Incident Response KitFree severity check

Compromised account or cloud admin access: incident response playbook

Use it when: Sign-ins from impossible locations, new admin accounts, disabled security settings or unexpected cloud resources.

First 15 minutes

  1. Disable the account or remove its admin rights.
  2. Revoke sessions, tokens and API keys it owns.
  3. Check for other accounts created or changed in the same period.
  4. Escalate to SEV2 or SEV1 if it had admin rights.

Set the severity and download a first-response checklist

What the full playbook covers

The full playbook is in the Incident Response & Business Continuity Kit with 8 more, the IR plan, a BCP/DR plan and 6 tabletop exercises.

Other playbooks

Incident Response & Business Continuity Kit

More free security and AI governance tools