How do you know if your company has already been hacked (without knowing it)?
Most breaches go unnoticed for months. Which signals point to an old or ongoing hack, and which checks can you run yourself today to verify your it security?

Ian
Co-Founder & CEO

Many business owners assume they would notice a hack straight away. In practice that rarely holds. An attacker who has gotten in has no interest in making noise. The longer they stay unnoticed, the more data they can read along with and the better they can anchor their access. Study after study shows that breaches go unnoticed for months on average before anyone realises.
So the question is not only whether your it security can stop an attack, but also whether you would even notice an attack that has already happened. Below are the signals we run into most often in practice, and concrete checks you can run yourself today.
Signals you should not ignore
A breach rarely announces itself with a clear alert. It is usually small things that do not add up:
- Systems or internet are suddenly noticeably slower, or devices run hot while nothing heavy is going on.
- Unexplained sign-ins: a login from abroad, in the middle of the night, or on a device nobody recognises.
- Clients or suppliers complain about strange emails supposedly from you, with invoices or links you never sent.
- Security is suddenly off: the antivirus is disabled, updates are turned off, or a staff member can no longer change a setting.
- Unknown accounts or new rules in the mailbox, for example a rule that quietly moves all mail from your accountant to a folder, unread.
- An extortion message or ransom demand, or files that are suddenly encrypted and unusable.
That last point about mailbox rules is often missed. Attackers set up silent forwarding or move rules so you do not see the traces of their fraud. You only notice when a client calls about an invoice you never sent.
Checks you can run yourself today
You do not need an expensive investigation to get a first picture. These checks take about half an hour in total:
- Review the sign-in history of your email and your key accounts. In Microsoft 365 and Google Workspace you can see recent logins per user, with time, location and device. Look for sign-ins that do not fit.
- Check the forwarding and mailbox rules on every account. Remove anything you did not set up yourself and ask who could have created it.
- Test your addresses on haveibeenpwned.com. If your email shows up in a known breach, assume the matching password is in the wrong hands.
- Verify that multi-factor authentication (MFA) is really on for everyone, not just the owner. Without MFA, one leaked password is enough to get in.
- Go through which accounts exist and are active. Is there still an open login from a former employee or an external party you no longer recognise?
If you find something suspicious, do not panic and change every password and nothing else. Whoever starts clicking blindly warns the attacker and may wipe traces you will need later. Document what you see first, then bring in someone who knows what to look for.
From suspicion to certainty
The checks above give you a first impression, not a definitive answer. Mainly they tell you whether something deserves a closer look. A thorough review also examines log files, access rights and systems you do not see day to day. The good news: precisely because attackers rely on silence, targeted looking often yields results quickly. And even if you find nothing, at least you know where you stand.
Not sure whether something is wrong, or simply want to know in black and white how your it security is doing? Start with our free security assessment, and within half an hour you will know where your biggest blind spots are.