top of page

Your Business May Be Under Attack. Is Your IT Company Watching for These 5 Signs?

  • 11 minutes ago
  • 4 min read
Two office employees looking concerned at a laptop displaying a red security warning icon, overlaid with the title '5 Signs Your Business Is Under Attack: Is your IT company watching?' and a five-step numbered indicator.


Most small business owners assume their IT company will tell them if someone's trying to break into an employee's account. That sounds reasonable: your provider manages Microsoft 365, resets passwords, helps when email breaks. Surely someone's also watching for suspicious logins and phishing attempts. But is anyone actually doing that?


Having security tools isn't the same as having someone monitoring them. Microsoft 365 can generate an alert. A filter can quarantine a message. MFA can block a login. None of those tools can call your employee, investigate what happened, or confirm the threat is gone. That takes a person who knows what to look for and takes responsibility for following up.

In the last few weeks alone, we at Pronto Tech investigated 10 risky sign-in alerts, 9 suspected phishing messages, 8 other login-related incidents, and one attempted payment fraud, for our managed clients alone.


Those cases point to five warning signs every business owner should recognize. As you read them, ask yourself one question: is my current IT company doing this for us?


1. A Sign-In From Somewhere Your Employee Has Never Been


Say an employee normally works out of Northern Virginia, and in the middle of the night, their account signs in from another country. That's not automatic proof of a hack (travel, mobile networks, and VPNs can all skew location data), but it's enough to warrant a look.

When we get a risky sign-in alert, we don't just forward it and call it done. We review the login, compare it to the employee's normal pattern, and reach out to confirm when needed. You can do a basic version yourself: open recent sign-in activity in Microsoft 365 and check for unfamiliar locations, devices, or times. One odd detail might be nothing. Several together deserve attention.


Ask yourself: Would I even know if one of our accounts signed in from somewhere it's never been?


2. A Phishing Message Good Enough to Fool a Busy Employee


The dangerous phishing messages don't look sloppy. They look familiar. One quarantined for a client last month had the subject line "Fw: Your account will be permanently deleted in 24 hours," built purely to create panic before anyone stopped to think.

When a client reports one, we don't just check the sender's display name. We check the real address, links, headers, and whether it reached anyone else in the company. You can do some of this yourself: hover over links before clicking, compare the sender's actual address to the name shown, and be wary of anything pushing you to bypass your normal process.


Ask yourself: Would someone on my team actually catch this, or click before thinking twice?


3. An MFA Prompt Nobody Triggered


An authentication prompt that appears when nobody's logging in usually means someone already has the correct password and is hoping your employee approves the request out of habit. Denying it is step one, not the whole response.

When a client reports this, we check the login activity behind it, and if it looks malicious, reset the password, revoke active sessions, and review the account for anything the user didn't do themselves.

Ask yourself: Would my team treat a prompt like this as a real warning, or just tap "deny" and move on with their day?


4. A Customer Gets an Email Your Employee Never Sent

Sometimes the first warning doesn't come from a dashboard. It comes from a customer. A compromised employee account can start sending phishing messages directly to a business's own customers, and because the message comes from a real account inside a real relationship, it looks completely trustworthy. Often, the business doesn't find out from a security alert at all. They find out because a confused customer calls asking about a strange email.


When we respond to a compromised account, the priority is containment: block access, revoke sessions, reset credentials, and check the mailbox for hidden forwarding rules or other changes an attacker might have left behind. Just as important, we help identify who actually received the fraudulent messages and get them a heads up, so a customer isn't left wondering whether a strange email was real.


Ask yourself: If this happened to us right now, would I actually know what to do first?


5. An Urgent Payment Request With New Instructions


This one doesn't need malware. Just the right employee at the wrong moment. Last month, an employee at one of our clients got an email that appeared to come from her CEO, requesting an urgent ACH payment on a plausible vendor invoice with new bank details attached. Something felt off, so she flagged it instead of sending it. We checked the message and confirmed it was spoofed. No money moved.

The real defense is a process one email can't override: any request involving new bank details or changed payment instructions gets confirmed by phone, using a number you already had on file, never one supplied in the message.


Ask yourself: Do my employees actually know what to do if a request like this landed in their inbox?


Security Software Is Only Part of the Job


Your business likely already has security features built into Microsoft 365 and your email system. The harder question is whether anyone's actively using them on your behalf. Who reviews the alerts? Who calls the employee? Who checks for a hidden forwarding rule? Who makes sure a blocked login attempt didn't turn into something bigger?


At Pronto Tech, that's part of what we do for every managed client: monitor, investigate, explain what happened in plain English, and act when something needs containing, so you're not left studying a security dashboard trying to decide how serious it is.


Your current IT company may already be doing all of this. It's worth finding out.


If you don't get a clear answer, contact us for a quick consultation. We'll show you exactly what we'd be watching for at your office, and where the gaps might already be.

 
 
bottom of page