Breakpoint Blog

Benjamin Mossé • 24 Sep 2025

Dimensioning Cyber Incidents: Is? Is Not? Why Not?

Got a compromised system? Don’t Panic. Investigate.

The first move in incident response isn’t action - it’s understanding.

I use a simple framework that’s helped me resolve over 100 cyber incidents with clarity and speed. It’s called:

“Is? Is Not? Why Not?” (IINWN)

Here’s how it works:

Create a table with 4 columns: **Dimension Is Is Not Why Not**

Then work through the dimensions that matter in every incident:

Object(s) impacted
Type of incident
Users impacted
User locations
Incident location
Time and date
Pattern of occurrence
Unique attributes

Now fill in only what you know for certain. No assumptions. No guesses.

Everything you don’t know becomes your marching orders for digital forensics. That’s your gap list.

Keep going until every “Why Not” has evidence behind it—logs, memory captures, host-based artifacts.

When done right, you’ll not only understand what happened—you’ll eliminate uncertainty.

And that’s how you respond with precision, speed, contain the incident, and recover with confidence.

Recent Blog Posts

Benjamin Mossé • 16 Oct 2025

Manage Legacy IT Risks

The 2024-25 ASD Threat Report highlights legacy IT as one of the top risks facing organizations t...
Benjamin Mossé • 15 Oct 2025

Restrict Administrative Privileges

Restricting admin privileges is one of the most common recommendations in cybersecurity. And like...
Benjamin Mossé • 14 Oct 2025

Action <> Reaction

Last month, I was speaking with a security team that had rolled out Security Awareness Training. ...