PG&E Public Safety Power Shutoff is scheduled for Wednesday, October 9th at 4 AM for much of Northern California. For planning purposes, PG&E suggests customers prepare for outages that could last several days. Please take appropriate actions to ensure the safety of your systems if you are in a targeted shutdown area. See if your area is affected here...

Introducing ATS Identity Threat Detection and Response

August 14th, 2026 by admin

Man working on laptop

The Growing Threat of Account Compromises

Account compromises have become the number one way businesses lose money to cybercrime, according to the FBI. Over the last decade, Business Email Compromise (BEC) has cost organizations a staggering $50 billion—making it the most financially devastating form of cybercrime affecting businesses worldwide.

The statistics paint a sobering picture: 90% of breaches worldwide are caused by phishing attacks, and 29% of identity-based attacks result in wire fraud, with an average cost of $137,000 per incident. For small and medium-sized businesses, a single successful attack can be financially catastrophic.

What makes these attacks particularly dangerous is their sophistication. 75% of successful attacks now bypass multi-factor authentication (MFA) by prompting users to unknowingly enter their MFA codes. Traditional security measures that businesses have relied on for years are no longer sufficient to protect against modern threats.

Why Traditional Security Falls Short

The landscape of cybersecurity threats has evolved dramatically. Attackers have adapted their methods to exploit the tools and platforms businesses use every day. Consider these troubling trends:

  • 73% of successful attacks are launched from within the United States, many without VPNs, making geographic filtering ineffective
  • 91% of attacks are automated, allowing criminals to scale their operations exponentially
  • Attackers frequently use compromised accounts of trusted colleagues, so malicious emails bypass spam filters completely
  • Microsoft-hosted links to shared documents and fake invoice requests appear legitimate to traditional security systems
  • Attacks arrive via text messages and collaboration platforms, not just email

The problem isn't that businesses lack security tools—it's that conventional security solutions were designed for a different generation of threats. Email filters catch obvious spam but miss sophisticated attacks that use legitimate Microsoft infrastructure. MFA protects against stolen passwords but fails when attackers manipulate users into providing their authentication codes. Endpoint protection secures devices but can't identify when a legitimate user account has been compromised.

Introducing ATS's Identity Threat Detection & Response Platform

Recognizing the critical gap in protection against identity-based attacks, ATS is transitioning clients to a comprehensive Identity Threat Detection & Response (ITDR) platform with 24/7 Microsoft 365 monitoring. This advanced capability represents a fundamental shift from reactive security to proactive threat detection and response.

The platform operates as a continuous guardian of your Microsoft 365 environment, analyzing user behavior patterns in real-time to identify compromised accounts before attackers can cause damage. Rather than waiting for users to report suspicious activity or discovering breaches weeks after they occur, the system identifies account compromises within an average of just three minutes.

How Behavioral Monitoring Stops Attacks

The ITDR platform uses deep behavioral analytics to understand how each user in your organization typically works. It learns normal patterns—when they log in, which applications they use, how they interact with files, and who they communicate with. When an account is compromised, the attacker's behavior inevitably differs from these established patterns.

The system immediately detects anomalies such as:

  • Unusual login times or locations
  • Abnormal email forwarding rules being created
  • Unexpected access to sensitive files or folders
  • Suspicious email sending patterns
  • Changes to mailbox settings or security configurations
  • Atypical file sharing or download activity

When suspicious behavior is detected, the platform takes immediate automated action to stop the attack while alerting ATS's security team for investigation. This happens in real-time, 24 hours a day, 7 days a week—including nights, weekends, and holidays when many attacks occur.

Protection That Works With Your Business, Not Against It

One of the most significant challenges with security tools is balancing protection with productivity. Many security solutions create friction for legitimate users, locking accounts when employees travel, work remotely, or simply access systems in ways that trigger overly aggressive rules.

The ITDR platform's behavioral analytics are sophisticated enough to distinguish between legitimate activity and genuine threats. An employee accessing files while traveling internationally doesn't trigger false alarms because the system recognizes their behavior patterns and device. A VPN user working from a new location continues their work without disruption.

This intelligence means your team experiences security without disruption. Employees don't face constant verification challenges or locked accounts. IT staff aren't overwhelmed with false positive alerts. Business operations continue smoothly while sophisticated threats are stopped automatically.

Stopping Attacks That Bypass Traditional Defenses

The ITDR platform specifically addresses the threats that traditional email filtering and endpoint security miss. When an attacker compromises an employee's account and uses it to send phishing emails to clients, standard email security doesn't flag these messages because they're coming from a legitimate account within your domain.

The platform identifies this threat by recognizing that the communication patterns are abnormal for that user. Before those phishing emails reach your clients, the attack is stopped. This prevents not just immediate financial loss but also the potentially devastating reputational damage that occurs when your clients receive phishing emails appearing to come from your company.

Similarly, when attackers modify invoices or create fraudulent payment requests—a common tactic in business email compromise schemes—the behavioral monitoring detects these actions as anomalous activities and intervenes before wire transfers are initiated.

The Three-Minute Advantage

The average detection time of three minutes represents a crucial advantage in the race against cybercriminals. In most breaches, attackers move quickly once they've compromised an account. They immediately begin reconnaissance, searching for valuable data, identifying key contacts, and planning their fraud scheme.

Traditional breach detection takes an average of 207 days, according to IBM's Cost of a Data Breach Report. During those months, attackers have unlimited time to exfiltrate data, compromise additional accounts, and execute wire fraud schemes.

By identifying compromises within three minutes, the ITDR platform stops attackers before they can:

  1. Access sensitive financial information or intellectual property
  2. Send phishing emails to your clients or partners
  3. Modify invoices or create fraudulent payment requests
  4. Establish persistent access through backdoor accounts
  5. Spread laterally to compromise additional user accounts
  6. Exfiltrate customer data or confidential documents

Comprehensive Microsoft 365 Protection

Microsoft 365 has become the backbone of business operations for organizations of all sizes. Email, file sharing, collaboration tools, and business applications all run through this platform. This centralization creates tremendous efficiency—but also tremendous risk if accounts are compromised.

The ITDR platform provides comprehensive monitoring across your entire Microsoft 365 environment, including:

  • Exchange Online email and mailbox configurations
  • SharePoint and OneDrive file activities
  • Teams communications and file sharing
  • Azure Active Directory identity changes
  • Application permissions and OAuth grants
  • Administrative actions and security setting modifications

This complete visibility ensures that no matter how an attacker attempts to exploit a compromised account, their actions are detected and stopped.

Preventing Client-Facing Fallout

One of the most damaging consequences of account compromises is the impact on client relationships. When phishing emails are sent from your domain to your clients, the damage extends far beyond immediate financial loss. Clients lose trust in your organization's ability to protect their information. Prospects question whether they want to do business with a company that's been compromised.

The ITDR platform specifically prevents this client-facing fallout by stopping phishing campaigns before they reach external recipients. Your clients never receive suspicious emails from your domain. Your reputation remains intact. Your business relationships continue unaffected by the attack that was stopped in the background.

24/7 Monitoring by ATS

The ITDR platform is backed by ATS's 24/7 monitoring and response capabilities. While the platform's automated detection and response handles immediate threats, ATS's security team provides continuous oversight, investigating alerts, refining detection rules, and ensuring optimal protection.

This combination of advanced technology and expert human oversight delivers comprehensive protection. Clients benefit from cutting-edge threat detection without needing to build internal security operations capabilities or hire specialized cybersecurity staff.

As a provider of managed IT services, ATS takes responsibility for the ongoing operation, tuning, and optimization of the ITDR platform. Your team can focus on business operations while ATS ensures your Microsoft 365 environment remains secure against identity-based threats.

The Cost of Not Having Identity Protection

With the average wire fraud incident costing $137,000 and business email compromise causing $50 billion in losses over the last decade, the financial case for identity threat detection is clear. But the true cost of compromise extends beyond immediate financial loss:

  • Legal and regulatory penalties for data breaches
  • Customer notification and credit monitoring costs
  • Forensic investigation and incident response expenses
  • Business disruption and productivity losses
  • Increased insurance premiums
  • Long-term reputational damage
  • Lost business opportunities

For many small and medium-sized businesses, a single significant compromise can threaten the organization's viability. Identity threat detection transforms this risk from catastrophic to manageable.

Making the Transition to ITDR

ATS is actively transitioning clients to the ITDR platform as part of our commitment to providing cutting-edge cybersecurity protection. The implementation process is designed to be seamless, with minimal disruption to business operations.

The platform integrates directly with your existing Microsoft 365 environment, leveraging native security APIs and audit logs. There's no software to install on endpoints, no changes to user workflows, and no impact on system performance. Users continue working exactly as they did before—they're simply protected by an additional layer of sophisticated behavioral monitoring.

After implementation, the platform begins learning normal behavior patterns for your organization. Within a short baseline period, it provides full protection against identity-based threats with 24/7 monitoring active.

Protect Your Business with ATS

Account compromises represent the most significant financial threat facing businesses today, and traditional security tools are no longer sufficient to stop sophisticated identity-based attacks. ATS's Identity Threat Detection & Response platform delivers the advanced protection your organization needs, with behavioral monitoring that identifies compromises in three minutes and stops attacks before they cause damage.

Don't wait until your business becomes another statistic in the $50 billion lost to business email compromise. Contact ATS today to learn more about how our ITDR platform can protect your Microsoft 365 environment with 24/7 monitoring and response.

Posted in: Cyber Security