Skip to content
CIM-004 Cyber Incidents & Offender Methods

What could a cyber incident contribute to my investigation?

A cyber incident may provide far more than evidence that an organisation experienced technical difficulty.

Evidential caution: that the incident either proves the whole offence or contributes nothing unless the offender is technically identified. In reality, cyber evidence often strengthens one part of a wider evidential picture.

What this means

It may help establish access, preparation, movement between systems, collection of data, communications with external infrastructure, disruption, concealment or the use of particular accounts and devices.

Incident records may help answer:

when activity began;

which systems or accounts were involved;

what method may have been used;

whether access was attempted or successful;

what information may have been viewed, copied or transferred;

whether the activity was automated or interactive;

what infrastructure communicated with the affected environment;

what actions were taken to hide or maintain access;

what operational impact followed.

The same records may also challenge an allegation. They may show that an alert was blocked, that a transfer did not complete, that the suspected account was inactive or that the activity was consistent with authorised maintenance.

Keep the investigative proposition precise. “Did this account authenticate?” is different from “Did this person control the account?” “Was a file accessed?” is different from “Was the file stolen?” “Did a device contact an IP address?” is different from “Did an offender issue a command?”

Cyber evidence should be combined with witness accounts, organisational records, device evidence, account information, financial material and other relevant enquiries.

The incident may establish a method or sequence without identifying the individual responsible. That is still valuable, provided the limitation is stated.

================================================================================

Operational takeaway

Use cyber-incident evidence to answer specific questions about access, activity, sequence and impact, not as a shortcut to personal attribution.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.