Compromise Assessment:
Is an Attacker Already Inside?

A compromise assessment answers one question: is someone in your environment right now? We look for evidence of real attacker activity across Microsoft 365, Entra ID, cloud, email and endpoints.

Custom scoped, independent of your IT team and MSP, and finished with a written answer your board, counsel and insurer can rely on.

Home Hero Icon
Microsoft 365, Entra ID and cloud
Home Hero Icon
Mailbox rules, app consents and sign-ins
Home Hero Icon
Endpoint and identity forensics
Home Hero Icon
Before a deal closes or after an incident
Compromise assessment: findingsILLUSTRATIVE
Evidence of compromise
Inbox rule moving payment emails out of the finance team's view
Third-party app with full mailbox access, consented by one user
Sign-ins from a hosting provider the company does not use
Checked and clear
No persistence found on the servers sampled
No new admin accounts or role changes
Illustrative example, not client data

What is a compromise assessment?

A compromise assessment is an investigation into whether an attacker is in your environment right now, or has been. It does not test whether you could be breached. It looks for evidence that you already were: stolen sessions, rogue mailbox rules, new admin accounts, persistence on servers and data leaving the network.

The output is a verdict, compromised or clean, with the evidence behind it. If the answer is compromised, the work moves straight into containment and incident response. If the answer is clean, you have a dated, independent record that you looked.

247 days
average time to identify and contain a breach (IBM, 2026)
$4.99M
global average cost of a data breach (IBM, 2026)
$11.5M
average cost of a data breach in the United States (IBM, 2026)

Compromise assessment vs vulnerability assessment vs penetration test

Question
Compromise assessment
Vulnerability assessment
Penetration test
The question it answers
Compromise assessment
Is an attacker already inside?
Vulnerability assessment
Where are we exposed?
Penetration test
Could an attacker get in?
Looks at
Compromise assessment
Logs, sign-ins, mailboxes, endpoints and cloud activity for evidence of attacker activity
Vulnerability assessment
Systems and settings for known weaknesses
Penetration test
Defenses, by simulating an attack
Finds
Compromise assessment
Actual compromise, past or present
Vulnerability assessment
Missing patches and misconfigurations
Penetration test
Exploitable paths into the environment
Best time to run
Compromise assessment
Before a deal closes, after an incident, after a vendor breach, or when something looks off
Vulnerability assessment
On a regular schedule
Penetration test
Before launches, audits and renewals
What you get
Compromise assessment
A verdict with evidence, and containment if needed
Vulnerability assessment
A prioritized list of weaknesses
Penetration test
Proof of what an attacker could reach

A clean penetration test does not mean you are not compromised, and a long vulnerability list does not mean you are. They answer different questions. Read more in What is a compromise assessment? If the evidence points to email fraud, see our business email compromise investigation.

When to Run a Compromise Assessment

Security tools tell you what they caught. A compromise assessment tells you what they missed.

These are the moments when not knowing is the bigger risk.

Enterprise Hero Icon
BEFORE CLOSE

Before a Deal Closes

Challenges Highlight  Icon
You inherit whatever is already inside.
Enterprise Hero Icon

Financial and legal diligence will not find an attacker who is quietly reading email or moving data. A compromise found after close becomes the buyer's breach.

We check the target's environment before you sign, so the price and the reps reflect what you are actually buying.

Enterprise Hero Icon
AFTER AN INCIDENT

After an Incident Is Closed

Challenges Highlight  Icon
Was everything actually removed?
Enterprise Hero Icon

Attackers rarely leave just one way back in. A password reset does not remove a mailbox rule, an app consent or a second admin account.

We confirm the environment is clean before you call it closed.

Enterprise Hero Icon
VENDOR BREACH

A Vendor or MSP Was Breached:
Are You Next?

Challenges Highlight  Icon
Their access is your exposure.
Enterprise Hero Icon

When a software vendor, MSP or payroll provider discloses a breach, the question is whether the attacker used that access to reach you.

We trace the vendor's access paths into your environment and look for activity that should not be there.

Enterprise Hero Icon
INSURANCE

Insurance Renewal
or a Board Question

Challenges Highlight  Icon
"Are we breached?" deserves evidence.
Enterprise Hero Icon

Insurers, lenders and boards increasingly ask whether you have looked for an active compromise, not just whether you have tools. A dated, independent report answers the question and documents that you checked.

Enterprise Hero Icon
PEOPLE CHANGE

An Admin Leaves or
You Switch Providers

Challenges Highlight  Icon
Know what you are taking over.
Enterprise Hero Icon

When a privileged administrator departs or a new MSP takes over, nobody can say for certain what access was left behind. A compromise assessment gives the new owner a clean starting point.

Enterprise Hero Icon
SOMETHING LOOKS OFF

Odd Sign-Ins, Odd Emails, Odd Payments

Challenges Highlight  Icon
Small signs are how most compromises start.
Enterprise Hero Icon

A sign-in from an unfamiliar country, a vendor asking about a payment you never sent, or a mailbox rule nobody remembers creating. We find out whether it is noise or an attacker.

What a Compromise Assessment Checks

Most attackers today sign in rather than break in.
So we start with identity, email and cloud, then go to endpoints wherever the evidence leads.

Services Icon

Microsoft 365 & Entra ID

Where most compromises live today.

What we do

We review sign-in and audit logs, MFA methods, admin role changes, app consents and risky sessions across your tenant, looking for access that does not belong to your people.

why it matters

A stolen session or a rogue app consent survives a password reset. These are the footholds that ordinary security tools rarely flag.

typical outcomes
Service Feature Icon

Sign-In and Session Review

Service Feature Icon

MFA Method Changes

Service Feature Icon

App Consent Review

Service Feature Icon

Admin Role Changes

Services Icon

Email & Payment Fraud Indicators

Is anyone reading your finance mail?

what we do

We check every mailbox for forwarding and hiding rules, delegated access, unusual sent mail and the signs of business email compromise around invoices and payments.

why it matters

Email compromise is how most wire fraud starts. Finding it before the next payment run is the difference between a finding and a loss.

typical outcomes
Service Feature Icon

Inbox and Forwarding Rules

Service Feature Icon

Delegated Mailbox Access

Service Feature Icon

Payment Change Requests

Service Feature Icon

Lookalike Domains

Services Icon

Endpoint Forensics

What ran, what stayed, what spread.

What we do

On a sample of servers and high-privilege workstations, we look for persistence, suspicious execution, credential theft tools and signs of movement between systems.

why it matters

Ransomware operators often sit inside for weeks before they encrypt. Their preparation leaves traces that a forensic review can find.

typical outcomes
Service Feature Icon

Persistence Mechanisms

Service Feature Icon

Execution Artifacts

Service Feature Icon

Credential Theft Tools

Service Feature Icon

Lateral Movement Evidence

Services Icon

Identity & Active Directory

The keys attackers want most.

What we do

We look for new or changed privileged accounts, service accounts used in odd ways, Kerberos abuse and the trails left by attackers mapping their way to domain admin.

why it matters

Once an attacker controls identity, every other control can be switched off. Identity is where a limited intrusion becomes a full one.

typical outcomes
Service Feature Icon

Privileged Account Changes

Service Feature Icon

Service Account Abuse

Service Feature Icon

Kerberos and Delegation Abuse

Service Feature Icon

Hybrid Identity Sync

Services Icon

Cloud Platforms

Attacks that never touch a laptop.

What we do

We review Azure, AWS and Google Cloud audit logs for new access keys, role changes, unusual API activity, exposed storage and data leaving the environment.

Why It Matters

Cloud attacks run on stolen keys and tokens. They leave nothing on an endpoint, so only the platform's own logs can show them.

Key Features
Service Feature Icon

Access Key and Token Review

Service Feature Icon

Role and Policy Changes

Service Feature Icon

Storage Exposure

Service Feature Icon

Data Movement Signals

Services Icon

Verdict, Containment & Report

A clear answer, not a scan output.

What we do

You get a written verdict with the evidence behind it. If we find an active compromise, leadership hears about it within hours and containment starts.

why it matters

Boards, counsel, insurers and buyers need an answer they can rely on and a record that you looked. A list of alerts gives them neither.

Key Features
Service Feature Icon

Compromised or Clean Verdict

Service Feature Icon

Escalation Within Hours

Service Feature Icon

Containment Plan

Service Feature Icon

Evidence Preserved

Service Feature Icon

Executive Report

Why an Independent Compromise Assessment

The people who run your systems should not be the only ones checking whether they were breached.

Enterprise Hero Icon

Independent of Your IT and MSP

We do not run your systems, so we have no reason to find nothing. Your team and your provider get the findings and work with us on the fixes.

Independent

Verdict
Enterprise Hero Icon

Cloud and Identity First

Most attacks today run through Microsoft 365, Entra ID and cloud accounts, not malware on a laptop. We start where attackers actually are.

Cloud First

Identity Led
Enterprise Hero Icon

An Answer, Not a Scan

Scanners list weaknesses. We tell you whether someone has used one, show the evidence, and say what it means for the business.

Evidence

Not Alerts
Enterprise Hero Icon

A Path From Finding to Fix

If we find something, we contain it, preserve the evidence and close every way back in. Incident response and remediation are part of the same team, not a hand-off.

Contain

And Close

Cloud compromise assessment

Most attackers no longer need malware on a laptop. They phish a password, steal a session token or trick a user into approving an app, then work entirely through Microsoft 365, Entra ID and cloud accounts. Those attacks leave nothing on an endpoint for antivirus to find. A cloud compromise assessment looks where they actually leave traces.

Sign-ins and sessions. Impossible travel, hosting-provider addresses, token reuse and sessions that outlived a password reset.

MFA and identity changes. New authentication methods, new devices joined to the tenant and changes to admin roles.

App consents and service principals. Third-party apps with mail or file access that nobody approved on purpose.

Mailboxes. Forwarding and hiding rules, delegated access and mail sent in the user's name.

Cloud platforms. New access keys, role changes and unusual API activity in Azure, AWS and Google Cloud.

Data movement. Large downloads, sharing links to outside accounts and files leaving the tenant.

Only Microsoft 365 and Azure?

When the concern is limited to Microsoft 365 and Azure, CLOUDSKOPE SARTUS™ covers compromise assessment as a six-day, fixed-fee engagement that also fixes what it finds.

How It Works

Compromise Assessment:
From Scope to Verdict

Every compromise assessment starts with the reason you are asking: a deal, an incident, a vendor breach or a feeling that something is wrong.
That reason sets the scope, so you pay to look where the risk actually is.

Most of the work runs on read-only access, with no disruption to your business.

How the Work Runs

Scope, collect, hunt, decide, fix, report.

If we find an active compromise, you hear about it within hours, not in the final report.

01

Scope

We agree on the trigger, the systems in scope, the timeline and who gets told what, including counsel if privilege matters.

02

Collect

Read-only access to Microsoft 365, Entra ID and cloud logs, plus forensic collection from a sample of endpoints agreed with your team.

03

Hunt

We look for persistence, credential theft, mailbox abuse, privilege changes and data leaving the environment, then follow every lead to its source.

04

Decide

Compromised or clean, with the evidence behind the answer. Anything uncertain is called out as uncertain.

05

Contain and Fix

If we find an attacker, we contain the access, preserve evidence for counsel and insurers, and close every way back in.

If we do not, we fix the weaknesses that would let one in.

06

Report

A written report for leadership, the board, counsel, insurers or a buyer: the verdict, the evidence, what was done and what is left.

Dated and defensible.

The compromise assessment report

The report is written for the people who have to act on it: leadership, the board, counsel, insurers and, before a deal, the buyer. It covers:

The verdict. Compromised, clean or inconclusive, stated plainly at the top.

The evidence. What we found, where, and how confident we are in each finding.

The scope. Which systems we examined and which we did not, so nobody reads more into a clean result than it supports.

What was done. Containment steps taken, evidence preserved and access removed.

What is left. A prioritized list of fixes, with owners, so the same gap does not reopen.

How long it takes and what it costs

Every compromise assessment is custom scoped, so there is no price list. Cost depends on the size of the environment, which systems are in scope and how deep the investigation needs to go. Pre-close work is sized to the deal timeline. After a short scoping call you get a written scope, timeline and fee.

Environment size. Users, locations, servers and cloud accounts.

Systems in scope. Microsoft 365 and Entra ID only, or also endpoints, on-premises Active Directory and other clouds.

The trigger. A deal deadline, a live incident or a routine check each sets a different pace and depth.

FAQ

Compromise Assessment Questions

Straight answers on scope, cost, cloud and what happens if we find something.

1What is a compromise assessment?+

An investigation into whether an attacker is in your environment now, or has been. We examine sign-ins, mailboxes, identity, cloud activity and a sample of endpoints for evidence of real attacker activity, then give you a verdict with the evidence behind it.

2How is it different from a penetration test or vulnerability assessment?+

A penetration test asks whether an attacker could get in. A vulnerability assessment lists weaknesses. A compromise assessment asks whether someone already did. A clean pen test does not rule out an existing compromise.

3When should we run one?+

Before a deal closes, after an incident is declared closed, after a vendor or MSP breach, when a privileged admin leaves or you change providers, at insurance renewal, or when something looks off, such as odd sign-ins or payment questions from a vendor.

4What is a cloud compromise assessment?+

A compromise assessment focused on Microsoft 365, Entra ID and cloud platforms such as Azure, AWS and Google Cloud. Most attacks now run through stolen sessions, app consents and mailbox rules, which only cloud logs can show.

5Will it disrupt our business?+

Most of the work runs on read-only access to logs. Endpoint collection is agreed with your team in advance and runs in the background. If we find an active attacker, containment steps are coordinated with you before anything is switched off.

6What happens if you find something?+

Leadership hears about it within hours. We contain the access, preserve the evidence for counsel and insurers, and close every way back in. If a full investigation is needed, our incident response work picks up without a hand-off.

7How much does a compromise assessment cost?+

It is custom scoped, so there is no price list. Cost depends on the size of the environment, the systems in scope and how deep the investigation goes. You get a written scope and fee after a short call. For Microsoft 365 and Azure only, SARTUS™ is a fixed-fee option.

8Should a compromise assessment be part of M&A due diligence?+

For most acquisitions, yes. Financial and legal diligence will not find an attacker who is quietly inside, and a compromise found after close becomes the buyer's problem. It fits within our M&A cyber due diligence.

Find Out Before Someone Else Does

Book a short scoping call. Tell us what prompted the question, and we will tell you what to look at, how long it takes and what it costs.

If something looks urgent, say so on the call and we will prioritize it.