home  /  insights  /  proving-a-control-failure-caused-the-breach
Causation & Exposure

How do you prove a specific control failure caused a specific breach?

By reconstructing the intrusion chain link by link and asking, at the link in dispute, whether the missing control would actually have stopped it. A list of deficiencies is not a causal argument.

September 4, 2026 · 5 min read

The short answer

By establishing the actual intrusion chain from the evidence, identifying where in that chain the disputed control sits, and then asking whether the control — properly implemented — would have prevented or detected the step it governs. A catalog of control deficiencies is not a causal argument, and the gap between the two is where a large share of breach claims and breach defenses are actually decided.

What this article establishes

  • A control deficiency and a cause of the breach are different findings, and only the second connects to liability.
  • The chain has to be reconstructed from evidence, not assumed from the vulnerability that is easiest to prove.
  • The counterfactual question is whether the control would have stopped this intrusion, not whether it is good practice.
  • Attackers adapt, so a control that closes one path may only have diverted the intrusion to another.

What does an intrusion chain look like when it is reconstructed properly?

A sequence of discrete steps, each of which has to be evidenced separately. Typically: initial access by some specific means; establishment of persistence; escalation of privilege; movement through the network to systems of interest; discovery and staging of data; and finally exfiltration or encryption. Each step leaves different artefacts in different places, and each is governed by different controls.

Reconstructing that sequence is the foundation of any causal opinion, and it is ordinary forensic work — logs, images, telemetry, timeline analysis. What it is not is an inference from the vulnerability that happens to be best documented. A commonly seen error is to identify a serious unpatched flaw, note that it could have permitted access, and treat that as the finding, when the evidence in fact shows the attacker entered through valid stolen credentials and never touched the vulnerable system at all.

Why is a list of control deficiencies not enough to establish causation?

Because most organizations have many control deficiencies at any moment, and the overwhelming majority of them play no part in any given incident. An assessment that catalogs twenty findings has established that the security had weaknesses. It has not established that any particular weakness is the one that mattered, and liability generally attaches to the second proposition rather than the first.

The practical test is to take each alleged deficiency and locate it on the reconstructed chain. Does it govern a step the attacker actually took? If the intrusion began with a phishing email against a user with no multi-factor authentication, then an unpatched server elsewhere in the estate is a genuine deficiency and a causal irrelevance. Keeping those two categories separate is much of what an independent analysis contributes, because advocates on both sides have an incentive to merge them.

How is the counterfactual question handled — would the control have stopped it?

By asking what the properly implemented control would have done against the specific technique used, which is a narrower and more answerable question than whether the control is good practice. Multi-factor authentication on the compromised path would have defeated a credential-stuffing attack using a password from an unrelated breach. It would not necessarily have defeated a real-time phishing proxy designed to capture and relay the second factor, and the distinction is evidentiary rather than rhetorical.

Detective controls need a further step. Establishing that monitoring would have generated an alert is not sufficient on its own; the analysis has to address whether the alert would have been seen and acted on given the organization’s actual alert volume and staffing at the time. An organization already receiving thousands of unreviewed alerts a day does not obviously benefit from one more, and a candid analysis says so — in whichever direction it cuts.

What is the alternative-path problem in breach causation?

It is the defense argument that closing the disputed gap would have changed the route rather than the outcome, because attackers adapt when they meet resistance. Where an intrusion shows the actor attempting several techniques, abandoning what did not work and continuing, there is real evidence that the campaign was adaptive and would likely have found another way in.

It is a legitimate argument and it is frequently overstated. It carries most weight against a determined, well-resourced actor demonstrably working through a defended environment, and least weight against an opportunistic intrusion that took the only easy path available and would plausibly have moved on to a softer target. Which of those the evidence actually shows is a question of fact, and it usually turns on how much of the attacker’s failed activity was captured — which returns to whether the logs survived.

How does the evidence available shape what can honestly be concluded?

Decisively, and an analysis that does not say so is not being straight. Where memory was captured, images were taken before remediation and logs covered the full dwell time, the chain can often be established step by step with high confidence. Where the initial access period fell outside log retention and the relevant hosts were rebuilt, parts of the chain may be genuinely undeterminable — and the correct expert answer is that they cannot be determined, not a plausible narrative presented with more confidence than the record supports.

This is where preservation and causation meet, and why the Institute puts preservation first on the site. The decisions made in the first hours, described in what disappears first after a breach, set the ceiling on what any expert can later establish for either side. Admissibility standards require an opinion to rest on sufficient facts and a reliable application of method, and an opinion outrunning its evidentiary basis is vulnerable for exactly that reason.

Does establishing causation settle what the breach is worth?

No, and the two questions belong to different disciplines. This Institute covers the technical chain — whether the control failure produced the intrusion, and what data was actually exposed as a result. What that exposure is worth involves entirely separate methodologies, its own admissibility record, and its own body of expert practice.

Quantification belongs to our Economic Damages Institute, which covers class-wide models and the measures of loss properly. Matters needing both are usually two engagements and often two experts, and it is considerably cheaper to know that at the outset than to discover it during expert disclosure.

For informational purposes only. Not legal advice, not a security assessment, and not an opinion on whether any organization’s security was reasonable.

Related

The practice area

incident conciergeorientation · not a security opinion
Happy to. Tell me roughly what happened and when it was discovered — and whether anything has been rebooted, reimaged or restored since. That last answer decides what evidence is still recoverable, so it is worth establishing before anything else.