Every other unit in this series measures impact in terms of what gets exposed. This one measures it in terms of for how long.
It is a variable that almost never appears in discussions of personal security, and in practice it is decisive: the same unauthorised sign-in produces modest damage if discovered in ten minutes and very serious damage if discovered in three months.
It expands on the recommendation account login alerts.
The factor that governs everything: time to discovery
| Time to discovery | What can still be done | What has already happened |
|---|---|---|
| Minutes | Revoke the session, change the password | Some content read |
| Hours | All of the above, with a few more checks | Possible sends, perhaps a configuration |
| Days | Recovery possible, but the damage has to be chased | Forwarding active, contacts reached |
| Weeks | The account may no longer be recoverable on your own | Other accounts reached through recovery |
| Months | A recovery process with the service is needed | Hard to reconstruct what was touched |
The progression is not linear: there is a jump between “days” and “weeks”, and it is the point where an incident on an account becomes an incident on a digital identity.
1. Confidentiality: exposure that accumulates
A practical example
An unauthorised sign-in to the main email, undetected. No visible change: the password works, everything looks normal.
What the incident looks like
Confidentiality here is not compromised at one moment: it is compromised continuously. Every day that passes adds that day’s mail.
And there is a qualitative difference from an instantaneous exposure: whoever has continuing access does not only read the messages — they observe the habits. Who you talk to, about what, in what tone, at what times, which services you use, when you are travelling. It is the material that makes possible the targeted deceptions described in the unit on attacks.
Another effect of prolonged access: the historical archive. Mail from ten years ago holds documents, credentials sent out of necessity, data about family and colleagues. Ten minutes of access does not get there; three weeks does.
What to watch for
- messages showing as read that you did not open;
- searches already run in the mailbox history;
- messages archived or moved that you do not remember.
What to do
Alerts, and a periodic check of the active sessions.
2. Integrity: the quiet construction
A practical example
During the prolonged access, a recovery method, a forwarding rule and a connected application are added.
What the incident looks like
This is where time changes the nature of the problem. With a few minutes somebody does one thing; with weeks they build a position.
| Configuration added | Effect | Does it survive a password change? |
|---|---|---|
| A forwarding rule | Continuous copying of the mail | Yes |
| A recovery method | It allows the account to be taken back | Yes |
| A connected application | Access through an independent token | Often yes |
| A session on another device | Active access | Depends on the service |
| A secondary phone number | It receives the verification codes | Yes |
The right-hand column is the part that surprises anyone facing this for the first time: changing the password is not enough, because these configurations are designed precisely to survive the loss of a password. That is their legitimate function — they exist to let you back in when you forget it — and it is what makes them useful to somebody who should not have them.
What to watch for
- a recovery method you did not add;
- sent messages you did not write;
- a connected application you do not recognise.
What to do
After a suspicious sign-in, the correct sequence is: remove the configurations first, then change the password. The reverse order closes nothing.
3. Availability: the definitive loss
A practical example
Password changed, recovery methods replaced, phone number removed. The account no longer responds.
What the incident looks like
It is the worst outcome, and it is reached almost only with long times to discovery: it requires nobody noticing while the replacement takes place.
Once complete, the account cannot be recovered with the automatic tools — because those tools use precisely the recovery methods that have been replaced. What remains is the manual procedure with the service’s support: it takes documents, time and patience, and the outcome is not guaranteed.
And since the main email is the recovery route for everything else, the loss spreads: every service using that address becomes hard to recover in turn.
What to watch for
- notifications of changes to recovery details;
- a service that no longer accepts your password;
- verification codes that stop arriving.
What to do
A second, independent recovery method, and alerts that make the first step of the replacement visible.
| Aspect | Impact with quick discovery | Impact with late discovery |
|---|---|---|
| Confidentiality | Some content read | The historical archive and your habits |
| Integrity | Little or nothing | Persistent configurations |
| Availability | None | Possible loss of the account |
Why the time to discovery is a choice, not chance
It is the central point of this unit.
Many people think that noticing a sign-in depends on luck, or on attention. In reality it depends almost entirely on a configuration made beforehand: alerts turned on and directed to an independent contact.
Without that configuration, discovery happens as a side effect — a contact reporting an odd message, a service that stops working, a charge. Those are events that arrive when the damage is already distributed.
With that configuration, discovery happens at the first sign-in, that is, before anything at all has been done.
The difference between the two scenarios is not a difference in personal attention: it is the difference of one setting turned on months earlier.
The chain effect between accounts
An aspect that prolonged access makes possible and brief access does not.
The main email is not an account like the others: it is the recovery key to all of them. Whoever has continuing access can, unhurried, start recovery on other services — bank, social, storage — and receive the confirmation messages in the mailbox they have access to.
The process takes time, and it produces messages you would see. But if those messages get deleted straight after being used — which active access allows — no visible trace is left.
That is why the main email deserves the most careful configuration: alerts on, an independent contact, a second factor, and a periodic check of the sessions.
Not all accounts weigh the same
The time to discovery has very different effects depending on which account is involved. It is worth distinguishing, because it guides where to spend the few minutes of configuration.
| Account | Impact of a delay | Why |
|---|---|---|
| Main email | Maximum | It is the recovery key to everything else |
| Password vault | Maximum | It holds the credentials of every account |
| Bank and payments | High but time-limited | Transactions can be disputed, within deadlines |
| Document storage | High and permanent | Files copied stay copied |
| Social networks | Medium, but fast | The relational damage occurs within days |
| Minor services | Low, with one exception | If they are used to recover others, they count |
The first two rows deserve attention because they share a characteristic: they hold nothing precious in themselves — they hold the access to everything else. A delay on any account produces a problem; a delay on these two produces a cascade.
The last row is the least intuitive: a low-value account used as the recovery address for an important one inherits the importance of what it recovers. It is a relationship almost nobody maps, and it is why it is worth looking, at least once, at which email address is set as recovery on each service.
Why the password alone does not close it
It is worth insisting on this point, because it is nearly everybody’s instinctive reaction and it is insufficient.
Changing the password closes a single channel: the one that goes through entering credentials. These stay open:
- the already active sessions, which on many services keep working;
- the connected applications, which operate with an authorisation of their own;
- the recovery methods added, which allow the new password to be reset;
- the forwarding rules, which require no access at all.
The fourth is the most insidious because it is entirely passive: it keeps copying the mail even if nobody signs in again.
Hence the correct sequence, which is counter-intuitive and should be stated explicitly: first remove the configurations, then revoke the sessions, then change the password. The reverse order has a perverse effect — it tells whoever has the access that they have been found, while leaving their means of return intact.
There is an impact that falls outside the three classic aspects and weighs more than it seems: after a late discovery, closing it is not enough — you have to understand it.
Closing is quick: revoke the sessions, remove the configurations, change the credentials. That is twenty minutes.
Understanding what happened is another matter. It means going through weeks of sent mail, checking every connected account, seeing whether documents were shared, contacting the people who may have received messages that were not yours. And it means doing it without a list, because no system keeps a record of what was simply read.
That work is not optional in a professional setting, where you have to be able to state what was exposed. And it is the most concrete reason why alerts are worth the five minutes they cost: they do not only avoid the damage — they avoid the investigation.
How this connects to the Cyber Welfare Framework
| Pillar | What this content contributes |
|---|---|
| Awareness | Understanding that here the decisive variable is time, not the type of data |
| Skills | Knowing that some configurations survive a password change |
| Secure Behaviour | Removing the configurations before changing the credentials |
Reference level: FL2 — Beginner.
Summary
- The same sign-in produces very different damage depending on when it is discovered.
- Between “days” and “weeks” there is a jump: from a compromised account to a compromised identity.
- Forwarding, recovery methods and connected apps survive a password change.
- The time to discovery does not depend on attention: it depends on a configuration made beforehand.
One thing to do today. Open your main email’s security section and look at the list of recovery methods. If there is an entry you do not recognise, you have found the most important thing of your day.
Related content
- Account login alerts — the recommendation this expands on
- Consequences of finding out too late — the concrete effects on daily life
- Security alert warning signs — what to look at in an alert
- How to turn on login alerts — the configuration that shortens the time to discovery
Related resources
Short reads from the Resources section, for anyone who wants to stop on a single aspect:
Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.



