Has an incident actually occurred, or is it only suspected?¶
An organisation may describe an incident before it has established what happened.
Evidential caution: that opening an incident ticket, escalating an alert or calling an event a “breach” proves that unauthorised activity occurred.
What this means¶
That is often sensible for response purposes, but investigators must distinguish suspicion from confirmation.
Was there a system event?
Was there an alert?
Did a user report unusual activity?
Was data found in an unexpected location?
Did a service stop working?
Was a suspicious file discovered?
Was there an external notification from a provider or third party?
Then ask what has actually been verified. A suspicious login may later be linked to legitimate travel. A malware alert may show that a file was blocked before execution. Missing data may result from retention or configuration rather than deletion. High traffic may reflect legitimate demand.
Useful reporting language includes:
“suspected unauthorised access”;
“activity consistent with”;
“an alert indicating”;
“the available records show”;
Avoid moving too quickly from an indicator to a conclusion.
At the same time, do not wait for complete certainty before preserving evidence. Volatile logs, active sessions and provider-held records may be lost while the incident is still being assessed.
The investigator should maintain two parallel positions: act quickly enough to protect evidence and limit harm, but describe the status of the incident cautiously.
================================================================================
What to check or do next¶
- Start by identifying the factual basis for the concern.
Evidential limits¶
This does not mean the concern should be minimised. It means the assessment should be described accurately.
“the available material does not yet establish”.
Operational takeaway
Preserve evidence on the basis of reasonable concern, but distinguish clearly between suspected, indicated and confirmed activity.