Cybatar Security Hub · Governance · Risk Management · Threat Resilience · Compliance & Audit
Unified enterprise security operations for modern organisations
Security playbooks / Credential Compromise Response
Defensive incident response playbook

Credential Compromise Response

What should a security team do when credentials or authentication tokens may be compromised?

Direct answer

Contain access before investigating deeply: preserve authentication evidence, revoke active sessions and exposed tokens, rotate compromised credentials or secrets, confirm approved MFA and recovery methods, identify what the identity accessed or changed, and monitor for continued activity after containment.

When to activate this playbook

Impossible-travel, unfamiliar-device, unusual-location or anomalous sign-in activity. Unexpected MFA, recovery-method, token, API-key or password changes. Authentication succeeds after a user reports credential disclosure. An account performs actions outside its normal role or time pattern.

First 15 minutes

Open an incident and identify the affected identity, role and business owner. Preserve sign-in, token, identity-provider and application audit evidence. Revoke active sessions and exposed tokens and disable the account temporarily where risk justifies it. Rotate affected passwords, keys or secrets through an approved recovery process.

First hour

Review MFA, recovery methods, delegated access, application consent and privileged-role changes. Scope applications, cloud resources, mailboxes, endpoints and data accessed by the identity. Look for persistence such as new credentials, tokens, rules, delegates, keys or accounts. Determine whether other identities share the exposed secret or are linked to the same event.

First day

Restore approved authentication methods and least-privilege access. Confirm suspicious sessions, tokens and persistence mechanisms remain revoked. Review affected systems for follow-on actions and remediate unauthorised changes. Document control improvements for MFA, secret storage, privileged access and monitoring.

Evidence to preserve

EvidenceIdentity-provider sign-in and audit logs.
EvidenceSession, token, API-key and application-consent records.
EvidencePrivileged-role, group-membership and recovery-method changes.
EvidenceApplication and resource access logs for the affected identity.
EvidenceIncident timeline and credential-recovery actions.

Key decision points

Was the exposed credential actually used?

Did the identity have privileged access?

Were new persistence mechanisms created?

Did the compromised identity access sensitive data or critical systems?

Communication discipline

Coordinate identity recovery with the account owner and system administrators. Use trusted channels for reset or recovery steps. Escalate material access or data-exposure findings to legal, privacy and business owners.

Where Cybatar fits

Incident and task coordination across security and business owners. Event, asset, exposure and evidence context attached to the incident. Threat-hunting and IOC records for related activity. Audit and governance records for remediation decisions.

Claim boundary

Cybatar is an operating and evidence layer; it does not itself guarantee identity-provider session revocation, credential rotation or MFA enforcement unless those actions are available through the organisation’s connected systems and authorised workflows.