Compromise Assessment:
Is an Attacker Already Inside?
A compromise assessment answers one question: is someone in your environment right now? We look for evidence of real attacker activity across Microsoft 365, Entra ID, cloud, email and endpoints.
Custom scoped, independent of your IT team and MSP, and finished with a written answer your board, counsel and insurer can rely on.
Breaches take an average of 247 days to identify and contain.
A compromise assessment looks now, on your schedule, before a regulator, a customer, a bank or a ransom note tells you.
What is a compromise assessment?
A compromise assessment is an investigation into whether an attacker is in your environment right now, or has been. It does not test whether you could be breached. It looks for evidence that you already were: stolen sessions, rogue mailbox rules, new admin accounts, persistence on servers and data leaving the network.
The output is a verdict, compromised or clean, with the evidence behind it. If the answer is compromised, the work moves straight into containment and incident response. If the answer is clean, you have a dated, independent record that you looked.
Compromise assessment vs vulnerability assessment vs penetration test
A clean penetration test does not mean you are not compromised, and a long vulnerability list does not mean you are. They answer different questions. Read more in What is a compromise assessment? If the evidence points to email fraud, see our business email compromise investigation.
When to Run a Compromise Assessment
Security tools tell you what they caught. A compromise assessment tells you what they missed.
These are the moments when not knowing is the bigger risk.
What a Compromise Assessment Checks
Most attackers today sign in rather than break in.
So we start with identity, email and cloud, then go to endpoints wherever the evidence leads.
Why an Independent Compromise Assessment
The people who run your systems should not be the only ones checking whether they were breached.
Independent of Your IT and MSP
We do not run your systems, so we have no reason to find nothing. Your team and your provider get the findings and work with us on the fixes.
Cloud and Identity First
Most attacks today run through Microsoft 365, Entra ID and cloud accounts, not malware on a laptop. We start where attackers actually are.
An Answer, Not a Scan
Scanners list weaknesses. We tell you whether someone has used one, show the evidence, and say what it means for the business.
A Path From Finding to Fix
If we find something, we contain it, preserve the evidence and close every way back in. Incident response and remediation are part of the same team, not a hand-off.
Cloud compromise assessment
Most attackers no longer need malware on a laptop. They phish a password, steal a session token or trick a user into approving an app, then work entirely through Microsoft 365, Entra ID and cloud accounts. Those attacks leave nothing on an endpoint for antivirus to find. A cloud compromise assessment looks where they actually leave traces.
Sign-ins and sessions. Impossible travel, hosting-provider addresses, token reuse and sessions that outlived a password reset.
MFA and identity changes. New authentication methods, new devices joined to the tenant and changes to admin roles.
App consents and service principals. Third-party apps with mail or file access that nobody approved on purpose.
Mailboxes. Forwarding and hiding rules, delegated access and mail sent in the user's name.
Cloud platforms. New access keys, role changes and unusual API activity in Azure, AWS and Google Cloud.
Data movement. Large downloads, sharing links to outside accounts and files leaving the tenant.
Only Microsoft 365 and Azure?
When the concern is limited to Microsoft 365 and Azure, CLOUDSKOPE SARTUS™ covers compromise assessment as a six-day, fixed-fee engagement that also fixes what it finds.
Compromise Assessment:
From Scope to Verdict
Every compromise assessment starts with the reason you are asking: a deal, an incident, a vendor breach or a feeling that something is wrong.
That reason sets the scope, so you pay to look where the risk actually is.
Most of the work runs on read-only access, with no disruption to your business.
How the Work Runs
Scope, collect, hunt, decide, fix, report.
If we find an active compromise, you hear about it within hours, not in the final report.
Scope
We agree on the trigger, the systems in scope, the timeline and who gets told what, including counsel if privilege matters.
Collect
Read-only access to Microsoft 365, Entra ID and cloud logs, plus forensic collection from a sample of endpoints agreed with your team.
Hunt
We look for persistence, credential theft, mailbox abuse, privilege changes and data leaving the environment, then follow every lead to its source.
Decide
Compromised or clean, with the evidence behind the answer. Anything uncertain is called out as uncertain.
Contain and Fix
If we find an attacker, we contain the access, preserve evidence for counsel and insurers, and close every way back in.
If we do not, we fix the weaknesses that would let one in.
Report
A written report for leadership, the board, counsel, insurers or a buyer: the verdict, the evidence, what was done and what is left.
Dated and defensible.
The compromise assessment report
The report is written for the people who have to act on it: leadership, the board, counsel, insurers and, before a deal, the buyer. It covers:
The verdict. Compromised, clean or inconclusive, stated plainly at the top.
The evidence. What we found, where, and how confident we are in each finding.
The scope. Which systems we examined and which we did not, so nobody reads more into a clean result than it supports.
What was done. Containment steps taken, evidence preserved and access removed.
What is left. A prioritized list of fixes, with owners, so the same gap does not reopen.
How long it takes and what it costs
Every compromise assessment is custom scoped, so there is no price list. Cost depends on the size of the environment, which systems are in scope and how deep the investigation needs to go. Pre-close work is sized to the deal timeline. After a short scoping call you get a written scope, timeline and fee.
Environment size. Users, locations, servers and cloud accounts.
Systems in scope. Microsoft 365 and Entra ID only, or also endpoints, on-premises Active Directory and other clouds.
The trigger. A deal deadline, a live incident or a routine check each sets a different pace and depth.
Compromise Assessment Questions
Straight answers on scope, cost, cloud and what happens if we find something.
1What is a compromise assessment?
An investigation into whether an attacker is in your environment now, or has been. We examine sign-ins, mailboxes, identity, cloud activity and a sample of endpoints for evidence of real attacker activity, then give you a verdict with the evidence behind it.
2How is it different from a penetration test or vulnerability assessment?
A penetration test asks whether an attacker could get in. A vulnerability assessment lists weaknesses. A compromise assessment asks whether someone already did. A clean pen test does not rule out an existing compromise.
3When should we run one?
Before a deal closes, after an incident is declared closed, after a vendor or MSP breach, when a privileged admin leaves or you change providers, at insurance renewal, or when something looks off, such as odd sign-ins or payment questions from a vendor.
4What is a cloud compromise assessment?
A compromise assessment focused on Microsoft 365, Entra ID and cloud platforms such as Azure, AWS and Google Cloud. Most attacks now run through stolen sessions, app consents and mailbox rules, which only cloud logs can show.
5Will it disrupt our business?
Most of the work runs on read-only access to logs. Endpoint collection is agreed with your team in advance and runs in the background. If we find an active attacker, containment steps are coordinated with you before anything is switched off.
6What happens if you find something?
Leadership hears about it within hours. We contain the access, preserve the evidence for counsel and insurers, and close every way back in. If a full investigation is needed, our incident response work picks up without a hand-off.
7How much does a compromise assessment cost?
It is custom scoped, so there is no price list. Cost depends on the size of the environment, the systems in scope and how deep the investigation goes. You get a written scope and fee after a short call. For Microsoft 365 and Azure only, SARTUS™ is a fixed-fee option.
8Should a compromise assessment be part of M&A due diligence?
For most acquisitions, yes. Financial and legal diligence will not find an attacker who is quietly inside, and a compromise found after close becomes the buyer's problem. It fits within our M&A cyber due diligence.
Find Out Before Someone Else Does
Book a short scoping call. Tell us what prompted the question, and we will tell you what to look at, how long it takes and what it costs.
If something looks urgent, say so on the call and we will prioritize it.
.png)