Handcuffs on Keyboard

On Monday morning, Delta 591 landed in Atlanta with a story attached. Somewhere over the desert on the way back from DEF CON, someone had knocked the cabin off the aircraft Wi-Fi with a deauthentication attack and stood up a rogue network called "Delta WiFi Fast." A passenger reported that the fake network served a phishing page collecting personal credentials and Google logins. The crew, having no vendor to call at 35,000 feet, did the only sensible thing available to them: they turned the Wi-Fi off for about half an hour. On the ground, federal authorities and airport police boarded the aircraft, questioned people and took portable Wi-Fi hardware away with them (CyberScoop, BleepingComputer).

Nobody on that aircraft asked Boeing for a better mousetrap. Nobody proposed an inflight SOC. The crew contained the incident and then handed the matter to police, which is what human beings have done about crime for as long as there have been police. It took a cabin crew roughly 30 minutes to do what our craft has failed to do in 30 years.

You can't deter a ghost

I posted about this and Gopal Padinjaruveetil wrote a long, careful response that I have been chewing on ever since. His title, borrowed from Kevin Mitnick, was You Can't Deter a Ghost. Raman PK's earlier framing in the same thread put it just as sharply: the patch will ship long before the verdict does.

Gopal's argument, stated as strongly as I can state it: attribution is the precondition for deterrence, not the other way around. Deterrence theory assumes a stable, identifiable actor who fears consequences. The infrastructure we built 35 years ago optimised for connectivity, not accountability. Identity, liability, traceability and observability were bolted on later, if at all. We then built a financial rail (cryptocurrency) on a deliberately non-attributable architecture and acted surprised when it became the payment channel for extortion. And now we are about to multiply the problem with autonomous agents that spin up, act and disappear inside a few seconds, with no clean audit trail of which agent did what on whose authority. Real carbon and silicon identity has to come before deterrence, he says. You cannot deter a ghost.

That is a good argument. Parts of it are simply correct, and the agentic-identity warning at the end is the part I think our craft is least prepared for. It also credits the criminology properly, which most rebuttals to my 2021 Handcuffs Over AI piece do not bother to do.

Here's the thing, though. The ghost is not a property of the physics. The ghost is a property of our filing cabinet.

Attribution is a police power, and we keep pretending it isn't

I have spent 20 years in this craft and I have never once attributed a crime. Not properly. Not in the way that word means to a prosecutor. I have written reports that named an actor group, mapped infrastructure, matched TTPs and produced a confident-sounding paragraph. That is not attribution. That is inference, dressed for a board meeting.

Attribution in the sense that matters (this human being, in this place, did this thing, and here is the evidence a jury can weigh) requires legal process. Subpoenas. Search warrants. Mutual legal assistance. Compelled records from registrars, hosts, exchanges and banks. Custodial interviews. The ability to knock on a door. No vendor has those powers, and neither does any CISO, any MSSP or any threat-intel team. It is not that we are bad at attribution. It is that attribution is not a thing we are permitted to do.

Which is exactly how it works for every other crime. Homicide is not attributed by the coroner, the locksmith, or the company that made the security camera. It is attributed by detectives who can compel things. The coroner's job is to produce evidence of a quality that lets the detective do theirs, and nobody in forensic pathology thinks their inability to arrest people means murder is undeterrable.

Somewhere along the way, our craft decided that the fact we cannot attribute means attribution cannot happen. That is the delusion. It is an urban legend with a 30-year run, and I have heard it repeated by people far smarter than me as though it were physics.

What the research actually says

The criminology on deterrence is not ambiguous and it is not new. The National Institute of Justice summarised it in 2016 in a short paper called Five Things About Deterrence, drawing on Daniel Nagin's 2013 essay. Point one: the certainty of being caught is a vastly more powerful deterrent than the punishment. Point two: prison is not much of a deterrent. Point four: increasing severity does very little. Point three is the one our craft should have tattooed somewhere visible: police deter crime by increasing the perception that offenders will be caught.

Perception. Deterrence is a psychological state in the mind of the offender, not a property of the statute book. Which is why the second finding matters so much.

Deterrence has been demonstrated experimentally inside computer systems. In 2014, David Maimon and colleagues published two honeypot experiments in Criminology (abstract via OJP). They stood up 86 target computers in the first experiment and 502 in the second, and observed 1,058 and 3,768 trespassing incidents respectively. Half the machines displayed a warning banner once an intruder was inside. The banner did not stop intrusions and did not reduce how often they happened. It significantly reduced how long the intruder stayed. A block of text. No handcuffs, no jurisdiction, no capability to do anything at all. Just a signal that someone might be watching, and measurable behaviour change on the other end of the wire.

Scale that up and you get the booter study. In 2025, Anh Vu, John Kristoff, Ben Collier, Richard Clayton, Daniel Thomas and Alice Hutchings published Assessing the Aftermath at USENIX Security, measuring the coordinated international takedown of DDoS-for-hire services. The December 2022 wave seized 49 booter domains. Global DDoS attack volume fell 20% to 40%, with a statistically significant effect on the UDP-based attacks that booters are known for. Domains that came back (most did, within a day or two) struggled to attract anyone, losing 80% to 90% of their traffic. Underground chat showed users and operators recalculating their safety, and some leaving.

And now the part I have to include, because a post about evidentiary honesty cannot cherry-pick. The effect decayed. The market proved resilient, the second wave in May 2023 had minimal measurable impact, and the aggregate suppression lasted about six weeks. One big case is not a strategy. Sustained certainty is the strategy, and sustained certainty is a volume problem, which brings us back to why almost nothing gets reported.

The numbers that should embarrass all of us

The last serious attempt to measure the cyber enforcement rate was Third Way's To Catch a Hacker in 2018. Their estimate: roughly three arrests per 1,000 reported incidents, an enforcement rate of about 0.3%. Adjust for the incidents nobody reports and the effective rate may be nearer 0.05%. Their companion state-level report adds the other half of the equation: only about one in six cybercrimes gets reported at all.

Hold that next to the crime types we supposedly cannot compare ourselves to. US homicide clearance in 2024 ran somewhere around 58% to 61% depending on whose count you use and whether exceptional clearances are included (Murder Accountability Project, CPRC). Property crime clearance sits in the teens. Cybercrime sits at a third of one percent, and I would bet a good dinner that most of that third of a percent is business email compromise where a bank froze a wire.

Meanwhile the volume keeps climbing. The FBI's 2025 Internet Crime Report logged more than a million complaints and about US$20.9 billion in reported losses, up 26% year over year, with cyber-enabled fraud accounting for 45% of complaints and 85% of the money (summary). I wrote about the 2020 edition of that report five years ago and the trend line has done nothing but steepen.

The delusion, measured

Everything above is context. This next study is the thing that made me want to write a whole post instead of a comment.

In March 2025, Sifra Matthijsse, Susanne van 't Hoff-de Goede and Rutger Leukfeldt published To report or not to report in the Journal of Criminal Justice. They surveyed Dutch entrepreneurs: 189 who had been hit by ransomware, and 2,496 who had not, the latter through a vignette experiment describing an attack and asking what they would do.

About 92% of the non-victims said they would contact the police.

About 18% of the actual victims did.

That is a 74-point gap between what we believe about ourselves and what we do. And the reasons the victims gave were not "the police lack jurisdiction" or "the protocols make attribution impossible." They were: we handled it ourselves or with someone we hired, and we believed the police would do nothing about it.

There it is. Not a protocol failure. Not a policy failure. A belief, held in advance of any evidence, that shapes behaviour at the exact moment behaviour matters. Deterrence is psychological in nature, and so is the helplessness that keeps us from producing it.

Three problems, not one

When I sketched this in the LinkedIn thread I said the problem is three-fold. I still think that, and I think the three are causally stacked in a specific order.

One: we believe the criminals are too clever for the police

This is the load-bearing belief, and it is measurably wrong. Rostislav Panev, a LockBit developer, was extradited from Israel. Oleksii Lytvynenko was extradited from Ireland for Conti and pleaded guilty. Karen Vardanyan was extradited from Ukraine for Ryuk. On the money side the record is even less ambiguous: the Justice Department's largest forfeiture in its history is a cyber-fraud case, about 127,271 bitcoin (roughly US$15 billion) tied to the Prince Group compounds in Cambodia. The Secret Service's largest-ever crypto seizure, US$225.3 million, came out of investment-fraud rails. Even the fast, unglamorous stuff works when it is fed quickly: IC3's Recovery Asset Team ran its Financial Fraud Kill Chain on roughly 3,900 incidents in 2025 and froze the majority of the money at issue.

I said in that comment that attribution, extradition and asset seizure are all easier in cybercrime than in physical crime. I want to split that claim into its three parts, because it is not equally true across them. Evidence generation: easier, and it isn't close. A digital crime scene is instrumented by default, timestamped, replicated across several independent custodians and does not degrade. The booter researchers say this outright, that online crime is far more measurable than offline crime. Asset seizure: easier, because a public ledger plus exchange records beats following cash. Extradition: no. Actors sitting inside states that will not extradite are genuinely out of reach, and the honest answer there is sanctions, indictment-in-absentia and patience for a travel mistake. Two out of three, stated plainly, is still a devastating case against learned helplessness.

Two: we are unprepared to work with law enforcement, so contact is expensive and risky for both sides

This is the consequence of believing problem one. If you never expect to hand a case to police, you never build for it, and when you finally do, the encounter is awful for everyone. The agency receives a shoebox: PDF timelines, screenshots of a console, an EDR export in a proprietary format, ticket comments, a Slack thread, and a spreadsheet a contractor made. Nothing hashed. Nothing time-normalised. No custodian. No statement of what was ruled out. Somebody now has to image devices and rebuild your investigation from scratch, and they are already buried. UK inspectors found police overwhelmed on digital forensics with more than 25,000 devices in the queue, and UCL researchers describe months-long backlogs driven in part by how organisations hand things over.

And it is risky in the other direction too, which is the part general counsel understands and the SOC usually does not. Give an agency unfettered access to your environment and you may hand over a separate crime you did not know about, committed by an employee, discoverable and reportable. You may hand over regulated personal data of people who are not parties to anything. You may waive privilege. The rational, defensible response to an all-or-nothing disclosure choice is to choose nothing, which is exactly what 82% of ransomware victims in that Dutch study did.

Three: vendors (me included) do not build tools that produce reportable evidence while protecting privacy

This one is ours. We built SecOps as a branch of IT, so our tools optimise for uptime, mean-time-to-restore and a clean dashboard. We sample. We summarise. We roll up. We drop what did not match a rule. We keep 30 days of the alerts that fired and none of the context that would have made them provable. Then we act astonished that the output is unusable in a courtroom. I have made this argument about detection quality before, in Which Detective Would You Hire? and The Haystack and the Needles, and it lands even harder here. A probabilistic pipeline cannot produce a deterministic exhibit.

Triage is the original sin

Every mature security architecture I have reviewed in the last decade has a triage stage near the front, and everyone treats it as a virtue. Reduce the noise. Keep what matters. Drop the rest.

Consider what triage means at a physical crime scene. It would mean the first officer walking in, deciding which items look interesting, photographing those, and having the rest incinerated before the detective arrives. No defence counsel on earth would let that stand, and no prosecutor would want to try. We would call it spoliation and the case would be over.

That is what we do to digital crime scenes, every day, by design, and we bill for it as efficiency.

The damage is specific, not vague. Sampling destroys completeness, so you cannot testify that the record is a full account. Summarisation destroys the best evidence, leaving a derived artifact whose provenance nobody can trace. Roll-up destroys the timeline resolution that establishes sequence, which is usually how intent is proven. Dropping unmatched data destroys the exculpatory material as well as the incriminating, and an investigator needs both to build a case that survives contact with a defence expert. And a retention window tuned to storage cost destroys everything, quietly, on a schedule, long before a case would come to court.

You cannot triage first and prosecute later. The order does not commute. This is the same argument I have been making about actuarial guesswork in Lava & Cyber Insurance and about who actually pays for all this in Profit and Loss (PNL) of Cyber Security. If your pipeline is lossy, every downstream claim you make is a guess wearing a suit.

What a Work Collection is

So what should we hand over instead? Not raw access. Not a shoebox. A Work Collection: a self-contained, self-authenticating package that asserts a specific allegation, carries the evidence for it, discloses what was withheld and why, and can be read by an investigator without re-doing the work.

The legal machinery for this already exists and almost nobody in our craft uses it. Federal Rules of Evidence 902(13) and 902(14) took effect on 1 December 2017. Rule 902(13) covers records generated by an electronic process or system. Rule 902(14) covers data copied from a device, storage medium or file, authenticated by a process of digital identification, "as shown by a certification of a qualified person" meeting the requirements of Rule 902(11) (Cornell LII, Federal Judicial Center). Translation: a competent custodian can authenticate electronic evidence by signed certification instead of putting a witness in a chair. That rule has been sitting there for nine years, waiting for our industry to build for it. On the handling side, ISO/IEC 27037 already defines the identification, collection, acquisition and preservation requirements and the first-responder role, and NIST SP 800-86 already tells you how to fold forensics into incident response rather than bolting it on afterwards.

Here is what I think belongs in the package. This is a proposal, not a standard, and I would like to be argued with about it.

  1. The claim. One paragraph, plain language, naming what you allege happened, when, to whom, and (where you can) which statutory elements each piece of evidence speaks to. Not "suspicious lateral movement observed." Something a duty prosecutor can read in 90 seconds and decide whether it is theirs.
  2. The custodian and the certification. A named human being with a title and a signature, attesting how the records were made and kept, in the form Rule 902(11) contemplates and 902(13) and 902(14) rely on. If your platform cannot name a custodian and describe its own record-keeping process, it cannot produce evidence. It can only produce content.
  3. The artifact manifest. Every included artifact with its cryptographic hash, its source system, the collection method, the collecting tool and version, and the collection timestamp. Hashes computed at collection, not at export. This is the difference between an exhibit and a file.
  4. Clock discipline. The time source for every contributing system, the measured offset, and any known skew. Half the digital cases I have watched fall apart do so on sequence, and sequence is the first thing a defence expert attacks. If your NTP was drifting on the DC, say so in the package rather than letting someone discover it in cross-examination.
  5. The linked timeline. Not a list of events. A graph: entities, the observed interactions between them, ordered in time and causally linked where causality is determinable, with every node and edge tracing back to a specific artifact in the manifest. Every claim supported, no artifact orphaned from the conclusions it informs.
  6. The theories, including the ones you rejected. What you concluded, what else the evidence could support, and what you eliminated with which artifact. Negative findings are the single most valuable and least-shared thing in an investigation, because they are the work the investigator otherwise repeats. This is also the honest thing to do. If your package only contains the material that supports your theory, you have not written an affidavit, you have written a brief.
  7. The minimisation record. What you withheld, the category it fell into (personal data not relevant to the allegation, privileged communications, unrelated third-party records, regulated health or financial data), the basis for withholding, and the process by which it could be produced under legal compulsion if the investigator needs it. This is the item that solves the over-disclosure problem, and it is the one nobody builds. Structured, field-level redaction means you can share attacker-facing infrastructure in full while sanitising victim-identifying detail, and show your working on both. An investigator who can see the shape of what was withheld can go get it properly, with a warrant, which is better for everyone including the defendant.
  8. Impact and loss. Quantified, with methodology. Downtime, recovery cost, funds transferred, data volumes, affected individuals, jurisdictions touched. Loss thresholds drive charging decisions and jurisdiction, and "significant business disruption" is not a number.
  9. The reproducibility statement. How a third party with the same inputs re-derives your outputs. Query definitions, transformation logic, tool versions. If it cannot be reproduced, it will not survive a competent expert.
  10. The disclosure tier. Where on the spectrum this package sits, and what the escalation path is. A sanitised anonymous tip that names no victim and helps agents spot a pattern. A structured, attributed bundle shared with a named unit under an existing relationship. Or the full attested affidavit for court. The organisation should choose the tier per incident, with the default at the most conservative setting, and the higher tiers should be a promotion of the same package, not a rebuild from scratch. That last property is the whole trick: the reason organisations do not escalate is that escalating currently means starting over.

And what does not belong: raw environment access, full disk images handed over as a substitute for thinking, anything under privilege that has not been cleared, unrelated employee conduct discovered incidentally, and speculation about actor identity dressed up as finding. Naming a nation-state in a Work Collection is a good way to have the entire package discounted.

What this actually saves

An investigator who receives a Work Collection is not opening an investigation. They are reviewing an assertion. The artifacts are already hashed, so provenance is a check rather than a project. The timeline is already normalised, so sequence is readable. The negative findings are already documented, so they do not spend three weeks eliminating what you eliminated in an afternoon. The minimisation record tells them exactly what to put in the warrant application. The certification means they may not need a foundation witness at all.

That is the difference between a referral that costs an agency 200 hours and one that costs it 20. Multiply by the volume in the IC3 report and you can see where certainty of punishment would come from. Not from one heroic case. From the boring, repeatable, industrialised production of prosecutable referrals, by thousands of organisations, at a cost low enough that police can actually absorb them. The DOJ's Criminal Division has published what it wants from victims since 2015 and updated it in 2018. We have simply not built to it.

The clock nobody is watching

One piece of timing that ought to concentrate minds. The Cybersecurity Information Sharing Act of 2015 is the law that makes voluntary sharing legally survivable in the US: liability protection, an antitrust exemption, privilege protection, confidential treatment, federal preemption. It expired on 30 September 2025 and was reauthorised retroactively for a single year in the appropriations bill signed on 3 February 2026 (Wiley Rein). It lapses again on 30 September 2026. That is seven weeks from today.

At roughly the same moment, CISA expects to finalise the CIRCIA rule, which makes covered-incident and ransom-payment reporting mandatory for critical infrastructure. The final rule has slipped from October 2025 to May 2026 to September 2026.

So the plausible near-term picture is compulsory reporting arriving alongside a gap in the protections that made reporting safe, into an industry whose tools produce material that is neither authenticated nor minimised. That is not a call for panic. It is a reason to build the package properly now rather than improvising it under a statutory deadline.

The part where I declare my interest

I run a company that builds security operations software. We think about evidence handling and chain of custody for a living, and if the argument in this post became the industry's default posture, that would be good for us. You should weigh what I have written accordingly, and I would rather say that out loud than have you find it in a footer.

That said, none of what I have proposed here is proprietary and none of it needs to be. Rules 902(13) and 902(14) are public. ISO/IEC 27037 is public. NIST SP 800-86 is public. The CCIPS guidance is public. What is missing is not a technology and not a standard. It is a decision by our craft that producing prosecutable evidence is part of the job, followed by the unglamorous work of building for it. I would be delighted to be one of ten vendors doing this badly rather than the only one talking about it.

Wrap Up

Gopal is right that we built an architecture for connectivity rather than accountability, and he is right that agentic AI is about to make the identity problem much worse. Where I part company is the conclusion. The ghost in Kevin Mitnick's title was not a metaphysical condition. Mitnick was caught. He was caught because somebody produced evidence a court could use.

The reason cybercrime feels unattributable is not that the physics forbid it. It is that we shred the evidence at ingest, hand police a shoebox on the rare occasions we hand them anything at all, and then cite the resulting arrest rate as proof that arrest is impossible. It is a self-fulfilling prophecy with a vendor budget attached. Ninety-two percent of us say we would call the police. Eighteen percent of us do.

That Delta crew had no tooling, no playbook and no threat intel feed. They contained the incident and handed it to people with badges, and if charges follow, every hacker who reads about it will do a small piece of arithmetic they were not doing last week. That is deterrence. It is available to us. It has always been available to us.

We just have to stop burning the evidence and start writing the affidavit.

Corrections welcome, as always, at [email protected]. I am particularly interested in being wrong about item seven.

Tags