Has an incident actually occurred, or is it only suspected?¶
Sometimes you know immediately. Sometimes you do not.
An alert, user report or unusual event may be enough to justify urgent action while the investigation is still deciding whether unauthorised activity actually occurred.
The useful approach is to separate the trigger from the evidence that confirms or disproves it.
Start with what caused the concern¶
The incident may have begun with:
- a security alert;
- a user report;
- an unexpected login;
- suspicious software;
- missing data;
- an outage;
- an external notification; or
- unusual network activity.
That is the reason to investigate.
It is not automatically the final conclusion.
Then look for the source evidence¶
Suppose an alert reports an impossible-travel login.
The investigation may then find:
The alert was real. The suspicious interpretation may not survive once the network context is understood.
The reverse can happen too: a modest-looking event may become clearly malicious once other records are joined.
Use clear stages of confidence¶
Useful wording might include:
- suspected — there is a reasonable trigger but little source confirmation yet;
- indicated — several records point in the same direction;
- confirmed — source evidence establishes the relevant incident activity.
Those are not magic legal categories. They are a practical way to stop early assumptions becoming permanent facts.
Preserve while the answer develops¶
Do not wait for absolute certainty before protecting evidence that may disappear.
If sessions, volatile logs or short-retention provider records may matter, preserve them while the incident is being assessed.
What evidence may disappear quickly? deals with that urgency.
Keep protection and reporting separate¶
You can take proportionate protective action while still saying:
“Unauthorised access is suspected and is being assessed.”
That is better than either extreme:
- doing nothing until every detail is proved; or
- calling the incident confirmed before the records support it.
The practical point is: act on reasonable concern, but keep the reporting calibrated to what the evidence has actually established so far.