Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What should teams do when a trusted account…
Governance, Ownership & Risk

What should teams do when a trusted account or executive identity is abused through email?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 8, 2026 Domain: Governance, Ownership & Risk

Treat it as an identity incident, not just a mail incident. Contain the account, revoke any delegated or standing authority it can exercise, review recent requests initiated from that identity, and inspect downstream approvals for business action taken on trust alone. The goal is to stop the compromised identity from continuing to authorise work.

When a trusted account is abused, what is the real incident?

The key question is whether the email compromise has turned a trusted identity into an execution path. If the account can request approvals, trigger work, or influence downstream action, the problem is not just message abuse. It is an identity and authority problem, which means response has to focus on containment, authority revocation, and traceable follow-up.

That distinction matters because business teams often see a familiar sender and assume the request is safe. Once trust has been exploited, the attacker is not relying on the mailbox alone, they are relying on the organisation’s willingness to honour the identity behind it.

Why the compromise must be treated as authority abuse

A trusted executive, shared inbox, or delegated account can function as a shortcut around normal verification. That makes the identity itself the asset under attack. If the account can approve invoices, authorise changes, request resets, or pressure staff into acting, the compromise extends beyond confidentiality into unauthorised business action.

Containment should therefore include the account, any active sessions, and any standing delegation or broad authority that the identity can still exercise. If you only reset a password but leave delegated approvals, mailbox rules, or workflow privileges in place, the adversary may continue to act through the same trust relationship.

A governance-oriented NHI guide is useful here because the same lifecycle discipline applies to any identity that can authorise work, whether human or non-human. The response objective is to remove the identity’s ability to exercise trust until the organisation has re-established control.

What teams should check after containment

Start with the recent actions taken from that identity. Review emails, approvals, delegated tasks, password resets, payment requests, vendor changes, access grants, and any workflow steps that were accepted because the sender was trusted. Then inspect downstream systems for actions that were initiated on the basis of that trust, not just for messages that were delivered.

That review should also include the boundaries around the identity: shared access, delegation settings, forwarding rules, API or workflow permissions, and any other standing authority that could survive the compromise. If the account participates in business processes, those processes may need to be paused until the approval path is revalidated.

The practical question is whether the identity was merely used to send mail or was used to authorise something material. The second case usually requires broader response, because the compromise may have created a chain of valid-looking business decisions rather than a single suspicious email.

Risk and Threat Considerations

Trusted identities are attractive because they can bypass scrutiny and create urgency, especially when the attacker can imitate routine executive or business communication. The main risk is that staff or automated workflows continue to accept requests that would normally be challenged, which lets the attacker convert trust into action.

Failure mechanism: The adversary abuses a legitimate identity, then uses existing delegation, standing privilege, or process trust to push approvals, resets, or payments that look authorised.

Impact: Organisations can suffer fraudulent transfers, unauthorised access changes, business process manipulation, and wider compromise if the same trust path is reused for additional actions.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack surface, NIST SP 800-53 Rev 5, CIS Controls v8 and NIST CSF 2.0 set the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementAbused trusted accounts often persist through compromised credentials and delegated access.
AC-6 — Least PrivilegeStanding authority lets a compromised trusted account continue authorising business actions.
AU-6 — Audit Review, Analysis, and ReportingResponse depends on tracing actions initiated from the abused identity.
Recommendation — Rotate credentials, revoke tokens, and retire standing authenticators after account abuse. Remove excess privileges and standing delegation from accounts that can trigger business action. Review logs for requests, approvals, and changes initiated from the compromised identity.
CIS Controls v8CIS-5 — Account ManagementAbused trusted accounts are an account governance and revocation problem.
Recommendation — Inventory, disable, and review accounts that can still act on behalf of the compromised identity.
ISO/IEC 27001:2022A.5.16 — Identity managementIdentity misuse requires revalidating who can act and under what authority.
Recommendation — Re-establish identity ownership, delegation, and approval authority before resuming business use.
OWASP Non-Human Identity Top 10NHI-01 — Improper OffboardingA compromised trusted account should be removed from active authority quickly.
NHI-05 — Overprivileged NHIStanding authority magnifies the damage a compromised trusted identity can cause.
NHI-10 — Human Use of NHITrusted identities abused through email often succeed because humans accept trust at face value.
Recommendation — Revoke the abused account’s active access paths and standing authorisation immediately. Reduce standing privilege so a stolen trusted identity cannot authorise broad actions. Validate high-impact requests out-of-band before acting on a trusted identity’s message.
NIST CSF 2.0PR.AA-05 — Identity Management, Authentication, and Access ControlThe incident is about revoking access and limiting what the identity can still do.
Recommendation — Restrict and revalidate access paths for identities involved in the abuse.

Practitioner Guidance

What to prioritise: Contain the identity first, then trace what that identity could still authorise. If approvals or transactions are pending, suspend or independently re-verify them before assuming they are legitimate.

What to verify: Check for delegated inbox access, mailbox rules, OAuth grants, workflow permissions, and any standing approvals that survived the compromise. Those are the controls most likely to preserve attacker reach after the password is changed.

Decision rule: If the identity can still cause a business action to execute, treat it as an active authority issue, not a closed email event. If the identity cannot authorise anything and no downstream requests were accepted, the response can stay narrower.

Practitioner takeaway: The measure of success is not whether the inbox is cleaned up, it is whether the compromised identity can no longer cause other teams or systems to trust it.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org