Direct answer
Protect the affected identity and business process first: preserve the suspicious message and authentication evidence, contain the affected account, revoke risky sessions or tokens, verify payment or data-change requests through an independent channel, identify related messages and accounts, and record every containment and recovery action in one incident timeline.
When to activate this playbook
A user reports a suspicious message, link, attachment or sign-in prompt.
Mailbox rules, forwarding settings, delegates or authentication methods changed unexpectedly.
A payment, bank-detail, payroll, supplier or account-change request cannot be independently verified.
Sign-in, session or application-consent activity is inconsistent with the user’s normal context.
First 15 minutes
Open an incident record and assign an incident owner.
Preserve the original message, headers, attachments or links without forwarding them in a way that destroys metadata.
Protect the affected identity by revoking risky sessions and disabling or rotating exposed credentials as appropriate.
If money or sensitive data may be moving, freeze the business process and verify instructions through a trusted out-of-band channel.
First hour
Review authentication, mailbox, forwarding, delegate, consent and relevant endpoint evidence for the affected user.
Search for related messages, recipients, sender infrastructure or indicators across the organisation.
Determine whether credentials, tokens, payment instructions, sensitive files or customer data were exposed.
Notify the appropriate security, finance, legal, privacy and management owners based on the incident scope.
First day
Complete credential, token and application-consent remediation and confirm the account has returned to an approved state.
Trace any financial or data-transfer activity and preserve confirmations from banks, suppliers, customers or other affected parties.
Document root cause, control gaps, affected assets and the decision trail.
Create follow-up actions for mail controls, identity controls, user awareness, payment verification and monitoring.
Evidence to preserve
EvidenceOriginal message and full headers.
EvidenceAuthentication, session and conditional-access logs where available.
EvidenceMailbox rules, forwarding, delegates and application-consent records.
EvidenceEndpoint/browser telemetry relevant to the interaction.
EvidencePayment, supplier, payroll or data-change requests and independent verification records.
Key decision points
Was an account or session actually compromised?
Was money transferred or were payment details changed?
Was sensitive or regulated data accessed or disclosed?
Are related users, mailboxes or systems affected?
Communication discipline
Use an independent channel when validating payment or account-change requests.
Keep incident facts separate from assumptions and preserve a time-stamped decision log.
Escalate notification decisions to legal, privacy, regulatory or insurer contacts where applicable.
Where Cybatar fits
Incident ownership, severity, timeline and response-task coordination.
Evidence records and forensic escalation linked to the incident.
Threat-intelligence and event context connected to affected assets and identities.
Governance reporting and follow-up remediation evidence.
Claim boundary
Cybatar can coordinate incident records, evidence, tasks and reporting, but it does not guarantee phishing prevention, mailbox recovery, fund recovery or legal/regulatory compliance. Identity, email, endpoint, banking and specialist-response actions depend on the organisation’s connected systems and response authority.