Skip to content
Skip to main content
Cyber Incidents & Offender Methods Operational Explainer

Who controls the affected system?

The organisation suffering the incident may not control every system or every useful record.

Cloud services, outsourced IT, security suppliers, identity providers and application vendors can split ownership, administration and evidence across several organisations.

If you send the request to the wrong place, you can lose time — and sometimes the evidence.

Map the control layers

For each important system, identify:

Question Example answer
Who owns or uses the service? Northway Logistics
Who administers the tenant/account? Northway IT
Who hosts the service? Cloud provider
Who manages the endpoints? Outsourced IT supplier
Who holds security telemetry? MDR / EDR provider
Who can authorise collection? System owner / incident lead
Who actually retains the source record? Depends on the event

That map tells you who to contact for each evidence source.

One provider may only hold part of the story

A security supplier may hold alerts and endpoint telemetry.

The application provider may hold the source audit log.

The customer organisation may hold identity and staff records.

The cloud provider may operate the infrastructure but not expose the customer-level event you need.

OrganisationBusiness contextUsers, roles, assets and impact.
IT / tenant adminConfiguration and accessAccounts, devices and administrative state.
Security supplierAlerts and telemetryDetection and endpoint/network observations.
Service providerPlatform recordsApplication, identity or cloud audit evidence.

Control also matters for attribution

An administrator account appearing in a log does not automatically identify the administrator as the user.

The account may have been:

  • shared;
  • automated;
  • compromised;
  • used by a contractor;
  • used through a management platform.

So identify who controlled the relevant session or process at the relevant time.

Get preservation to the right evidence holder quickly

If a cloud tenant owns the audit log, asking the infrastructure provider for the same record may simply result in a referral.

That can cost time.

Before sending an urgent request, work out who actually retains the data you need.

The practical point is: map ownership, administration and evidence retention separately. The affected organisation may be the victim without being the holder of every useful record.

Reference: CIM-008Cyber Incidents & Offender Methods