How should uncertainty about the initial access route be reported?¶
Uncertainty about initial access should be stated clearly rather than hidden behind confident technical language.
Avoid the dangerous assumption¶
The dangerous assumption is that an incident report must name one definitive point of entry.
It should not if the evidence does not support that conclusion.
Use language that separates fact from inference.
For example:
“The earliest confirmed unauthorised event was…”
“The available records are consistent with…”
“The evidence supports two possible routes…”
“No surviving record establishes how the first foothold was obtained.”
Avoid statements such as “the attacker entered through” where the route is only assumed from vulnerability, timing or later behaviour.
Explain the basis of the assessment.
Identify:
- the earliest confirmed event
- the suspected route
- the records supporting it
- the missing evidence
- alternative explanations
- the confidence of the conclusion
- what further work might resolve it.
Do not treat missing logs as evidence that a particular route was used.
Likewise, do not imply that uncertainty about entry means the rest of the incident is unproven.
Later account activity, malware execution, persistence or data access may be strongly evidenced even where the initial route remains unknown.
Where current product or vulnerability behaviour matters, record the source relied upon.
Use confidence terms consistently and explain what they mean. Words such as possible, likely or highly likely should reflect the evidence and organisational reporting standard rather than the writer’s instinct.
Operational takeaway¶
Report the initial access route at the level the evidence supports, explain the alternatives and keep uncertainty about entry separate from proven later activity.