skip to content

Your earliest logs aged out at 90 days and an executive wants one intrusion start date — what do you commit to?

level: principalimportance: should knowfreq 42%

answer

  1. two bounds, never one date
  2. no records retained is not no activity
  3. coverage argument before any negative claim
  4. worst-case assumption needs a named owner
  5. one agreed wording, used everywhere

basics

~20 s

Commit to what the evidence supports: earliest observed activity with its date and citation, plus an explicit statement that the window before the retention edge cannot be assessed. Never convert an absence of records into a start date.

solid answer

~40 s

Give three separate statements rather than one date. First, the earliest observed activity attributed to the intrusion, with the record behind it. Second, the evidence floor: these sources retain ninety days, so nothing before that point can be assessed either way — no records is not no activity. Third, what remains unestablished, named plainly. Then turn the unknown into a decision instead of leaving it as a gap: agree with counsel and the executive that downstream work runs on the worst case, that credentials and secrets in scope are treated as exposed from the floor, and record who accepted that. Name what would change the answer — longer-lived sources such as artefact metadata, ticketing, backups, on-disk host artefacts, supplier records — and say the claim reopens if any of them land.

go deeper

for a junior

Know that a missing log window means unknown, not clear. An intrusion can never be dated from records that no longer exist.

for a middle

Be ready to give earliest observed activity and the evidence floor as two separate claims, each with the source behind it.

for a senior

Show the coverage argument required before asserting that nothing happened earlier, and name where longer-lived evidence might still survive.

for a principal

Own the wording that counsel and executives will quote, and make sure the worst-case assumption filling the gap is explicitly accepted by a named decision-maker.

## Why the pressure exists, and why you cannot satisfy it A single start date makes everything downstream easy: reset scope, briefing lines, the shape of what gets told to whom. That is exactly why it is asked for, and it is why the date, once given, will be quoted back in rooms you are not in. If the evidence does not support one, supplying it is not helpfulness — it is manufacturing a fact that the next person to test it will break, taking every decision built on it down with it. ## The three statements that replace the date **1. Earliest observed activity.** A fact: a date, an entity, and the record that shows it. This is an **upper bound** on when the intrusion started; the real start is at or before it. **2. The evidence floor.** These sources are retained for ninety days; therefore no assertion, positive or negative, can be made about the window before that point from them. State the floor as a date, not as a policy. **3. What is not established.** Initial access, the entry path, whether activity preceded the floor. Named plainly rather than left as an absence the reader fills in themselves. There is no lower bound. That asymmetry is the whole answer, and stating it out loud is what separates a defensible report from a confident one. ## The epistemics you have to be able to defend Absence of evidence in a window **where nothing was retained** carries no information at all. Absence of evidence in a window that **was** covered is weak positive evidence, and only as strong as a **coverage argument**: that a source capable of recording the behaviour existed on the relevant assets, was healthy for the whole window with no collection gaps, was retained, and was actually searched with a query that would have matched. Any of those four missing and the negative claim is not available to you. This is the part executives find least intuitive and the part a regulator, a customer's assessor or opposing counsel will press hardest. Being able to state it in two sentences without hedging is the skill. ## Turning the unknown into a decision An unbounded window is not a reason to stop; it is a reason to decide what the organisation assumes. That decision is not yours alone, and it should not be left implicit: - **State the assumption**: everything reachable with what was exposed at the earliest observed activity is treated as exposed from the evidence floor. - **Drive scope from the assumption, not the observation**: the credential reset, secret rotation and eradication list follow the worst case, because the observed date is only an upper bound. - **Get it accepted by a named person** and record it. 'We assumed the worst case' with no owner becomes 'security decided' when it is expensive, and 'nobody told us' when it is wrong. - **List what would change it**: evidence kept for other reasons often outlives security logging — build artefacts and their metadata, package and registry pull records, ticketing and change records, backups and their catalogues, on-disk host artefacts, mail archives, supplier and third-party records. Work them or record why you did not. ## Language discipline Agree one wording with counsel and use it verbatim everywhere: report, briefings, anything issued. The failure mode is a hard bound in the written report and a softer verbal date in a meeting — the two will meet, and the written one will look like a walk-back. If you are asked in a corridor when it started, the answer is the same sentence you wrote down. And write the reopening condition into the report itself: if evidence pushing earlier appears, the scope statement is revised. That converts a future correction into something the report already anticipated. ## The result is legitimate Some intrusions are never fully dated. The picture stops at the retention edge and the report says so, with the bound, the citations and the assumption everyone is working to. That report survives contact with a challenge. The one carrying an invented start date does not, and the damage when it fails is not confined to the date — it puts every other claim in the document up for re-argument. The seniority in this question is not analytical. No further analysis produces the date. It is deciding what the organisation commits to in writing, holding that line against pressure from people who outrank you, and making sure the assumption that fills the gap is owned by someone with the authority to own it.

  • What would let you claim that nothing happened before a given date?
    A coverage argument: a source that would have recorded the behaviour existed on the relevant assets, was healthy across the whole window with no collection gaps, was retained, and was actually searched with a query that would have matched. Even then the claim is bounded to that behaviour and that source, and you say so.
  • Which evidence commonly outlives the security log window?
    Things kept for other reasons: build artefacts and their metadata, package and registry pull records, ticketing and change records, backups and their catalogues, on-disk host artefacts, mail archives, and supplier or third-party records. Coverage is patchy and none of it was designed for this, but it can sometimes push the floor back.
  • The executive says the report looks weak without a date. How do you answer?
    A report that states a bound and cites its evidence survives being tested; one with an invented date collapses the first time somebody checks it, and takes every other claim with it. Then offer the decision they actually need: what assumption the organisation runs on, recorded as their decision rather than a security guess.

saying these in an interview costs you the question

  • Supplies a single start date the evidence cannot support
  • Reads no logs as no activity
  • Treats the retention edge as the intrusion's start date
  • Makes a negative claim without showing the source was healthy and searched
  • Leaves the worst-case assumption unowned and unrecorded
  • Gives a softer verbal date than the written report states

context