Office365: Protecting the largest, most popular Saas application

Office365 is Microsoft’s fastest-growing product. A staple for individuals and organisations alike, the SaaS offering has dominated the productivity space, with more than 258 million users and 75 million Team users. Covid-19 has significantly accelerated the adoption of Office365 across the globe.  As a result, organisations are exposed to new cyber threats and challenges that they may not be prepared or aware of.

For many users, Office365 is the core of enterprise data sharing, storage, and communication. It is therefore no surprise that it has become a prime target for cyber attackers. With its ecosystem of programs, Office365 account takeover has become the largest security threat vector in the cloud, beating email compromise.

  • Takeovers cost an estimated $6.5-$7 billion in losses across multiple industries
  • Between 2018-2020, there’s been a 98% rise in compromised credentials to accounts
  • 99% of cloud security failures are in the customer’s portion of the responsibility model
  • 56% of breaches are taking months or longer to discover

Thanks to Vectra, the entire Office 365 ecosystem can be protected against data breaches. Cognito Detect sees threats emerging from the cloud in real-time and stops them in their tracks. Users can identify threats across the entire network, tying together attacker activities and progression between cloud, hybrid, and on-prem environments.

For their recent Spotlight report, Vectra was able to observe 4 million Office365 accounts over a 90 day period. They were able to identify suspicious high-risk behaviours associated with attacker techniques exploiting built-in Office 365 capabilities.

Lateral movement is the most common type of suspicious behaviour (the techniques attackers use to move through a network in search of key data), closely followed by command-and-control communication.

  • 96% of customers sampled exhibited lateral movement behaviours
  • 71% of customers samples exhibited suspicious Office365 Power Automate behaviours
  • 56% of customers samples exhibited suspicious Office365 eDiscover behaviours

Attackers live off the land using legitimate Office365 tools and features to remain hidden and bypass security controls. Cognito Detect puts an end to Office365 account takeovers by understanding attacker behaviours and account privilege.

Crucially, Vectra can help you to identify and remediate any threats within Office365 in real time.  Please get in touch today if you would like to find out more, and one of our friendly experts would be more than happy to walk you through the process.

Jan 20 2026

Join Us in Supporting the Great Gloucestershire Mouse Hunt

Core to Cloud is proud to support the Great Gloucestershire Mouse Hunt, a county-wide campaign collecting essential computer peripherals to help improve access to...
Jan 14 2026

From Defence to Resilience: A Strategic Framework for Ransomware Preparedness

Ransomware has evolved into a highly organised and commercially driven threat, capable of bypassing traditional cyber security controls. As attacks become more...
Nov 11 2025

Core to Cloud Partners with The ITSA Digital Trust to Empower Digital Inclusion and Support Sustainable Technology

At Core to Cloud, we’ve always believed that technology should make a positive difference by protecting people, enabling innovation, and building a more inclusive...
Oct 27 2025

Human-led, AI-Enhanced MDR: Rethinking the Balance of People and Technology

By Phil Howe, CTO at Core to Cloud It’s getting colder and wetter outside, and to some the security landscape may feel more complex than ever. Threat actors are faster,...
Oct 22 2025

From Warning to Action: The NCSC Calls on UK Organisations to Build Resilience

In its 2025 Annual Review, the UK’s National Cyber Security Centre (NCSC) issued one of its clearest warnings to date: organisations must prepare for a day when their...
Jun 25 2025

Think You’re Ready for a Cyberattack? Prove It.

In the face of increasing cyber threats, most organisations have invested heavily in technology - firewalls, antivirus, endpoint protection, and cloud security. But...
Jun 13 2025

Secure & Strong Partners with Women in Tech & Cyber Hub (WITCH)

At Core to Cloud, we believe the future of cybersecurity is inclusive, empowering, and community-driven. That’s why we’re proud to announce a meaningful new partnership...
Jun 13 2025

Core to Cloud Expands Strategic Partnership with Vectra AI to Strengthen 24/7 SOC Capabilities

Cirencester, UK, 13 June 2025: Core to Cloud, a leading UK-based provider of cybersecurity services, is deepening its strategic partnership with Vectra AI, the...
May 19 2025

Supply Chain Cyberattacks: Lessons from a Retail Incident

In early May 2025, the UK retail sector experienced a wake-up call. A ransomware attack targeting a retailer’s IT infrastructure disrupted supply chains, impacted...
Mar 14 2025

Rev Up Your Security: Why Cybersecurity is a High-Speed Race, Not a Sunday Drive

Picture this: You’re on the starting grid. The engines roar. The stakes are high. In the relentless Grand Prix of cybersecurity, there’s no cruising—only speed,...

Trusted by CISOs and IT teams at over 150 organisations