Skip to content
Skip to main content
Cyber Incidents & Offender Methods Operational Explainer

How should uncertainty about the initial access route be reported?

State the earliest confirmed foothold, the route or routes supported by the evidence, and what prevents a firmer conclusion. Technical confidence should never exceed the surviving records.

Separate observation from inference

Phrases such as the earliest confirmed unauthorised event was or the records are consistent with show the status of a conclusion. Avoid saying an offender entered through a vulnerability when the evidence proves only that the vulnerability existed.

Explain the supporting events, missing records, alternatives and contradictions. Missing logs are not positive evidence for one route, particularly where retention or logging coverage is unknown.

If the organisation uses confidence terms such as likely, define and apply them consistently. The assessment should arise from evidential weight, not the writer's instinct or a desire for one narrative.

Preserve what is known later

An unknown point of entry can coexist with well-supported malware execution, account activity, persistence or data access. Keep uncertainty about entry local to that proposition rather than allowing it to weaken unrelated findings.

Identify focused further work that could resolve the route, such as provider logs or historical configuration. If no surviving source can answer it, say so directly.

Key takeaway

Report the entry route at its actual confidence level, explain the evidential basis and alternatives, and keep that uncertainty separate from proven later activity.

Reference: CIM-105Cyber Incidents & Offender Methods