skip to content

What does declaring a security incident commit an organisation to that continuing to investigate does not?

level: juniorimportance: should knowfreq 58%

answer

  1. the word is not free
  2. preserve instead of remediate
  3. the policy has a notice clause
  4. counsel before the first written report
  5. declaration is what grants disconnect authority

basics

~20 s

Declaring turns an open investigation into a formal intrusion response: evidence must be preserved rather than remediated away, the cyber insurer normally has to be notified, the work moves under legal counsel, and named people gain authority to disconnect systems.

solid answer

~50 s

Investigating is cheap and reversible; declaring is neither, and the obligations it triggers mostly live outside the SOC. **Preservation**: from the declaration onward you are expected to image, snapshot and hold logs rather than reimage a host and move on. **Insurance**: most cyber policies require prompt notice of a circumstance, and many require panel counsel and panel forensics vendors, so response spend committed before notice may not be covered. **Privilege**: many organisations route the investigation through counsel so that reports written to advise on legal exposure are harder to compel later; that has to be set up at declaration, not retro-fitted onto a report already written. **Authority**: declaration is usually what lets a duty officer isolate or disconnect a production system without the owning team's agreement. What it does not do is decide whether a regulator or a customer must be told, which is a separate determination made on its own evidence.

go deeper

for a junior

Be ready to name the four things the word triggers: preserve evidence, notify the insurer, involve counsel, and grant response authority. Also say clearly that a declaration is a working belief, not a proven conclusion.

for a middle

Explain the mechanics: what preservation means on a specific host, why notice must precede committed forensics spend under a panel clause, and why privilege has to be arranged at declaration rather than afterwards.

for a senior

Show the judgment under asymmetry. You are expected to argue why a slightly trigger-happy bar beats a cautious one, and to describe the declaration message you would actually send at 02:00 without over-claiming impact.

for a principal

Own the cost side. Be ready to say how many declarations a year your organisation can absorb, how you keep insurer notice cheap enough that nobody avoids it, and how you stop the word being hoarded by one unavailable executive.

## The line you are crossing Every security team runs a stream of open investigations: an alert that has not resolved, a strange authentication, a host somebody wants explained. None of that binds the organisation to anything. **Declaring an intrusion** is the moment a person with authority states that the activity is adversarial and unauthorised, and it converts a technical opinion into an organisational fact. In NIST 800-61 terms this sits at the end of detection and analysis, where analysis produces an incident; in the older PICERL phrasing it is *identification*. Interviewers ask this question because juniors routinely treat the word as a label and are surprised that it costs money. ## What the word actually triggers **Preservation replaces remediation.** Before declaration, an engineer who reimages a suspicious host has cleaned up. After declaration, that same act destroys the only copy of the evidence that would have proved what happened. The expectation flips: snapshot the disk, capture volatile state where you can, freeze log retention on the relevant sources, and stop routine cleanup on anything in scope. Preservation costs almost nothing if you start at hour zero and is impossible to recover if you start at hour forty. **Insurance notice starts.** Cyber policies are written around a duty to notify the insurer promptly once you become aware of a circumstance that may give rise to a claim. Many wordings go further and specify a panel: the counsel firm, the forensics firm, sometimes the ransom negotiator you are permitted to use if you want the costs covered. A team that scrambles its favourite forensics firm at 02:00 without checking the panel clause may be spending money the policy will not reimburse. The correct sequence is notify, confirm the panel position, then commit spend. **The work may move under counsel.** Where an organisation expects litigation or regulatory scrutiny, it commonly has outside counsel direct the investigation so that reports produced to advise on legal exposure attract privilege. Two honest caveats belong in your answer: privilege varies by jurisdiction and is frequently narrower than teams assume, and it protects certain communications and advice-driven reports, never the underlying facts, the raw logs or the business records. It also cannot be bolted on afterwards, which is why the decision belongs at declaration. **Authority is granted.** In most response plans, the declaration is the thing that gives the incident lead or duty officer the standing right to isolate a host, pull an appliance off the internet, or force a credential reset without waiting for the service owner's consent. Outside a declared incident those are requests; inside one they are instructions. ## What declaring is not It is not an accusation and not a conclusion. It is a working determination of reasonable belief, held with the evidence available at the time, and it is normal for scope to grow, shrink, or for the whole thing to be withdrawn. It is not a severity grade either: how bad the intrusion is, judged by what the intruder reached, is a separate call made after the declaration. And it does not by itself start a statutory notification duty. Whether a regulator or a data subject must be told rests on a different evidentiary question about access to protected data, decided on its own timeline. ## The asymmetry, and why a bar exists Over-declaring has real costs: a circumstance on the policy record, drawdown against a retainer, executive attention consumed, and analyst credibility spent. Under-declaring has worse ones: evidence overwritten, an adversary given uncontested days, and later the very awkward question of when you first knew. Because the costs are asymmetric but not zero on either side, mature teams write down an explicit bar and a named person who applies it, rather than leaving the word to whoever happens to be awake. ## What a declaration message contains A good one is short and factual: the artefact that met the bar, the systems and accounts believed in scope right now, what has already been preserved, what the responder is authorised to do next, and who to contact. It deliberately avoids conclusions about attribution, impact or data loss that the evidence does not yet support, because that message will be read later by people deciding what you knew and when.

  • Does declaring mean you have concluded that an attacker succeeded?
    No. It is a working determination of reasonable belief that activity is adversarial and unauthorised, made on the evidence available. Scope routinely grows or shrinks afterwards, and a declaration can be withdrawn if a benign explanation appears. Its job is to authorise response and preservation, not to assert a finding.
  • Why is reimaging the affected host the classic first mistake after a declaration?
    Because it is the instinct that makes an outage go away and an intrusion unprovable. The image, the memory and the local logs are usually the only record of how the intruder got in and what they took; once rebuilt, you cannot show scope, cannot answer a regulator, and cannot tell whether the persistence you never found is back.
  • Who actually pays for an over-declaration?
    The organisation: a circumstance recorded against the cyber policy, hours drawn down from a counsel or forensics retainer, executives pulled into a bridge overnight, and the security team's credibility the next time it uses the word. Real, but all recoverable, which is why the bar is set to tolerate some over-declaration rather than none.

saying these in an interview costs you the question

  • Treats declaring as a label with no cost or consequence
  • Reimages the affected host first and preserves afterwards
  • Assumes declaring automatically starts a regulator notification duty
  • Engages a favourite forensics firm without checking the policy's panel clause
  • Thinks privilege can be added to a report after it is written

context