Nobody breaks in any more. They sign in.
The account is the way into the business, and the credential that opens it may already be circulating somewhere your staff have never heard of. This is monitoring for that, and the controls that make a stolen password worth nothing.
An attacker with a working username and password does not trip anything. There is no exploit to detect and no malware to quarantine, because from the outside it is simply one of your staff signing in. That is why identity, rather than the laptop, is where this work now sits.
Continuous monitoring for company domains, email addresses and credentials appearing where stolen data is traded.
Multi factor authentication and conditional access configured, then checked for the accounts that were exempted and forgotten.
A containment path that covers what a password reset alone leaves behind.
What does identity protection mean in practice?
It means treating the sign in as the thing being defended. In practice that is a short list: every account carries multi factor authentication, the conditions under which a sign in is allowed at all are written down and enforced, administrator accounts are separate from everyday ones, mailbox auditing is switched on, and somebody notices when a credential belonging to the business appears in a leaked data set. None of it is exotic. Most of it is simply owned by nobody.
Why does a leak somewhere else become our problem?
Because people reuse passwords. When a retailer or a forum a member of staff signed up to with their work address is breached, the pair that leaks is a work email address and a password, and the question is only whether that password is also the one that opens your email. Dark web monitoring is how you find out before somebody else tries it.
What actually stops a stolen password being useful?
Multi factor authentication, first and by a distance, because a password on its own stops being enough. After that: conditional access, so a sign in from an unexpected place or an unmanaged device is challenged or refused; separate administrator accounts, so the one credential that leaks is not the one that can change everything; and revoking sessions rather than only resetting passwords, because a token already issued keeps working after the password changes.
How is this different from antivirus?
Antivirus looks for something malicious running on a device. This looks at whether the right person is signing in. Both matter, and the second one is where the incidents we are called about now start: a legitimate sign in from a stolen credential, an inbox rule quietly forwarding invoices, and a payment redirected weeks later. Nothing on the endpoint was ever infected.
Is this only a Microsoft 365 concern?
No, but Microsoft 365 is usually where the damage lands, because it holds the email that authorises payments and the files worth taking. The same logic applies to your accounting system, your remote access and any cloud service holding customer records. The starting point is a list of what your staff can sign in to, which is a question a surprising number of businesses cannot answer.
The two pieces of this with pages of their own
Before you call
Is this included in the service plans?
We already have multi factor authentication. Do we still need this?
Can you tell us what is already exposed before we commit to anything?
What happens when something of ours turns up?
A free dark web scan
and thirty minutes.
We scan for your company email addresses, passwords and customer data in the places stolen and leaked data gets traded, then spend thirty minutes walking you through what came back and what it actually means. No pressure, no jargon, no obligation. You keep the report either way.
Worried about what it takes to move?
Changing IT provider is the single biggest reason businesses stay somewhere they have outgrown. We plan the move around your working week, and we help carry the cost of getting across. Ask us how that works when we speak.