What a 02:14 alert looks like from our side
Minute by minute: a forwarding rule on an accounts payable mailbox, found and contained before anyone was awake.
Priya Raman, night watch lead
6 min

At 02:14 on a Sunday in September, Microsoft 365 flagged a sign-in to an accounts payable mailbox from a new country. The MFA push had been approved. The mailbox owner was asleep in Dayton.
The first three minutes
Our platform opened a case at 02:15 because a second signal arrived forty seconds after the sign-in: a new inbox rule called RSS feeds, forwarding any message with invoice or remittance in it to an outside address. I took the case at 02:17.
Containment
The client’s runbook allows us to revoke sessions without a call, so we did that at 02:21, forced a password reset and re-registered MFA. The rule came out at 02:24. Seventeen outbound messages were sitting in the queue; none left.
The morning
We called the IT lead at 06:58, before his first coffee, and the written summary reached him at 07:30 with the timeline and fourteen evidence files. Two follow-ups went on the monthly report: number matching for MFA pushes, and a callback rule for vendor bank changes.
Thirty minutes to find out who is watching your network tonight.
Bring your last insurance questionnaire or audit finding. We tell you in plain words where you are exposed after hours and what closing it would cost, then send a written quote within two business days.