Skip to content
Skip to main content
Cyber Incidents & Offender Methods Foundation Explainer

Does an employee account identify the employee who acted?

No. An employee account identifies a technical identity used by a session. It may be shared, compromised, automated, remotely controlled, left signed in or used after employment ended.

Reconstruct device and session control

Preserve authentication method, multi-factor event, device and session IDs, remote-access route, command or browser history and physical and communication context. Compare the activity with the employee's normal device, role and work pattern.

Badge data shows building access, not use of a particular device. Remote work can explain digital activity without physical presence, so several indirect indicators should not be presented as one decisive fact.

Test alternative controllers

Examine whether the normal device had malware, token theft or unusual remote sessions. An employee's denial is not proof of compromise, and a successful login is not proof of knowing action.

Combine independent technical and contextual evidence before personal attribution, recording unresolved conflicts rather than resolving them through account ownership.

Key takeaway

Treat employee-account activity as technical attribution and require corroborated device, session and contextual evidence before identifying the person who acted.

Reference: CIM-233Cyber Incidents & Offender Methods