958·VAT GB467113788
    Contact UsPrivacy Policy
    All systems operational