Proving Non-Impact. How to make the most effective use of… | by Matt Linton | Jun, 2024 | Medium
How to make the most effective use of cybersecurity investigators, and when ineffectively using them is still worth it As members of a DFIR team, our job is to perform investigations. Whether we’re in-house dedicated teams or are serving customers as consultants, we are hired to find answers to essential questions. However, there can be significant limitations on when and how much it costs to answer these questions. Typically, investigators are asked to prove that something did happen or to analyze the cause behind a known event. But increasingly, as DFIR teams are brought into broader risk-management needs, we’re asked to prove whether anything happened at all. In this post, I want to explore the difference between “proving a positive” and “proving a negative” because the latter is often a source of incredible frustration and wasted effort by DFIR teams. Note: A friend who reviewed this post mentioned that nothing in forensics can be “proven” with the same finality as in mathematics.
How to make the most effective use of cybersecurity investigators, and when ineffectively using them is still worth it As members of a DFIR team, our job is to perform investigations. Whether we’re in-house dedicated teams or are serving customers as consultants, we are hired to find answers to essential questions. However, there can be significant limitations on when and how much it costs to answer these questions. Typically, investigators are asked to prove that something did happen or to analyze the cause behind a known event. But increasingly, as DFIR teams are brought into broader risk-ma
Explore this link on the map →