home  /  causation & exposure  /  breach causation
the chain · cybersecurity incidents

Breach causation.

Not whether the security was weak, but whether this weakness let this attacker in.

begin here

What happened, and when did you learn of it?

Start a conversation with the Incident Concierge, already scoped to breach causation. Pick a starting point, or describe the incident directly.

Incident Conciergebreach causation · orientation, not a security opinion
Tell me what the forensics established about the entry point, and which control is said to have failed. Causation analysis needs both to be specific — without the path there is nothing to test against.

Establishing that an organization's security fell short is a standard-of-care finding. Establishing that the shortfall caused this intrusion is a separate exercise, and it is where a surprising number of otherwise strong cases become soft. The analysis is counterfactual: had the missing control been present, would this attack path have been closed? Answering it requires the attack path to be known in enough detail to test — initial access vector, the specific vulnerability or credential used, the movement that followed — which brings the whole thing back to whether the forensic evidence was preserved. Where the path is well evidenced, causation is often straightforward in both directions. Where it is not, both sides are reduced to arguing from the general adequacy of the program, which is a much weaker form of the argument.

mechanisms

Testing the counterfactual.

The question is always specific: which control, against which step.

The actual entry point

Which vector was used. Without this, counterfactual analysis is speculation.

The control alleged missing

Named specifically, not "inadequate security". Generality defeats the analysis.

Would it have closed this path

The core question, tested against the evidenced path rather than in the abstract.

Would it have limited spread

A control that would not have prevented entry may still have contained the damage.

Alternative paths

Whether the attacker would simply have used another route. The strongest defense argument.

Detection timing

Whether better monitoring would have shortened dwell time, which affects scope rather than occurrence.

methodology

What the evidence shows — and what we examine.

How causation is tested.

Start from the evidenced pathCausation analysis without a known attack path is assertion in both directions.
Name the control preciselyWhich control, at which step. "Better security" cannot be tested.
Separate prevention from limitationA control may not have stopped entry while substantially reducing what was reached.
Test the alternative-path defenseWhether the attacker demonstrably had another route, or only theoretically.
what's at stake

What causation decides.

Whether a standard-of-care finding actually converts into liability.

whether the breach of duty matters prevention versus limitation of harm apportionment among causes what forensic evidence is essential which expertise the matter needs the scale of provable consequence

"They would have got in anyway" is testable, not rhetorical.

It is a real argument when the attacker demonstrably had other routes available, and a weak one when the evidenced path ran straight through the missing control. The distinction is in the forensic record, which is another reason preservation decides so much.

common questions

Breach causation — practical questions.

What if the entry point was never established?

Then causation becomes considerably harder for the plaintiff and the case shifts onto weaker ground for everyone. Without a known attack path there is no counterfactual to test, and the argument degenerates into competing generalisations about whether the program was adequate overall. Some plaintiffs argue that the failure to determine the entry point is itself evidence of inadequate monitoring and response — which is a real argument on adequacy, though a different one from causation. It is another reason the preservation question decides more than it appears to.

Does a control have to prevent the breach to matter?

No, and treating prevention as the only relevant question loses a lot of ground unnecessarily. Segmentation may not stop an intruder entering but may confine them to one subnet holding nothing sensitive. Monitoring may not prevent entry but may cut dwell time from months to hours, which changes what was reached. Tested backups do not prevent ransomware but change whether the organization pays. Each supports a causation argument about the extent of harm rather than its occurrence, and extent is frequently where the money is.

How is causation handled when several failures contributed?

It usually is several, and the sequence matters more than the count. Real incidents chain — a phishing email, then a credential without MFA, then flat network architecture, then absent monitoring — and each link is a separate control and sometimes a separate responsible party, including vendors. The productive analysis maps the chain and asks which links were load-bearing: which failures were necessary to the outcome, and which merely made it easier. That mapping also drives apportionment between defendants.

Where does technical causation stop?

At the point where data left the environment. Everything after that — whether the data was used, by whom, to what effect, and what the resulting loss is worth — moves out of forensics and into other disciplines. What was done with the data is often unknowable; what the loss is worth is a damages question with its own methodologies and its own admissibility record, and it belongs with the Economic Damages Institute. Being explicit about that handoff is more useful than an expert stretching past their evidence.

related

Related specialization areas & resources.

Test the counterfactual specifically.

Describe the attack path and the control at issue. The Institute will help you frame the question.

incident conciergeorientation · not a security opinion
Tell me what the forensics established about the entry point, and which control is said to have failed. Causation analysis needs both to be specific — without the path there is nothing to test against.