How should uncertain findings be expressed?¶
Express an uncertain finding in language that matches the evidence, then explain what supports it, what is missing and which credible alternatives remain. Clear qualification makes a conclusion more accurate and testable; it does not make the investigation weaker.
Technical terminology should describe the event, not disguise uncertainty about what it means.
Match the statement to the evidence¶
Terms such as confirmed, strongly supported, supported, consistent with, possible, not established and contradicted can help distinguish levels of confidence when their meaning is used consistently.
For example, network records may confirm repeated outbound connections. Interactive command and control may be supported by their content and timing. The identity of the operator may remain unestablished. Those propositions should not inherit one confidence level simply because they appear in the same sequence.
For each material inference, identify:
- the records and reasoning that support it;
- assumptions on which it depends;
- missing or conflicting evidence;
- credible alternative explanations; and
- evidence that could resolve the difference.
Put limitations beside the conclusion¶
Do not confine central uncertainty to a footnote. If a finding depends on incomplete logs, provider interpretation or an inferred link, say so where the finding is stated and in any summary that relies on it.
Consistency matters, but confidence can change when new evidence arrives. Preserve the date and reasoning for significant assessments so a later revision can be understood. Avoid unsupported words such as “clearly” and avoid listing every theoretical possibility as equally plausible; identify the explanation best supported by the available evidence.
Key takeaway
State the strongest conclusion the evidence supports, place material limits and alternatives alongside it, and preserve the reasoning behind any confidence assessment.