How do I decide whether cloud evidence needs urgent action?¶
Cloud evidence becomes urgent when delay is likely to lose useful records, allow continuing harm, or make the account state harder to reconstruct.
The seriousness of the offence matters, but it is not the same thing as evidential urgency. A modest incident can still need immediate preservation if the relevant session, audit or deleted-item records are short-lived.
Start by identifying what may change¶
Imagine a cloud account where an unfamiliar administrator session is still active.
The provider currently shows:
S-8841New recovery method added: 14:06 UTCExternal sharing link created: 14:11 UTCAudit export available: last 30 daysYou now have two risks:
- the session may continue to expose data; and
- the current account state may change as soon as containment begins.
Both matter.
Use four questions to decide priority¶
This is the balance to manage.
Preservation and containment should be coordinated¶
Where operationally possible:
- identify the account, tenant, resource and time range;
- preserve the short-lived or volatile records first;
- capture the current access and permission state;
- carry out the containment action;
- record exactly what changed; and
- verify whether the risk actually ended.
What should I do if a cloud account may be compromised? develops that sequence.
If immediate harm requires action before full preservation, act to protect people or data and document the evidential effect. The aim is not to keep a perfect untouched scene while damage continues.
delay risks losing relevant evidence or allowing continuing harm that cannot sensibly wait.
changing everything immediately without recording the current state or understanding what each control will alter.
The practical point is: cloud urgency is a race against both evidence loss and continuing harm. Preserve the fragile records, then make each containment action traceable.