← Email & Phishing

runbook

Prepare the First Actions for a Suspected Mailbox Compromise

Prepare roles, safe communication, evidence ownership, decision authority, continuity, and qualified handoff before mailbox compromise is suspected.

For

An owner or operations lead preparing a role-and-decision card before a suspected mailbox compromise creates stress and unsafe improvisation.

Not for

Live investigation, containment, password reset, session revocation, forwarding-rule removal, forensic collection, recovery, notification decisions, or provider-specific incident instructions.

Failure addressed

People investigate through a suspect channel, destroy evidence, take uncoordinated account actions, delay escalation, or lack surviving authority and communications.

A suspected mailbox compromise is a bad moment to discover that the only contact route is the mailbox itself, no backup administrator is available, or nobody knows who may authorize the next decision. Preparation can expose those gaps before urgency turns them into unsafe improvisation.

Here, “first actions” means the first prepared decisions and handoffs to consult—not instructions for acting on a live mailbox. This guide does not diagnose compromise, inspect evidence, contain an account, recover access, notify anyone, or provide emergency support.

Keep ten preparation concepts separate

The trigger category records why qualified handoff may be needed without declaring an incident. Internal accountability identifies who owns activation of the prepared handoff. Coordination keeps decisions and dependencies coherent. Mailbox or provider administration identifies a future execution role without granting authority. Evidence ownership identifies who controls authorized evidence handling without collecting it. A safe communication category avoids silent reliance on the suspected mailbox without proving the alternative is uncompromised. Business and financial continuity identify affected operating responsibilities without establishing incident scope. Decision authority records who may later approve bounded actions. Qualified escalation identifies where specialist decisions belong. Residual risk, exercise, and review keep gaps visible.

Do not collapse these concepts into one incident ready, contained, safe channel, evidence preserved, or response complete checkbox. Naming a role does not create competence, availability, independence, access, authority, or a surviving communication path.

What the sources establish—and what they do not

NIST SP 800-61 Rev. 3 supports incorporating incident-response preparation throughout cybersecurity risk management to improve preparation and the effectiveness of detection, response, and recovery. NCSC supports layered organizational defenses, a supportive reporting culture, second-channel verification for important requests, and planning before incidents occur.

Those sources do not prescribe the ten concepts, eight stages, mailbox-specific roles, safe-communication categories, 18 fields, authority model, tabletop method, completion rule, or review cadence below. Those are PlainFort editorial choices. They are not an incident-response standard, forensic method, containment sequence, certification, readiness proof, or protection guarantee.

Follow an eight-stage preparation workflow

1. Define the suspicion threshold and stop boundary

Record generic trigger categories that move work from ordinary EP-13 reporting to qualified handoff: suspected unauthorized mailbox use, unexplained account behavior reported through an approved route, unexpected message activity reported by others, possible disclosure, or a linked business or financial concern.

A trigger is not an incident verdict. Do not sign in, inspect messages, test the account, or ask the reporter to prove compromise. Use Trigger category recorded — incident not determined and stop at handoff.

2. Assign internal accountability, coordination, and backups

Name the internally accountable owner, coordination role, mailbox or provider administrator category, real backups, and escalation authority. Record capacity, availability, conflict, access, competence, and authority gaps.

One person may hold several roles in a small team, but the combination must not hide missing independent review or backup. A contractor or provider may later advise or execute under separate authorization; it does not silently become the internal accountable owner or business-impact authority.

3. Prepare safe communication and authority categories

Identify a communication category outside the suspected mailbox context and name its owner and backup. Record who may later authorize account, containment, continuity, stakeholder, legal or privacy, and recovery decisions.

Different does not automatically mean secure, trusted, or uncompromised. If ownership, availability, or independence is uncertain, use Safe communication category pending and escalate.

4. Assign evidence ownership without collecting evidence

Name who may control authorized evidence references, access decisions, protection, retention decisions, and qualified handoff. Record only a non-sensitive evidence-location category.

Evidence owner assigned — no evidence collected is the honest preparation state. Do not prescribe what to collect, how to preserve it, whether it is sufficient, or how to establish chain of custody.

5. Map business, financial, and communication continuity

Record the category of business operations that may depend on the mailbox, the continuity owner, the financial-impact owner, and alternative communication ownership. Keep EP-14 available when a payment-change concern exists, without reproducing or executing its verification gate.

Preparation cannot establish what is affected. Use Continuity dependency unresolved when connected applications, recovery paths, devices, business processes, or financial workflows may depend on facts that have not been examined.

6. Prepare qualified escalation and sibling handoffs

Document how ordinary EP-13 reporting hands off to EP-15, how financial concerns route to EP-14, how device loss or theft routes to DN-18, and how broader incident roles and communications route to BR-24.

Name categories for qualified incident-response, provider, forensic, legal, privacy, records, HR, insurance, banking, communications, and law-enforcement help only where relevant. Do not contact or activate any destination through this guide.

7. Exercise the card without touching a live account

Run a tabletop read-through using roles and category labels only. Check whether owners and backups are available, authority boundaries are understood, communication categories have owners, evidence responsibility is clear, continuity gaps are visible, and escalation routes are known.

Do not use a real account, mailbox, provider, tenant, device, message, contact, payment, log, rule, session, credential, or evidence item. Do not simulate provider clicks, password reset, session revocation, evidence collection, notification, financial action, or recovery.

8. Close preparation with residual risk and review

Close only the document. Preserve missing authority, unavailable backups, communication uncertainty, evidence gaps, continuity risks, exceptions, and qualified handoffs.

Preparation card complete — containment not established means the fields are ready for independent review. It does not mean an incident can be handled safely, evidence is preserved, an account is contained, or recovery will succeed.

Use preparation states, not incident conclusions

  • Prepared — no live action authorized
  • Trigger category recorded — incident not determined
  • Role assigned — capacity and authority unverified
  • Backup unavailable — escalate
  • Safe communication category pending
  • Evidence owner assigned — no evidence collected
  • Decision authority pending
  • Qualified handoff required
  • Continuity dependency unresolved
  • Legal, privacy, records, insurance, or notification decision required
  • Blocked — qualified response required
  • Deferred — owner and review trigger required
  • Preparation card complete — containment not established

These states describe preparation and handoff position. They do not determine compromise, severity, scope, attribution, evidence sufficiency, containment, recovery, notification duty, or whether any account, device, person, system, or communication route is safe.

Stop before preparation implies readiness

Stop and route to qualified help if the suspected mailbox would be the only communication route; no surviving administrator, accountable owner, coordinator, backup, evidence owner, continuity owner, or decision authority exists; a privileged, executive, financial, recovery, shared, or high-impact mailbox could be involved; payment loss, credential use, widespread messages, sensitive-data exposure, connected applications, forwarding, sessions, recovery paths, or device compromise may exist; legal, privacy, notification, employment, contractual, insurance, records, banking, or law-enforcement duties are unclear; continuity depends on the mailbox; the primary trigger may be device loss or a broader incident; or any live inspection, containment, collection, recovery, notification, contact, or provider action is needed.

These are handoff triggers only. Do not use this guide to inspect a mailbox, message, header, rule, session, log, connected application, device, provider, or account; reset credentials; revoke access; remove forwarding; change MFA or recovery; preserve or export data; contact affected parties; notify authorities; or restore service.

Keep sibling and future guides separate

  • EP-11 owns the cross-layer email-security baseline. EP-15 consumes its ownership, evidence, residual-risk, escalation, and review vocabulary without recreating it.
  • EP-13 owns ordinary suspicious-message reporting, acknowledgement, triage, feedback, and closure. EP-15 begins only when suspected mailbox compromise requires qualified handoff; it does not copy or analyze the reported message.
  • EP-14 owns independent payment-change verification and authorization. EP-15 identifies financial-process impact only; it does not verify a payment, contact a bank, recover funds, or authorize money movement.
  • EP-12 owns domain-authentication and delivery planning. Domain-authentication evidence does not establish mailbox integrity or incident scope.
  • DN-18 owns the future device-loss or theft containment sequence. A lost device is not silently converted into this mailbox workflow.
  • BR-24 owns the future organization-wide incident role, communications, and coordination model. EP-15 prepares only the mailbox-specific trigger card.

EP-15 does not investigate, contain, recover, notify, perform forensics, determine legal obligations, or provide emergency support. It stops at qualified handoff.

Build the 18-field pre-incident card

  1. Bounded trigger category and incident-not-determined statement: The generic reason for handoff, without a verdict.
  2. Affected-mailbox category: A role category, never an address or identifier.
  3. Approved reporter route and EP-13 handoff state: The reporting boundary and its current state.
  4. Internal accountable owner: The internal role accountable for activating the handoff.
  5. Incident-coordination role and real backup: Coordination ownership, availability, and actual backup.
  6. Mailbox or provider administrator category and authority state: Execution capability kept separate from permission.
  7. Evidence owner, protection category, and qualified handoff destination: Ownership without evidence content or collection instruction.
  8. Safe communication category, owner, availability, and residual risk: An alternative category without a security claim.
  9. Business-process and continuity owner: The affected capability category and owner.
  10. Financial-impact owner and EP-14 handoff state: Financial boundary without payment action.
  11. Authority categories for later account, containment, communication, and recovery decisions: Decision rights, not live authorization.
  12. Non-sensitive initial evidence-location reference and reported or inspected distinction: An inert location category and evidence calibration.
  13. Action category requiring qualified support: The question that stops the card, without live instruction.
  14. External escalation category and activation authority: The approved destination category and who may activate it.
  15. DN-18 device-loss or theft handoff state: Future guide boundary and unresolved dependency.
  16. BR-24 organization-wide incident, legal, privacy, records, and communications handoff state: Broader response boundary.
  17. Unresolved risk, blocked dependency, and exception state: Every visible gap, owner, limit, and review condition.
  18. Tabletop completion evidence, next exercise, and review trigger: Evidence that the card was read through—not that response works.

This ordered record is not a live incident checklist, investigation worksheet, forensic record, evidence-collection guide, account-action runbook, notification matrix, severity score, or readiness certification. Completion does not authorize action or prove containment.

Work through a fictional example

Fictional example — do not copy as a completed email-security record. This example contains no real or plausible incident, person, mailbox, account, message, provider, device, evidence, contact, credential, financial, employment, legal, privacy, or notification data.

  1. Bounded trigger category and incident-not-determined statement: Unexpected mailbox activity reported; compromise not determined.
  2. Affected-mailbox category: Privileged-mailbox category.
  3. Approved reporter route and EP-13 handoff state: Approved reporting route; Qualified handoff required.
  4. Internal accountable owner: Operations owner role.
  5. Incident-coordination role and real backup: Coordinator assigned; Backup unavailable — escalate.
  6. Mailbox or provider administrator category and authority state: Administrator category known; Decision authority pending.
  7. Evidence owner, protection category, and qualified handoff destination: Evidence owner assigned; no evidence collected; qualified response category recorded.
  8. Safe communication category, owner, availability, and residual risk: Alternative category proposed; availability unverified.
  9. Business-process and continuity owner: Customer-communication capability; continuity owner assigned; dependency unresolved.
  10. Financial-impact owner and EP-14 handoff state: Finance-process owner recorded; EP-14 handoff pending if a payment concern appears.
  11. Authority categories for later account, containment, communication, and recovery decisions: Categories listed; authority evidence not inspected.
  12. Non-sensitive initial evidence-location reference and reported or inspected distinction: Approved evidence location referenced; facts reported, not inspected.
  13. Action category requiring qualified support: Mailbox-state assessment; no live instruction recorded.
  14. External escalation category and activation authority: Qualified incident-response category; activation owner identified.
  15. DN-18 device-loss or theft handoff state: Device trigger unknown; future boundary recorded.
  16. BR-24 organization-wide incident, legal, privacy, records, and communications handoff state: Broader-scope and decision handoffs pending.
  17. Unresolved risk, blocked dependency, and exception state: Backup and safe communication unavailable; Blocked — qualified response required.
  18. Tabletop completion evidence, next exercise, and review trigger: Read-through incomplete; repeat after backup or authority change.

Review the card without claiming readiness

Review when owners, backups, administrators, communication categories, evidence responsibility, business or financial dependencies, decision authority, providers, incident-support arrangements, legal/privacy/records duties, or official guidance changes. Reopen it when a tabletop exposes a gap or a future sibling guide changes the handoff.

The card is ready for local editorial review when all 18 fields are truthful, every gap remains visible, the two documentary claims stay separate from PlainFort’s model, and every live question stops at an authorized qualified destination. Publication and any live incident use remain separate decisions.