30 Apr We Thought We Were Covered… Until This Happened
But increasingly, that’s not where problems start.
The SME who just didn’t see it
A UK-based SME (similar in size to many of our clients) recently experienced something subtle.
No alarms. No obvious breach. No ransomware screen.
Just a login from an unusual location.
It turned out to be a compromised Microsoft 365 account. The attacker didn’t force their way in — they logged in quietly using valid credentials.
Over the next few days:
- Emails were monitored
- Invoice details were altered
- A payment was redirected
Nothing “technical” failed. Everything worked exactly as it should.
That’s the problem.
Why this is happening more often
Most modern attacks don’t look like attacks anymore.
They look like:
- Normal logins
- Normal emails
- Normal user behaviour
Traditional tools don’t always flag this clearly — because technically, nothing is “broken”.
Where MDR fits in
This is where 24/7 monitored detection and response makes the difference.
Instead of relying on tools alone, you have:
- Continuous monitoring of behaviour
- Real people investigating unusual activity
- Fast response before issues escalate
This type of incident is exactly what MDR is designed to detect early — often before any real damage is done.
Final thought
If you’re unsure whether something like this would be visible in your current setup, we’re happy to run through it with you.
No pressure — just a quick, practical conversation.