The attacker can prove what they took. You can only prove what you logged. - Johannes Stillig
The attacker can prove what they took. You can only prove what you logged.
29 Jul 2026<br>11 min
I'm Johannes. I have spent eighteen years on the response side of security, and the thing I keep returning to is that a control is only worth what you can prove about it afterwards.
In roughly one breach in five, the first person to tell the world what happened to your customers' data is the person who took it.
IBM's numbers this year: 50% of breaches are found by the organisation's own security teams, 31% by a benign third party, and 19% are disclosed by the attacker. That last group is the one worth sitting with. It means the opening account of the incident is written by someone with a motive, a timeline that suits them, and a folder of your data to quote from.
Everyone prepares for the regulator. The regulator gives you a private conversation, a phased process, and lawyers on both sides who understand that facts take time. That is the easy adversary. Nothing about the public version of a breach works like that.
Here is the asymmetry nobody plans for, and it is not about security at all.
The attacker can prove what they took. They have it. They can post a thousand records and let anyone verify the claim in an afternoon.
You can only prove what you logged.
If you did not log it, you cannot rebut them. You can deny, and a denial without evidence is a press release. Their claim comes with a sample. Yours comes with a spokesperson. There is no contest.
The ninety minute silence
The shape of a bad breach is always the same and it is not the shape people expect.
Nobody argues about whether to contain. That part is well drilled and everybody knows their lines. The hard question lands about ninety minutes in, usually from the general counsel or the comms lead, and it is always a version of: what did they actually take?
Then the room goes quiet.
Not because anybody is incompetent. Because answering it requires knowing which systems were touched, what lived on them, which records were read rather than merely reachable, and whether anything left the estate. That is four separate evidence problems, and every one of them is answerable only from data that somebody chose to collect, at a retention period somebody chose, long before there was a question.
I have sat in that silence more than once. It is the most expensive thirty seconds of the whole incident, because everything public downstream is decided in it.
Absence of evidence is not neutral
This is the part I would most like people to take away, because it runs against instinct.
Security teams treat "we have not found evidence of exfiltration" as a neutral, honest, cautious statement. It is not neutral. In public it reads as "we do not know," and into that gap flows the worst plausible number.
Once a figure is circulating, you inherit it. If a leak site claims four million records and you cannot say otherwise with evidence, four million is the number in every article, every customer email, every board pack, and every counterparty's risk review for the next two years. You can correct it later. Corrections never travel as far as the original, and the people who mattered most have already updated.
So the practical stakes are not the fine. They are these, and all of them are decided by whether you can produce a credible, specific, fast answer:
Whether you notify everyone or the affected. One of those is survivable.
Whether your largest customers hear a number from you or read one somewhere else.
Whether "we contained it in days and here is exactly what was in scope" is available to you as a sentence at all.
For a period during my career I ran a cyber practice inside a law firm, acting for people whose exposure was reputational long before it was regulatory. That work changes how you see this. For those clients the fine was a rounding error. The story was the whole event, and the story was decided almost entirely by who could evidence their version first.
The clock you are actually racing
The 172 is the number that makes this hard.
In the best measured case this year, where an organisation's own security team found the breach itself, it took 172 days to identify and another 52 to contain. That is the good outcome. Third party and supply chain compromise took the longest of anything: 196 days to identify, 71 to contain, 267 in total, on data that is yours and logs that belong to somebody else.
So the attacker has had most of a year inside an estate you were not watching closely enough to notice, and you have somewhere between hours and a couple of days before the public version sets.
You are not racing the regulator's clock. You are racing the first article.
And it does not end quickly. 86% of breached organisations reported operational disruption. 65% said they had not fully recovered. 45% raised prices afterwards, about a third of them by more than...