Security notice to clients
Your M365 accounts are a target.
Here’s what we’re doing about it.
We’re adding identity and device protection as standard for every business we manage — because waiting until after a breach is too late.
How to opt outThe threat
Most breaches don’t start with a virus.
They start with a login. Someone clicks a phishing link, reuses a password, or gets caught in a credential-harvesting campaign. The attacker gets in using a real username and a real password — so nothing flags it as unusual.
Once inside, they move quietly. They set up hidden rules to intercept your emails. They watch payment conversations. They impersonate your CEO or your supplier and redirect an invoice. By the time anyone notices, the money is gone, the data is copied, or both.
Credentials stolen
Phishing, password reuse, or session hijack.
Login looks normal
Attacker signs in — MFA may already be bypassed.
Silent persistence
Hidden mail rules, mailbox access, quiet reconnaissance.
Damage done
Invoice fraud, data theft, or ransomware deployment.
Shared responsibility
Microsoft keeps the platform running. Watching your accounts is on you.
What Microsoft covers
- Platform uptime and infrastructure security
- Core email and file service delivery
- Patching Microsoft’s own software
What you’re responsible for
- Monitoring who logs into your accounts
- Detecting misuse once someone is inside
- Responding to identity-based attacks
This is Microsoft’s own published policy — the shared responsibility model. It means that a compromised account, a hidden inbox rule, or a payment redirection attack is your problem to detect and contain, not theirs. That’s the gap these services are designed to close.
What we’re adding
Two services. Switched on as standard.
Huntress ITDR
Account break-in monitoring
Watches your Microsoft 365 environment for signs someone other than your staff has got in — logins from unexpected locations, hidden mail rules designed to intercept messages, attempts to impersonate a manager or supplier to redirect payments. When something looks wrong, Huntress’s 24/7 security team investigates and tells us exactly what to do — fast.
Huntress EDR
Device attack protection
Watches the computers and laptops your team uses for signs of attack — malicious software, ransomware, or someone attempting to take remote control of a machine. Backed by the same 24/7 security operations team. If something triggers, they’re already on it.
Pricing & timing
What it costs and when it starts.
You don’t need to do anything to be protected. If you’d like to opt out, see the section below.
Opting out
You can opt out. We’d rather you understood the trade-off first.
Without this monitoring in place, an account or device compromise can run undetected for longer and spread further before anyone notices. When we’re eventually called in, we have less forensic data to work with — which means investigations take longer and cost more.
Important: if you opt out and experience an identity-based incident
Incident response and recovery services may be charged at up to 3x our standard hourly rate. This reflects reduced visibility, longer attacker dwell time, and the significantly increased effort required to investigate and contain a breach without ITDR telemetry. Opting out confirms that Nectar has recommended this protection and you’re accepting the increased risk.
To opt out, get in touch and we’ll send you a short agreement to sign. Once it’s signed, the opt-out is confirmed — and you can switch protection back on at any time.
Contact us to opt outCommon questions
Answers to what we get asked most.
Isn’t Microsoft 365 already secure?
Microsoft keeps its platform secure and running — but under its own published rules (the shared responsibility model), monitoring for misuse of your accounts is your responsibility, not theirs. Unusual logins, hidden mail rules, impersonation — none of that is something Microsoft watches for on your behalf. This service fills that gap.
We already use MFA. Isn’t that enough?
MFA is essential and we strongly recommend it. But attackers have increasingly effective ways around it — token theft, session hijacking, MFA fatigue attacks. This service watches what happens after someone logs in, so unusual activity gets caught even when a login code has been bypassed.
What if we do nothing?
Without monitoring, account and device compromises are usually only spotted after the damage is done — a fraudulent payment, leaked data, or systems offline. The longer it goes undetected, the more it costs to fix.
Why does incident response cost more if we opt out?
When ITDR isn’t in place, there’s less forensic data available, investigations take longer, and the scope of compromise is often wider. That directly increases the effort required to respond safely — which is reflected in the rate.
Can we opt back in later?
Yes. You can re-enable either service at any time in writing. Your risk posture may change, and we’d rather you came back to it than stayed exposed.
Is this a compliance requirement?
Not mandatory on its own — but it strongly supports common security standards and demonstrates that you’re taking reasonable steps to protect client information. It’s relevant to Essential Eight, ISO 27001, and NZ privacy obligations.
Questions about what this covers?
Call us on 0508 632 821 or email [email protected] — we’re happy to walk through what this monitors and how it fits your situation.
Call us on 0508 632 821