All casework
Cyber Incident Investigation
Reconstructing a business email compromise
How mailbox activity, payment communications and access logs can be organized into a defensible incident timeline.
THE CHALLENGE
A payment instruction appeared to come from a known counterparty, but the organization needed to establish whether an account had been compromised and when.
Jurisdiction
United Kingdom / Europe
APPROACH
- Preserved original emails and headers
- Reviewed sign-in and mailbox audit activity
- Examined forwarding rules and message handling
- Correlated technical activity with the payment timeline
DELIVERABLES
- Incident chronology
- Indicators schedule
- Evidence appendix
- Containment recommendations
OUTCOME & LIMITATIONS
The organization received a clear separation between confirmed activity, likely intrusion points and remaining evidential gaps.