Microsoft 365 Compromise Assessment — Starting at $225 | Precision Forensics

Initial cybersecurity and forensic assessment

Precision M365 Compromise Assessment

Suspect a Microsoft 365 or business email compromise? Get an experienced initial assessment before the evidence disappears.

An initial assessment for organizations experiencing suspected Microsoft 365, Exchange Online, email-account, or identity compromise.

What the Initial Assessment Addresses

The assessment helps identify the apparent scope of the problem, preserve time-sensitive information, and determine the appropriate response.

Reported Activity

Review of known symptoms, suspicious messages, sign-in concerns, account changes, and the available incident context.

Apparent Scope

An initial view of affected users, accounts, services, and relevant time periods based on the information available.

Evidence Preservation

Identification of audit, sign-in, message, configuration, and other records that may require prompt preservation.

Risk Indicators

Initial review for indicators such as suspicious access, forwarding or inbox rules, account changes, or unauthorized application activity when available.

Recommended Actions

Practical containment, collection, investigation, notification, or remediation steps appropriate to the initial findings.

Situations That May Warrant Assessment

Suspicious Sign-Ins

Unexpected locations, devices, authentication events, or user reports suggest unauthorized account access.

Business Email Compromise

Fraudulent payment instructions, impersonation, altered correspondence, or unexplained mailbox activity.

Mailbox Changes

Unknown forwarding, inbox rules, delegates, message deletion, or configuration changes.

Identity Concerns

Unexpected password resets, multifactor-authentication changes, consent grants, or privilege changes.

Data Exposure Questions

Questions about what an unauthorized user may have accessed, sent, downloaded, or changed.

Preservation Deadlines

Audit and account records may be subject to licensing, retention, or availability limits and need prompt attention.

Clear scope

An Initial Assessment — Not Full Incident Response

The starting price covers a limited initial assessment based on the agreed scope and information available. A complete compromise investigation may require broader log collection, multiple accounts, third-party systems, or continuing response work.

  • The assessment does not guarantee identification of every affected account, action, or data item.
  • Available findings depend on Microsoft licensing, logging, retention, access, and the time elapsed.
  • Immediate security or legal obligations may require action outside this assessment.
  • Containment should be coordinated so that relevant evidence is preserved where practicable.
  • Any investigation, remediation, or incident-response work beyond the initial assessment is scoped and approved separately.

How It Works

1

Report the Concern

Describe the suspected compromise, affected users, observed activity, and actions already taken.

2

Review Available Evidence

Precision Forensics completes the agreed initial review and identifies preservation priorities and apparent indicators.

3

Plan the Response

Receive an explanation of preliminary findings, limitations, and recommended next investigative or response steps.

Starting at $225. Scope varies with the number of accounts, available records, and incident complexity. Any broader forensic investigation or incident-response engagement will be proposed separately.

Concerned About a Microsoft 365 or Email Account?

Begin with a focused assessment of the apparent problem, evidence-preservation needs, and next steps.

Starting at $225