Compromised account or cloud admin access: incident response playbook
Use it when: Sign-ins from impossible locations, new admin accounts, disabled security settings or unexpected cloud resources.
First 15 minutes
- Disable the account or remove its admin rights.
- Revoke sessions, tokens and API keys it owns.
- Check for other accounts created or changed in the same period.
- Escalate to SEV2 or SEV1 if it had admin rights.
Set the severity and download a first-response checklist
What the full playbook covers
- Contain (2 steps)
- Eradicate (1)
- Recover (1)
- Who to notify
- Evidence to keep
The full playbook is in the Incident Response & Business Continuity Kit with 8 more, the IR plan, a BCP/DR plan and 6 tabletop exercises.