For regulated financial & legal firms
Microsoft 365 Compromise Assessment
Seen something that doesn’t sit right — an unexpected login alert, a client replying to an email you never sent, a password reset you didn’t request? You don’t have to wonder. Our Compromise Assessment reviews the recent activity in your Microsoft 365 tenant for the specific signs of account takeover and tells you plainly whether someone has been in your environment. Provided at no cost to qualified financial and legal firms.
What We Look For
Inbox rules that hide an intruder’s tracks
Attackers who get into a mailbox often create hidden rules that quietly delete or forward mail so their activity never surfaces. We review every inbox and forwarding rule so each one can be confirmed as legitimate.
Apps granted access you didn’t approve
A common way attackers keep a foothold is by tricking a user into granting a malicious app permission to your data. We review every OAuth app consent for grants that don’t belong.
Sign-ins that don’t add up
Logins from unexpected countries, two locations minutes apart, or legacy protocols that slip past multi-factor are classic takeover indicators. We review recent sign-in activity for anomalies worth explaining.
Quiet changes to MFA and admin access
Registering a new multi-factor device or adding an administrator role is exactly what an attacker does to lock in access. We check for changes to MFA registration and privileged roles that no one on your team made.
What was opened — mail, files, and sites
Getting in is only half the question — what an intruder reached is the other half. Using the available audit and access logs, we identify which mailboxes, SharePoint sites, and OneDrive files were opened during the period in question, so you know what was actually exposed, not just that access occurred.
What was sent or taken out
We look for the signs that data left your tenant — mail auto-forwarded to outside addresses, files shared to external parties, or bulk downloads — so you have a clear picture of what may have been exfiltrated and what it means for your firm.
What You Receive
Compromise Assessment Findings Report
A concise report in plain language: either a clean bill of health, or the specific indicators we found — each one explained, with prioritized next steps.
Advisor Review
A working session with a Go West IT advisor to walk through what we found and what it means for your firm.
If we find evidence of an active or past compromise, we won’t leave you to figure out the next step. We’ll explain exactly what it means and the fastest, safest path to contain it.
SOC 2 Type II · Microsoft Partner — Modern Work, Enterprise · Built for RIAs, banks & law firms
Request Your Assessment
