Skip to content
Skip to main content
Cyber Incidents & Offender Methods Foundation Explainer

What is initial access?

Initial access is the first supported foothold an offender gains in an account, device, application or network. It is not necessarily the first suspicious event detected: access may have existed quietly before visible activity began.

Possible routes include stolen credentials, phishing, a malicious file, remote access, exploitation of a public service, supplier compromise or physical access. More than one route may be available in the same incident.

Earliest detected activityFirst thing your records happened to showMay occur after access was already established.
Initial accessEarliest supported footholdThe account, device, service or permission that first gave useful unauthorised access.

Define the foothold

State what access means in the case. An authenticated account, executed code, controlled device, exploited service, granted application permission and accessed dataset are different footholds with different records and consequences.

Authentication, email, web-server, endpoint, cloud and provider records can establish the earliest evidenced event. Trace backwards from later persistence or movement, but do not assume those later mechanisms reveal the original entry route.

Report the boundary of the evidence

Distinguish the earliest event found from the earliest event that could have occurred. Retention gaps or missing devices may prevent the true point of entry being recovered. If several routes remain plausible, explain their evidential support and what would distinguish them.

The initial route matters because it identifies other accounts and systems that may share the exposure. A compromised supplier account, for example, creates a different affected population from one exploited endpoint.

Key takeaway

Identify and define the earliest supported foothold; do not relabel the first detected activity as initial access without evidence of how access began.

Reference: CIM-092Cyber Incidents & Offender Methods