PRACTICAL RESULTS

Real technology problems. Practical action. Clearer business control.

Technology and security work matters most when it helps a business regain access, contain an incident or address risks that have been left unresolved.

These examples show how OmekaTech has approached real Microsoft 365 and email-security issues, connecting technical actions with the business need to restore operations and protect information.

Client identities are withheld to protect confidentiality. Results depend on each organisation’s environment and circumstances.

EXPLORE THE EXAMPLES

See the situation, the response and the result.

Each example explains the problem, the work undertaken and the outcome supported by the available records.

Client identities are withheld to protect confidentiality. Results depend on each organisation’s environment and circumstances.

MICROSOFT 365 • RECOVERY • SECURITY UPLIFT

Recovering access and strengthening Microsoft 365 security

A business lost access to its Microsoft 365 environment following a tenant compromise. OmekaTech assisted with recovery and subsequent security improvements.

Microsoft Secure Score increased from 25% to 65% during the documented security uplift.

EMAIL SECURITY • INCIDENT RESPONSE

Containing a compromised mailbox and warning external recipients

A compromised mailbox sent a malicious PDF to external contacts. Unauthorised rules and automatic-reply settings also affected normal mailbox behaviour.

18 external recipients identified and assisted with notification and resolution.

CASE STUDY 01 — MICROSOFT 365

Recovering access and improving the security of a compromised Microsoft 365 environment.

A business experienced a Microsoft 365 tenant compromise and lost access to its environment, including email. The immediate priority was to assist with recovery, followed by a review of security weaknesses and practical improvement work.

The situation

The incident exposed the business’s dependence on Microsoft 365 and highlighted the need for stronger access controls and clearer security oversight.

Restoring access was an immediate operational concern. Addressing the underlying security position was also necessary to reduce ongoing exposure.

The response

OmekaTech assisted with the recovery process and subsequent Microsoft 365 security uplift.

The work included moving from Microsoft 365 Business Basic to Business Premium and introducing Conditional Access controls as part of the improvement program.

The engagement combined immediate recovery assistance with changes intended to establish a stronger security position.

The outcome

Access was recovered and the business’s Microsoft 365 security configuration was strengthened.

Microsoft Secure Score increased from 25% to 65% during the documented uplift. This provided a measurable indication of progress against Microsoft’s security recommendations.

25%

Recorded starting Microsoft Secure Score

65%

Recorded Microsoft Secure Score following the uplift

Stronger controls

Conditional Access introduced as part of the security improvement work

Microsoft Secure Score is an indicator of configuration progress. It is not a guarantee against compromise, a complete risk assessment or proof of compliance.

Recovering access is only part of the response. A business also needs to understand why the incident occurred, strengthen relevant controls and establish ongoing responsibility for security.

Explore Microsoft 365 Security
Explore Cybersecurity & Risk Management

Client identity has been withheld. Results relate to this engagement and should not be interpreted as a promised outcome for another organisation.

CASE STUDY 02 — EMAIL SECURITY

Containing a compromised mailbox and protecting external recipients.

The situation

A compromised business mailbox was used to send a malicious PDF to external contacts.

Unauthorised mailbox rules and out-of-office settings had also been created, affecting how messages were handled and displayed. Messages had been redirected away from the normal inbox.

The response

OmekaTech reviewed the affected mailbox, removed the unauthorised rules and out-of-office changes, and restored messages that had been redirected away from the inbox.

An email security policy was created to block the identified PDF. Sent-message information was exported to support the investigation.

The business was also assisted with notifying 18 external recipients so they could take appropriate precautions.

The outcome

The malicious message was restricted, normal mailbox behaviour was restored and affected external contacts were warned promptly.

The business retained a clearer record of the event and the response actions taken.

18

External recipients identified and assisted with notification

1

Identified malicious file blocked through email policy

Clearer records

Evidence, communication and response actions documented

A compromised account requires more than a password change. Mailbox settings, message activity, external recipients and response records also need attention.

Explore Microsoft 365 Security
Explore Cybersecurity & Risk Management

What Happens to Business Access When an Employee Leaves?

Client details have been withheld to protect confidentiality. Results vary according to the nature, timing and scope of each incident.

LESSONS FOR BUSINESS LEADERS

A useful response connects immediate action with longer-term improvement.

01

Restore and contain

Identify the immediate operational or security issue and take appropriate action to regain control of the affected environment.

02

Review the wider exposure

Identify the immediate operational or security issue and take appropriate action to regain control of the affected environment.

03

Keep a clear record

Document findings, changes, communications and outstanding actions so leadership understands what happened and what still requires attention.

04

Improve the controls

Translate the findings into practical security and management improvements, with clear ownership and review arrangements.

The appropriate response depends on the incident, the systems involved and the information available. These examples illustrate specific engagements rather than a universal response checklist.

THE BEST PLACE TO START

Understand your technology risks before they become a business disruption.

The Executive Technology and Security Assessment gives leadership an independent view of the current technology environment, material risks and recommended priorities.

The review is valued at $795 and is available at no cost to qualified businesses.

  • Z
    A current-state technology and security summary
  • Z
    Prioritised risks and improvement opportunities
  • Z
    Practical recommendations and next steps

No obligation to proceed with an ongoing service.

FREQUENTLY ASKED QUESTIONS

Questions about these case studies

Why are client names withheld?

These examples involve sensitive business and security information. Client identities and identifying details have been withheld to protect confidentiality.

Can you guarantee the same result for our business?

No. Outcomes depend on the organisation’s environment, the nature and timing of the issue, available evidence, existing controls and the scope of the engagement. An assessment is required before appropriate recommendations can be made.

Does a higher Microsoft Secure Score mean a business is secure?

A higher score can indicate progress against Microsoft’s security recommendations. It does not guarantee that an organisation cannot be compromised, replace a business risk assessment or establish compliance.

Can OmekaTech work with our existing IT provider?

Yes. OmekaTech can provide assessment, security expertise or defined improvement work alongside an existing IT provider or internal team. Responsibilities and communication paths are agreed at the beginning.

Are these complete incident investigation reports?

No. These are concise summaries of selected engagements. They describe the situation, key response actions and recorded outcomes while omitting confidential information and detailed investigation material.

How do we get started?

For a planned review, start with the Executive Technology and Security Assessment. If you are experiencing an active incident, contact OmekaTech directly to discuss the issue and available assistance.