What is ITDR? Identity attacks explained for Perth SMEs

What is ITDR? Identity attacks explained for Perth SMEs

Stolen passwords and fake MFA prompts beat many firewalls. A practical guide to Identity Threat Detection and Response for Perth business owners, with links to our stack page and uplift program.

Back to Blog

The invoice that was almost paid twice

A WA trade business almost paid a supplier invoice to a new bank account. The email thread looked right. The tone matched. The only odd detail was urgency. The real supplier rang two days later asking where the payment was. Someone had been inside the mailbox, silent, waiting for a payment window.

No ransomware. No smashed servers. Just identity abuse. That is the class of problem Identity Threat Detection and Response (ITDR) is built for. For a structured overview of how we treat ITDR as required stack, see /security-standard/security-stack/itdr/. This piece is the owner’s story: how these attacks feel, what “good” looks like, and how it ties to Continual Security Uplift (see /one-plan/).

The scare in that story is how ordinary it felt. Nobody “got hacked” in a movie sense. Someone signed in as a trusted person and waited. Detection has to notice that calm phase, not only the dramatic ending.

Identity is the door most attackers prefer

Firewalls still matter. So do patching and backups. But cloud email and cloud files mean a valid login is often enough. Attackers buy credentials, phish staff, steal session cookies, or wear people down with repeated MFA prompts until someone taps Approve.

Once inside, they set forwarding rules, register their own MFA methods, create inbox rules that hide security alerts, and hunt for finance conversations. They may never touch a laptop agent if they can work entirely in the browser as you.

That is why “we turned MFA on in 2021” is not a full identity strategy. MFA is a seatbelt. ITDR is noticing when the car is being driven from the wrong city at the wrong hour.

Perth firms feel this because so much of the business now lives in Microsoft 365. Quotes, contracts, payroll exports, client advice. Steal the mailbox and you steal the operating rhythm of the company.

How these attacks show up before the money moves

Early signs are easy to miss. A password reset the user does not remember. An MFA prompt at a strange hour. A new inbox rule named something boring. A sign-in from a place the staff member has never visited. A sudden flood of “are you travelling?” messages from Microsoft that get ignored.

Finance teams sometimes notice odd supplier behaviour first: changed bank details, pressure to pay early, slight tone shifts in email. By then the attacker may already have days of reading time.

ITDR is meant to catch the technical signals earlier so you are not relying on a sharp-eyed accounts person every time. People still matter. Detection buys them time.

Train staff to report weird prompts. Pair that with monitoring so you are not depending on courage alone at 11pm after a long day on site.

ITDR versus posture work (and why you want both)

ITDR is detection and response for active identity threats: impossible travel, atypical sign-ins, privilege escalation, suspicious consent grants, and takeover patterns.

Identity Security Posture Management (ISPM) is the continuous tidy: MFA gaps, stale guests, over-privileged roles, legacy auth still allowed. Posture reduces how easy you are to own. ITDR reduces how long an attacker gets to stay.

Skipping either creates a blind spot. Perfect posture with no detection still fails when a user is tricked. Perfect detection with rotten posture means you fight the same fire every month.

In practice, a good quarter shrinks both problems: fewer risky standing privileges, and faster handling when something still slips through.

What Perth owners should hear in a quarterly review

You should hear how many risky sign-ins were investigated, which were real users travelling, and which were blocked takeovers. You should hear whether mailbox forwarding anomalies were found. You should hear what Conditional Access changes followed.

You should not hear only “Microsoft Secure Score is fine” with no identity narrative. Score helps. Stories of handled events build trust with boards and insurers.

Ask for response times. Ask who can revoke sessions at night. Ask how often guest accounts are reviewed. Write the answers down. Compare them next quarter.

Ask whether shared admin accounts still exist “for convenience”. Ask how break-glass accounts are stored and monitored. Soft answers here often match soft controls.

Business Premium helps, then you still have to operate

Microsoft 365 Business Premium gives you the identity platform and Defender-related risk signals when configured. Conditional Access, authentication strengths, and audit logs are there to be finished.

Plenty of Perth tenants have unfinished policies and broad exclusions “so nobody gets locked out”. Attackers love those exclusions. ITDR does not excuse lazy configuration. It catches what slips through while you tighten the estate under uplift discipline.

Pair identity monitoring with endpoint EDR so a stolen session that drops a payload still hits a second line (see /security-standard/security-stack/edr/). Use SIEM thinking so identity and mailbox signals are not separate silos (see /security-standard/security-stack/siem/).

Common sense stays in force. Separate admin accounts for admin work. No permanent global admin for reading email. Phishing drills so staff pause before approving mystery prompts. Licences enable the work. Habits finish it.

A short playbook when you suspect mailbox takeover

Force sign-out and reset credentials for the account. Revoke sessions and app passwords. Check inbox rules and forwarding. Review recent sent items and deleted items. Warn finance to verify bank changes by phone using known numbers.

Then ask your provider what detection should have fired earlier. If the answer is silence, you found a process gap, not only an incident.

Document what happened for insurers and for your next uplift review. Near misses that never change Conditional Access will return wearing a different subject line.

Make ITDR part of uplift, not a scare purchase

After a near-miss, firms sometimes buy a tool and never staff the alerts. Six months later the licence renews and nobody remembers the portal password. That pattern is how trust dies.

Continual Security Uplift keeps identity work on a cadence: baseline, harden, review, repeat (see /one-plan/). ITDR is required in our Standard because we will not pretend MFA checkboxes are enough.

If you are comparing providers, take our ITDR page into the meeting: /security-standard/security-stack/itdr/. Ask them to match the operating claims, not the acronyms. If they cannot, keep looking. Your mailbox is too valuable to leave on hope.

Identity attacks favour patience. Your defence should favour notice and speed. Put ITDR on the floor with EDR and SIEM, run it inside Continual Security Uplift, and give directors a story they can repeat without wincing.

Want the required-stack definition we run with clients? Read /security-standard/security-stack/itdr/ and the Our One Plan.