HomeBlog › Incident Response
Incident Response

Business Email Compromise Incident Response Checklist for IT Teams

BreachLens Research·May 25, 2026·8 min read

A repeatable, phase-by-phase checklist your team can follow the moment a Microsoft 365 mailbox compromise is suspected.

Think your Microsoft 365 may be compromised?

Upload your M365 audit log to BreachLens and get an instant, forensic-grade timeline of attacker activity — inbox rules, token theft, mailbox access and more. Free tier, no credit card, results in minutes.

Start a free investigation →

When a Business Email Compromise is suspected, ad-hoc responses cost time and evidence. This checklist gives IT and security teams a repeatable sequence aligned to the standard incident-response phases: contain, preserve, investigate, eradicate, recover, and report. Adapt it into your runbook.

Phase 1 — Contain (first 30–60 minutes)

Phase 2 — Preserve evidence

Phase 3 — Investigate

Phase 4 — Eradicate

Phase 5 — Recover

Phase 6 — Report & document

Phase 3 is where most investigations stall — manually correlating sign-in logs, mailbox-access events, and rule changes across thousands of rows. BreachLens automates that correlation from an uploaded M365 log and outputs the timeline and IOCs for you.

Get answers in minutes, not days

BreachLens parses your Microsoft 365 logs automatically and reconstructs exactly what an attacker did. Run your first investigation free.

Start a free investigation →

Frequently asked questions

What is the first step in a BEC incident response?

Containment: block sign-in for the affected account and revoke its active sessions in Microsoft Entra ID so stolen tokens stop working. Then reset the password out-of-band. If funds moved, call the bank to attempt a recall in parallel.

What evidence should be preserved during a BEC investigation?

Enable Unified Audit Logging, place the mailbox on Litigation Hold so deleted items are retained, and export the audit logs and mailbox before you remove rules or messages. Also log your own response actions with UTC timestamps.

Which Microsoft 365 logs matter most for BEC?

The Unified Audit Log, Microsoft Entra ID sign-in logs, and the MailItemsAccessed mailbox-audit events. Correlating all three reconstructs initial access, persistence, what was read, and dwell time.