home  /  incident response & forensics  /  attribution & scope
the response · cybersecurity incidents

Attribution and scope.

Everyone wants to know who. The case turns on what was reached, and the evidence for that is thinner than people expect.

begin here

What happened, and when did you learn of it?

Start a conversation with the Incident Concierge, already scoped to attribution & scope. Pick a starting point, or describe the incident directly.

Incident Conciergeattribution & scope · orientation, not a security opinion
Tell me what the forensics established about initial access and dwell time, and what telemetry existed for egress. Scope arguments live or die on that last point, so it is worth pinning down early.

Two questions get conflated after an incident and they carry very different evidentiary weight. Attribution — who did this — is the one everyone asks, and honest forensic analysis usually supports statements about tooling, technique and infrastructure rather than the naming of an actor: infrastructure is rented, tools leak and are reused, and misdirection is a standard technique. Scope — what did they actually reach — is the question that drives notification obligations, class definitions, regulatory exposure and damages, and it is genuinely hard. The distinction that causes the most trouble is between access and exfiltration: demonstrating an attacker could reach a database is not the same as demonstrating they took it, and the evidence separating those two frequently does not survive, which leaves organizations notifying on assumption rather than on proof.

mechanisms

What the evidence supports.

Strongest at the top. Attribution sits at the bottom for good reason.

Initial access vector

How they got in. Usually well-evidenced and central to the standard-of-care question.

Dwell time

How long they were present before detection. Drives both scope and adequacy arguments.

Lateral movement

What they reached inside. Evidenced by authentication and network telemetry.

Access to data

Which systems and stores were reachable and accessed. Often provable.

Actual exfiltration

Whether data left. Much harder, and frequently the decisive gap in the record.

Actor identity

Technique and infrastructure, yes. A named actor, rarely with confidence.

methodology

What the evidence shows — and what we examine.

How scope is established.

Reconstruct the timelineInitial access forward, so dwell time and reach are bounded by evidence rather than assumption.
Trace lateral movementAuthentication records and network telemetry, to establish what was actually reachable.
Separate access from exfiltrationExplicitly, because the two get merged and they carry very different consequences.
State the uncertaintyWhere the record cannot answer a question, saying so is more defensible than inference.
what's at stake

What scope decides.

Notification, class size, regulatory exposure and the size of the claim.

who must be notified the size of any class regulatory exposure the scale of the claim coverage position whether remediation was complete

Access is not exfiltration, and the record often cannot tell them apart.

Showing an attacker could reach a database is not showing they took it. When the telemetry that would distinguish them has aged out, organizations end up notifying on the conservative assumption — which is prudent, and expensive.

common questions

Attribution and scope — practical questions.

Can you prove nothing was taken?

Almost never, and that asymmetry costs organizations a great deal. Proving a negative requires evidence that no exfiltration occurred, which in practice means complete egress monitoring for the entire dwell period — something most environments do not have. The honest position is usually that no evidence of exfiltration was found, which is a weaker statement and frequently the true one. Whether that supports a decision not to notify is a legal question, and it is exactly the point at which conservative assumptions start driving very large costs.

How reliable is threat-actor attribution?

Reliable about behavior, unreliable about identity. Forensic evidence supports strong statements that activity is consistent with a known toolset, technique or infrastructure pattern, and that is genuinely useful for understanding what the attacker was likely after. Moving from there to naming a group requires intelligence that most incidents do not generate, and confident naming should be treated skeptically. Attribution is also less load-bearing in civil matters than it feels: what drives the case is what was reached and whether the safeguards were reasonable.

Why does dwell time matter so much?

Because it bounds everything else. A long dwell time expands the range of what could have been reached, weakens any argument that the compromise was contained, and is itself evidence about the adequacy of monitoring — an intruder present for months without detection is a finding about the detection capability, not only about the intruder. It also tends to be the most quotable number in the matter, which means it is worth establishing carefully rather than accepting a first estimate.

What if the logs cannot answer the question?

Then the analysis says so, and resisting the temptation to fill the gap is what separates a credible expert from an attackable one. Gaps in the record are ordinary — retention expires, telemetry was never collected, a host was reimaged — and an opinion that acknowledges them while stating what the surviving evidence does support will withstand cross-examination. One that infers exfiltration from access, or completeness from absence of evidence, will not. It is also worth being direct about the consequence: gaps generally push decisions toward the conservative and costly assumption.

related

Related specialization areas & resources.

Establish scope before you assume it.

Describe what the forensics found. The Institute will help you see what the evidence supports.

incident conciergeorientation · not a security opinion
Tell me what the forensics established about initial access and dwell time, and what telemetry existed for egress. Scope arguments live or die on that last point, so it is worth pinning down early.