Skip to content
CIM-000 Cyber Incidents & Offender Methods

A cyber incident may be relevant to my investigation — where do I start?

You have been told that a cyber incident may be relevant to your investigation.

Evidential caution: that the words “cyber incident” describe a proven technical event. They may not. You may have been given an alert, a user report, an incident ticket, a screenshot, a summary from an IT team or an intelligence assessment. Each has a different evidential value.

What this means

What system, account, device or service is affected?

What activity has actually been observed?

Is the activity still happening?

What records or volatile data may disappear?

Who has technical control of the affected environment?

At this stage, you are not trying to prove the whole incident. You are trying to stop evidence being lost and establish a defensible starting position.

================================================================================

What to check or do next

  • Do not begin by trying to name the attack or identify the offender. Begin by working out what has actually happened, what evidence may exist and what could be lost.
  • Start with five immediate questions.
  • Preserve the original material you have been given. Record where it came from, who produced it, when it was produced and whether it is a direct system record or somebody’s interpretation. Ask for the underlying records rather than relying only on screenshots or summaries.
  • Identify the people who can explain the environment. That may include the system owner, IT staff, a security provider, a cloud administrator or a digital-forensics specialist. Do not allow well-intentioned troubleshooting to overwrite logs, terminate sessions or rebuild systems before the evidential consequences are understood.

Evidential limits

Keep systems, accounts, devices and people separate. A suspicious action associated with an account or device does not by itself identify the person responsible. Shared access, stolen credentials, automation, remote control and legitimate administration may all need to be considered.

Operational takeaway

Establish what was actually observed, preserve the most vulnerable evidence and separate technical activity from personal attribution before drawing conclusions.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.