Article

Nobody noticed for six days

What school leaders should be asking about their email system, and why "we haven’t had a problem" is not an answer.

Most organisations believe they would know if someone else were reading their email. Very few would.

Here is how it actually goes.

The first sign is never a security alert

An administrator account is accessed by someone who should not have it. Nothing breaks. No alarm sounds. The intruder does not delete anything, does not change any settings, does not lock anyone out. They simply have access, and they use it quietly.

Days later a member of staff mentions that a supplier received something odd from the school. Or Microsoft starts blocking outbound mail because too much spam has left the domain. That is usually the moment of discovery: not a security system doing its job, but a symptom becoming impossible to ignore.

By then the question is no longer whether something happened. It is how long it has been happening, and what was seen.

Why passwords were never the point

The instinctive reaction is to reset passwords. It feels decisive, and it is genuinely necessary. But it is worth understanding what it does and does not achieve.

If accounts were created in bulk, using a predictable password pattern that was never changed, then resetting them addresses today’s problem and leaves tomorrow’s untouched. The weakness was never any individual password. It was the process that created hundreds of them the same way.

We see this constantly in schools. A new intake arrives. Accounts are provisioned in a batch, each with a formulaic password. Students are told to change it. Most never do, because nothing forces them to and nobody checks. Three years later a large proportion of the organisation is still using the password it was handed on day one, and anyone who works out the formula gets everyone at once.

The pattern is not laziness. It is what happens when account creation is treated as an administrative task rather than a security one.

Multifactor authentication that does not authenticate

Almost every organisation we assess will tell you it has multifactor authentication. Often the setting is there. Users have registered a phone number. The box is ticked.

Then you look at the actual sign-in records and find the second factor is almost never requested, because no policy requires it. Registration and enforcement are different things, and the gap between them is where most incidents live.

There is a second trap underneath it. Some older email protocols cannot perform multifactor authentication at all. If they remain switched on, an attacker with nothing but a password can use them to send mail from your domain, and your carefully configured MFA never enters into it. These protocols exist for printers and scanners. Most organisations no longer need them and do not realise they are still enabled.

The account nobody closed

Every organisation has them. Someone left months ago. Their mailbox is still active, still licensed, still holding years of correspondence, still reachable with whatever password they last set.

Nobody is watching it, because nobody uses it. That is exactly what makes it valuable to someone else.

If your organisation cannot produce a list of accounts belonging to people who no longer work there, that list exists anyway. You just have not read it.

What this costs, in the terms that matter

The spam is the least of it.

An intruder holding a senior mailbox can read everything in it. Financial arrangements, staff matters, safeguarding correspondence, parent complaints, legal advice. None of that requires them to change a single setting, and none of it leaves a trace an untrained eye would notice.

Worse, they can send as that person. A payment instruction that genuinely originates from the head’s mailbox, in the middle of an existing conversation, is not something a finance officer is likely to challenge. This is the most common way schools and small organisations lose money, and it requires no technical sophistication once the mailbox is open.

And there is the part that is hard to price. If parent or student information was accessible, that becomes a governance and possibly a regulatory matter, and the honest answer to was anything taken is frequently we cannot tell, because the logging needed to answer it was never turned on.

Five questions worth asking your IT provider

Not technical questions. Questions whose answers you can judge.

How would we know? If someone signed into an administrator account from another country tomorrow, what would happen, who would be told, and how quickly? If the answer involves someone happening to look, you have no detection.

How many active accounts belong to people who have left? A precise number should exist. If it does not, that is the finding.

When did our accounts last change their passwords? Ask for the distribution, not an average. If a large group all changed on the same day two years ago, that is a batch that was never revisited.

Is multifactor authentication enforced, or just available? These are different answers and the difference is everything.

What legacy protocols are still enabled? Anything that cannot support a second factor is a way around whatever you have configured.

Why this keeps happening

Almost every organisation in this position has competent people doing sensible things. What they do not have is anyone whose job is to watch continuously.

Security is not a project that completes. Accounts are created every term. People leave every year. Settings drift. A configuration that was correct in September is not automatically correct in March, and nobody finds out until something surfaces.

The organisations that come through this well are not the ones with the most expensive tooling. They are the ones where somebody is looking, regularly, and where finding a problem is a Tuesday rather than a crisis.

If nobody is doing that for your environment, then the honest position is not that you are secure. It is that nothing has surfaced yet.

Where to start

If you cannot answer those five questions, that is itself the finding. It does not mean something is wrong in your environment. It means you would not know if it were, and that is a different problem with a straightforward solution.

Unisolva provides managed Microsoft 365 tenant security on an annual agreement: somebody watching sign-in and administrative activity continuously, access controls enforced and kept enforced, accounts provisioned securely and leavers actually closed, privileged accounts reviewed on a schedule rather than when something goes wrong, and a defined response path.

If you would rather start smaller, we will run a one-off assessment of your tenant and give you written answers to the five questions above. Most of what we find surprises people. Almost none of it is expensive to fix.

Find out what your tenant would actually tell us

A one-off Microsoft 365 assessment, or a managed agreement with somebody watching continuously.