Skip to content
Back to WikiDefinitions

How to recognise a cyberattack

A cyberattack rarely announces itself. The earliest signs are usually subtle: a login from an unfamiliar country, an email sent from your account that you did not write, a colleague receiving a message that claims to be from you, or a system slowing down without explanation. According to the NCSC, most attackers operate inside a network for weeks before detection. The gap between the first warning sign and visible damage is where recovery cost is decided. Early recognition depends on two habits: paying attention to small anomalies, and having a clear reporting channel so staff can raise concerns without hesitation.

Technical warning signs

Multi-factor authentication prompts you did not trigger. Login notifications from countries your organisation does not operate in. Sudden, unexplained disk activity or CPU usage on workstations. Antivirus alerts that briefly appear and then disappear, often a sign of malware disabling the security product. New administrator accounts you did not create. Scheduled tasks or services with unfamiliar names running in the background. Outbound network traffic to addresses your organisation has no reason to contact.

Individually, any of these can be innocuous. Two or more in combination, especially on systems with access to sensitive data, justify immediate investigation.

Behavioural warning signs

Colleagues receiving replies to emails they never sent. Customers or partners reporting odd messages from your domain. Finance noticing small, successful test transactions before a larger fraudulent transfer. Invoices arriving with banking details that do not match the supplier's usual account, a common signal of business email compromise.

Attackers studying a target usually test the response first. Reports of phishing emails that reference internal project names, real colleagues, or ongoing deals suggest that reconnaissance has already happened.

Signs of business email compromise

Business email compromise (BEC) is one of the most common attack patterns against Dutch mid-market organisations. The warning signs include: email forwarding rules you did not set up, often hiding incoming mail from view; sent-items folders with messages you did not send; login history showing access from unfamiliar IP addresses or mail clients; and invoice fraud attempts that match your actual supply chain closely.

If you suspect a compromised inbox, do not simply change the password, because attackers usually establish secondary persistence through OAuth-authorised apps. A full [phishing incident response](/phishing-incident-response) clears forwarding rules, revokes app tokens, and audits access logs.

Signs of a broader network compromise

Lateral movement within a network produces specific, detectable signals: unusual use of remote administration tools (PsExec, RDP, PowerShell remoting), repeated failed login attempts across multiple accounts in a short window, and new service accounts with elevated privileges. Attackers often test backup systems before launching ransomware, so unexpected access to backup servers is a late-stage warning that deployment may be imminent.

What to do when you spot a sign

Report it, even if you are not certain. A false alarm costs ten minutes. A missed genuine attack costs weeks of recovery. Every organisation should have a clearly named security contact, a phone number that is answered, and a simple reporting procedure any staff member can use without fear of being wrong. When a report comes in, preserve the evidence first (screenshots, email headers, log excerpts) before any remediation. Premature cleanup destroys the trail investigators need. SecDesk answers suspected-incident calls and can confirm or rule out within the first hour.

Discuss this with a senior responder.

Discuss this with a senior responder
Incident response

Need incident response?

088 SECDESK (7323375)

Call us. A senior responder picks up.

  • Two-hour SLA
  • Dutch senior responders

Emergency form

Two-hour response.

Is this urgent? Call us.

088 SECDESK (7323375)

Cannot wait? Call 088 SECDESK (7323375) now

Emergency line088 SECDESK
Call now