Join our Newsletter — 33% off our NHI Course

Who should own detection and response when compromised internal accounts are used for east-west phishing?

Email security and identity teams should share ownership, because the failure spans both account compromise and malicious internal message delivery. Security operations needs visibility into suspicious sign-ins and message bursts, while identity teams should reset credentials, revoke sessions, and harden account protection. Governance should treat internal phishing as both an identity and email security problem.

Why compromised internal accounts turn east-west phishing into a shared ownership problem

Once an internal account is compromised, the incident stops being only an email issue or only an identity issue. The attacker now has a trusted sender, access to internal relationships, and a path for lateral social engineering. That means detection has to watch both authentication signals and message behavior, while response has to cut off the account’s ability to continue abusing trust.

In practice, the handoff boundary should follow the failure path, not team silos. Email security owns message-level detection and containment, while identity owns account recovery, session revocation, and credential hardening. The operational question is not which team “owns” the incident in the abstract, but which team can interrupt the compromise fastest at each stage.

Compromised internal accounts are especially dangerous because recipients are more likely to trust them, reply quickly, and forward content. That makes east-west phishing both a delivery problem and an access problem: the same account that sent the message may also expose mailbox, SSO, or downstream application access. A clean response model therefore needs coordinated triage across sign-in telemetry, mailbox telemetry, and privilege scope.

What each team must actually detect and contain

Security operations should look for unusual sign-in locations, impossible travel, token abuse, and sudden spikes in outbound or internal messages. Those signals often arrive before user reports do, and they tell you whether the compromise is still active. Identity teams should immediately reset the affected account, revoke active sessions, rotate credentials where needed, and confirm whether multifactor protections or recovery paths were weakened.

That division matters because neither side sees the whole blast radius alone. Email controls can quarantine or trace malicious messages, but they do not fully restore trust in the account. Identity controls can recover the account, but they do not necessarily identify which internal recipients were targeted or whether the messages are still propagating.

For practitioners, the useful model is shared ownership with clear task ownership: one team stops the sending channel, the other removes the attacker’s durable access. If the account has already been used for follow-on abuse, the incident should also be treated as a trust-reset event, not just a password reset.

How governance should frame east-west phishing

Governance should classify this as an identity-led messaging incident with email impact, not as a routine mailbox cleanup. That framing matters because it determines escalation paths, evidence retention, and whether the incident is measured as credential compromise, internal fraud exposure, or user trust abuse. The risk is not just message delivery, it is the abuse of an authenticated relationship.

When the same compromise pattern repeats, it usually means one of three things: detection is too slow, recovery is too shallow, or the account protection baseline is too weak. Mature governance should therefore ask whether suspicious sign-ins are being correlated with internal message bursts, whether session invalidation is mandatory, and whether privileged or high-reach users get stronger controls than ordinary users.

Risk and Threat Considerations

Compromised internal accounts create a high-trust attack path because recipients are more likely to open, reply to, or act on messages from a known sender. The main risk is not just credential theft, but the use of that access to spread phishing laterally, reset business conversations, or reach additional systems through the victim’s trust relationships.

Failure mechanism: An attacker maintains access long enough to send convincing internal messages before the account is quarantined or the session is revoked, allowing trust-based propagation across the organisation.

Impact: The compromise can expand from a single account to multiple victims, generate further credential theft or fraud, and delay containment because the traffic appears to come from a legitimate internal source.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 DE.CM-01 — Networks and network services are monitored to detect potential cybersecurity events Internal message bursts and suspicious sign-ins need continuous monitoring to spot compromise quickly.
RS.MI-01 — Incidents are contained Compromised accounts must be contained by cutting off the sending channel and active sessions.
Recommendation — Correlate authentication anomalies with message-volume spikes to detect east-west phishing early. Contain the account by revoking sessions and blocking abusive mail flow immediately.
NIST SP 800-53 Rev 5 AU-6 — Audit Record Review, Analysis, and Reporting Responder visibility depends on reviewing sign-in, mailbox, and activity logs together.
IA-5 — Authenticator Management Response requires credential reset, session revocation, and authenticator hardening after compromise.
Recommendation — Review correlated mailbox and authentication logs to confirm scope and timing. Rotate credentials and reissue authenticators after confirming account compromise.
CIS Controls v8 CIS-5 — Account Management Shared ownership hinges on managing account recovery, session control, and access removal.
Recommendation — Revoke compromised access and verify account recovery under a formal account-management process.
MITRE ATT&CK T1114 — Email Collection Internal phishing commonly abuses trusted mailboxes to collect replies and spread messages laterally.
T1078 — Valid Accounts The attacker is using a legitimate internal account as the delivery mechanism.
Recommendation — Map observed message abuse to ATT&CK techniques and hunt for follow-on mailbox abuse. Assume valid-account abuse and prioritize token/session invalidation over simple message cleanup.

Practitioner Guidance

What to prioritise: Treat the first 30 minutes as a containment race. Stop outbound abuse, revoke sessions, and preserve mailbox and authentication evidence before you start debating whether the root cause was email compromise or identity compromise.

What to verify: Confirm whether the account sent messages after the first suspicious sign-in, whether forwarding rules or recovery methods were changed, and whether any privileged access was reachable from the compromised session. If those checks are incomplete, the incident is not yet contained.

What good looks like: A good operating model gives SOC analysts enough visibility to spot message bursts quickly and gives identity responders enough authority to cut off the account without delay. The process should feel coordinated even if two teams are executing different controls.

Practitioner takeaway: East-west phishing is owned by the team that can most quickly break the attacker’s trust channel, but effective response only works when email detection and identity recovery are treated as one incident workflow.