How should uncertainty about the initial access route be reported?¶
State the earliest confirmed foothold, the route or routes supported by the evidence, and what prevents a firmer conclusion. Technical confidence should never exceed the surviving records.
Separate observation from inference¶
Phrases such as the earliest confirmed unauthorised event was or the records are consistent with show the status of a conclusion. Avoid saying an offender entered through a vulnerability when the evidence proves only that the vulnerability existed.
Explain the supporting events, missing records, alternatives and contradictions. Missing logs are not positive evidence for one route, particularly where retention or logging coverage is unknown.
If the organisation uses confidence terms such as likely, define and apply them consistently. The assessment should arise from evidential weight, not the writer's instinct or a desire for one narrative.
Preserve what is known later¶
An unknown point of entry can coexist with well-supported malware execution, account activity, persistence or data access. Keep uncertainty about entry local to that proposition rather than allowing it to weaken unrelated findings.
Identify focused further work that could resolve the route, such as provider logs or historical configuration. If no surviving source can answer it, say so directly.
Key takeaway
Report the entry route at its actual confidence level, explain the evidential basis and alternatives, and keep that uncertainty separate from proven later activity.