Skip to content
Skip to main content
Cyber Incidents & Offender Methods Operational Explainer

What evidence may show deliberate disruption?

Deliberate disruption requires evidence that an unauthorised action intentionally made a system or service unavailable, degraded or unsafe. Not every outage during an incident was caused by the offender.

Identify the technical cause

Commands, service stops, lockouts, configuration changes, encryption, deletion, resource exhaustion and remote sessions can link an actor-controlled process to failure. A threat or ransom note may support intent but does not identify which action caused the outage.

Record responder shutdown, isolation and restoration alongside hardware, certificate, capacity and supplier failures. This separates offender effects from containment and unrelated faults.

Map dependencies and operational impact

Selective targeting of identity, virtualisation, communications or management can interrupt many dependent services while affecting few systems directly. Preserve dependency information and distinguish direct technical impact from wider business consequence.

A widespread technical change may have little operational effect, while one disabled critical service can be severe. Report causes and consequences separately and avoid assigning the aggregate outage to one source without evidence.

Key takeaway

Attribute deliberate disruption from specific unauthorised actions and dependencies, separating offender effects from containment, recovery and unrelated failure.

Reference: CIM-181Cyber Incidents & Offender Methods