Suspicious activity
Signal / Security monitoring
Two signals. A reason to look closer.
Identity protection flags an unusual sign-in. Endpoint protection reports suspicious activity on a managed laptop. An engineer needs to establish what happened.
- Identity detection & responseUnusual account activity to verifyITDR
- Endpoint detection & responseA laptop finding to investigateEDR
An alert alone does not establish that a breach occurred.
Investigate / Human judgement
Check the person, device and evidence.
An engineer checks the sign-in with the colleague through a known contact route. They compare endpoint findings, NinjaOne device context and available events in the SIEM, our security log analysis system. HaloPSA holds the findings and a named DSC owner.
If the colleague does not recognise the activity, we assess the evidence and the response needed.
If the colleague recognises the sign-in, the endpoint finding still needs an explanation.
Act / An authorised response
Contain the risk with authority to act.
For the unrecognised activity branch, investigation supports a response. The engineer checks the agreed response plan or obtains approval before disruptive action, such as revoking sessions or isolating the laptop.
The HaloPSA record captures the reason, authority, actions and update to the colleague. Escalation and any reporting duties are considered during the response.
A recognised sign-in still needs checking.
For this branch, the engineer verifies the colleague's explanation and separately establishes that the endpoint activity is expected. They record the supporting evidence before closing either finding.
A colleague recognising a sign-in would not, by itself, justify dismissing an endpoint alert.
Recover / Check the outcome
Check the account. Check the laptop.
Following remediation, the engineer verifies the device and account before restoring access. The colleague tests the services they need, and the record keeps any remaining concern visible.
Verify normal work can continue.
The engineer confirms the colleague can work and records the checks supporting the expected-activity finding. Any unresolved evidence stays open for investigation.
- Technical check
- Device, identity and available event evidence
- Human check
- Confirmation from the affected colleague
- Service record
- Outcome, exceptions and next owner
Review / People & governance
The learning becomes part of the service.
The record feeds the management review, with evidence behind the outcome and an owner for each further action.
- PeopleRelevant staff guidance and a clear way to report concerns.
- ControlsReview access, detection settings and any remaining technical findings.
- GovernanceRecord risk decisions, action owners and review dates, including escalation and reporting decisions made during the response.
For the expected-activity branch, any detection adjustment needs review before the control is changed.




