An unfamiliar sign-in alert is one of the most common security events a law firm will see, and one of the easiest to mishandle. Some are harmless, such as a lawyer on a hotel network. Others are the first visible step of an account takeover. The difference often comes down to how quickly and methodically someone responds.
This walkthrough follows a hypothetical 20-attorney firm. No real firm or event is described. The aim is to show a sensible order of operations that you can adapt.
Hour 0: The alert arrives
Imagine an alert says an attorney's Microsoft 365 account signed in from another country at 3 a.m. The attorney is asleep in Dallas. A help desk technician or an on-call administrator sees it.
First, resist two instincts: ignoring it because it might be a false alarm, and panicking and wiping things. Instead, treat it as a possible compromise until proven otherwise.
Hours 0 to 1: Contain
Containment comes before investigation. The goal is to cut off the attacker without destroying evidence.
- Reset the password and force sign-out of all active sessions and tokens. A password change alone may not end an attacker's existing session.
- Review multi-factor methods. Attackers sometimes register their own phone or authenticator app. Remove any method the user does not recognize.
- Block the suspicious sign-in source if your tools allow it.
- Preserve logs. Export sign-in and audit logs before retention windows roll over.
- Notify the firm's incident lead. Decide who owns the response.
Hours 1 to 4: Scope
Now ask what the attacker could see or do.
- Check mailbox rules. Attackers frequently create rules that forward mail externally or hide messages containing words like "invoice" or "wire."
- Review sent items and look for messages the user did not write, especially to clients or the firm's accounting staff.
- Check file access in the document management system and shared drives.
- Look for new app consents or connected applications.
- See whether the same source touched other accounts.
If the account belongs to a lawyer who handles real estate closings or settlements, pay extra attention to anything touching payment instructions.
Hours 4 to 8: Decide on notification
If evidence shows the attacker accessed client information, the firm's obligations come into play. ABA Model Rule 1.4 on communication and Formal Opinion 483 on lawyers' obligations after a data breach are common reference points, and state law may add notification duties. Bring in the managing partner and, where appropriate, outside counsel and your cyber insurance carrier. Many policies require prompt notice, so check yours. Do not make a final determination alone at 5 a.m.
If clients may have been targeted through the compromised account, contact them by phone using a number you already have, not one from the suspicious email.
Hours 8 to 24: Recover and harden
- Confirm that unauthorized rules, devices and app permissions are removed.
- Scan the user's devices for malware.
- Re-enable access with a fresh password and verified MFA.
- Check whether conditional access, geographic restrictions or stronger authentication methods would have blocked the sign-in.
- Brief the affected attorney, without blame, on what happened.
After the first day: Write it down
Document the timeline, the decisions, who was notified and what was changed. A one-page summary is enough. This record helps with insurance, client questions and your own improvement.
Then ask hard questions:
- Why was this account reachable from that location?
- Did MFA fail, or was it bypassed through a stolen session?
- How long did it take to notice and to respond?
- Is someone watching alerts outside business hours?
Build the muscle before you need it
Few small firms have anyone awake to read alerts at 3 a.m. That is the case for managed detection and response, where a security team monitors around the clock and takes first-step containment actions you pre-approve. Even without that, you can write a one-page playbook and practice it once a year.
Counsel Cyber provides monitoring and incident response for law firms, and we can help you write a playbook that fits your size. If you would like to run a tabletop exercise based on a scenario like this, we can arrange one.