Securing an executive's email after a targeted destabilisation attempt
Emergency migration of a chairman's mailbox from a compromised corporate email service to Google Workspace. PST export, access hardening and advanced protection.
Context
The chairman of a company was targeted by an attempt to destabilise him, which carried the risk of sensitive emails being deleted from his work mailbox, hosted by an outside supplier. Confidential emails had been read and potentially exfiltrated. Trust in the existing infrastructure was gone.
The work was launched as an emergency, with two objectives: secure the executive’s communications immediately, and migrate to a fresh, fully controlled environment.
The problem
A confirmed compromise
Suspicious logins had been identified on the chairman’s account, from unusual IP addresses. The extent of the unauthorised access was hard to assess: how many emails had been read, forwarded, copied? Nothing was certain.
Operational urgency
The chairman had to keep communicating without interruption, while having the assurance that his exchanges were no longer being monitored. Every hour counted.
The intervention
Phase 1: immediate isolation and lockdown
- Changed every password and revoked active sessions
- Enabled multi-factor authentication (MFA) on all critical accounts
- Audited the automatic forwarding rules (silent redirects had been set up)
- Froze the compromised account for analysis
Phase 2: migration to Google Workspace
- Full export of the mailbox in PST format (archived from the legacy desktop client)
- Creation of a dedicated Google Workspace environment, configured securely from the outset
- Import of the email history into Gmail using a script
- Configuration of the DNS records (MX, SPF, DKIM, DMARC) for the new service
- Cut-over of the mail flow
Why this choice
The decision was not ideological, it was operational. In this situation, the objective was to restore a reliable service within hours, with simple administration and a high level of security.
This case is a reminder of something that is often forgotten: a company does not need a full Microsoft tenant and the whole ecosystem around it to work properly. What it needs is robust email, controlled access, strong authentication, backups and clear governance.
Another factor weighed in the balance: AI is already built into the Google environment. For a business leader who is not yet comfortable with AI agents, that is a useful way in — help with drafting, summaries of email threads, contextual assistance inside everyday tools, with no additional technical project.
Google is clearly pushing this usage, whether users want it or not. That is a deliberate trade-off here: imperfect but immediately available support is better than a theoretical AI strategy that never reaches production.
Pragmatism therefore drove the decision: take the option that was fastest to secure, clearest for the executive and simplest to maintain over time.
Phase 3: security hardening
- Enrolment in Google’s Advanced Protection Program (physical security keys)
- Alerts on logins from unusual devices or locations
- Restriction of the third-party applications allowed to access the account
- Training for the executive on good practice: recognising phishing, managing devices, sharing documents securely
Phase 4: documentation and prevention
- Incident report setting out the findings, the actions taken and the recommendations
- An email security policy put in place
- Review of the legacy supplier’s access, and termination of the contract
Results
- Migration with no interruption of service
- Full history preserved: all emails, contacts and calendars migrated from the PST
- Stronger security: MFA, physical keys, login alerts, strict DMARC
- Autonomy regained: the executive controls his own environment, with no remaining dependence on the compromised supplier
- Silent redirects removed: the information leaks stopped immediately
What this case illustrates
A business leader’s mailbox is a prime target. Without multi-factor authentication, without an audit of forwarding rules, without access logging, an email account becomes an open door. Migrating to a secure environment is not a luxury: it is a basic protective measure that should have been in place before the incident.