
Incident Response
For organizations whose email or accounts may already be in someone else's hands, and who need the attacker out, the damage understood, and the gap closed before it happens again.
Short on time? Let your favourite AI sum up Teclara.
A response engagement for organizations dealing with a suspected account takeover, business email compromise, or other active incident in Microsoft 365 or Google Workspace. We contain the affected accounts, investigate what the attacker reached, remove what they left behind, and close the gap that let them in. Once the environment is clean, it can move into Managed Security & Compliance so the monitoring and response that were missing stay in place.
- Duration
- Scoped to the incident
- Engagement
- Response
Output
What you walk away with
A defined output, on paper or in your tenant. Yours to use whether the work continues with us or not.
Containment
Active sessions revoked, passwords and sign-in methods reset, and the attacker's foothold removed, including forwarding rules, mailbox rules, and connected applications.
Investigation timeline
Sign-ins, sessions, mailbox changes, application access, and affected files placed in one timeline, so you can see what the attacker reached and when.
Clean-up and hardening
The weakness that let the attacker in is closed, whether that was missing MFA, a legacy sign-in path, or an administrator role nobody needed.
Path into managed coverage
A plan to bring the cleaned environment into Managed Security & Compliance, so sign-ins, email, and devices are watched by a human-led team from then on.
How it works
How the work runs
A short, defined sequence. Nothing in your tenant or domain changes until the scope and access are confirmed.
First call
Tell us what you are seeing. We confirm the platform, who can grant administrative access, and which accounts look affected.
Containment
We cut off the attacker's access first: sessions, credentials, sign-in methods, and anything they configured to keep a way back in.
Investigation
We work through the sign-in, mailbox, and application records to establish what was accessed, sent, or changed.
Clean-up and hardening
We remove what the attacker left behind and fix the control that failed, so the same route is not open next week.
Handoff
You get the timeline, a record of what changed, and the path into managed coverage. Legal, insurance, privacy, and client notification decisions stay with your counsel, insurer, and leadership.
Best fit
When this engagement is useful
A staff mailbox is sending messages nobody on the team wrote
A client or supplier received a payment or banking change request that did not come from you
Someone approved a sign-in prompt they did not start
Forwarding rules, mailbox rules, or connected apps appeared that nobody set up
Ransomware or unfamiliar activity has appeared on a work device
Frequently asked questions.
Who is Incident Response: Account Takeover and Email Compromise for?
Incident Response: Account Takeover and Email Compromise is built for organizations with a suspected account takeover, Microsoft 365 or Google Workspace teams, and owners dealing with a fraudulent payment request.
How does this engagement start?
Every engagement starts with a short first call to confirm the situation, the decision owner, the access required, and whether this is the right engagement for what you actually need.
What happens after the first call?
Teclara confirms the scope, the access, and the timing. If the engagement is a fit, we agree on the work and start. If a different engagement fits better, we say so.
Short on time? Let your favourite AI sum up Teclara.
Ready to start?
Book the first call. We will confirm the situation, the access required, and whether this engagement is the right starting point.
