Skip to content
Skip to main content
Cloud Services Operational Explainer

How do I decide whether cloud evidence needs urgent action?

Cloud evidence becomes urgent when delay is likely to lose useful records, allow continuing harm, or make the account state harder to reconstruct.

The seriousness of the offence matters, but it is not the same thing as evidential urgency. A modest incident can still need immediate preservation if the relevant session, audit or deleted-item records are short-lived.

The practical test
Ask two questions at the same time: what evidence may disappear if we wait, and what harm may continue if we do nothing?

Start by identifying what may change

Imagine a cloud account where an unfamiliar administrator session is still active.

The provider currently shows:

Current account state
Active session: S-8841New recovery method added: 14:06 UTCExternal sharing link created: 14:11 UTCAudit export available: last 30 days

You now have two risks:

  • the session may continue to expose data; and
  • the current account state may change as soon as containment begins.

Both matter.

Use four questions to decide priority

1What could disappear?Sessions, tokens, alerts, deleted items, audit events, temporary links or short-retention records.
2What harm is still happening?Unauthorised access, disclosure, deletion, financial loss or further compromise.
3What can be preserved quickly?Current state, targeted exports, event IDs, permission history and relevant logs.
4What will containment change?Sessions, credentials, permissions, alerts, timestamps or later attacker behaviour.

This is the balance to manage.

Preservation and containment should be coordinated

Where operationally possible:

  1. identify the account, tenant, resource and time range;
  2. preserve the short-lived or volatile records first;
  3. capture the current access and permission state;
  4. carry out the containment action;
  5. record exactly what changed; and
  6. verify whether the risk actually ended.

What should I do if a cloud account may be compromised? develops that sequence.

If immediate harm requires action before full preservation, act to protect people or data and document the evidential effect. The aim is not to keep a perfect untouched scene while damage continues.

Urgent action is justified where

delay risks losing relevant evidence or allowing continuing harm that cannot sensibly wait.

Urgent does not mean

changing everything immediately without recording the current state or understanding what each control will alter.

The practical point is: cloud urgency is a race against both evidence loss and continuing harm. Preserve the fragile records, then make each containment action traceable.

Reference: CLD-160Cloud Services