This blog entry is part six in an ongoing conversation with my good friend Gopal Padinjaruveetil on the role, benefits and challenges of deterrence in cybercrime. If you want to catch up, here are the historical posts:
- In 2021, I wrote a piece for Dark Reading titled "Handcuffs Over AI" that argued that lessons from handling physical crime are the most important innovation we can adopt in deterring cybercrime and reducing the costs and risks associated with it.
- Last week, I reposted that article on LinkedIn in response to the DEF CON and Delta WiFi hijacking.
- In response, Gopal answered on LinkedIn with questions about the hurdles of implementing effective attribution to achieve the goals I described.
- In like order, I posted this blog entry on "The Deterrence Delusion" examining attribution, deterrence and the roles of industry, vendors and law enforcement.
- Gopal offered counterpoints to that entry in this LinkedIn post (and its comments), which I would summarise as four objections:
- How the psychological shame and worry of victims in cybercrime create a barrier to reporting.
- How the strains on relationships between law enforcement and victims hinder reliable pathways to reporting.
- How creating more "Work Collections" (as defined in my last blog entry) exacerbates the understaffing at both victim organisations and law enforcement.
- How the use of agentic AI in cybersecurity operations complicates reporting.
Victim Shaming
First and foremost, Gopal is correct that victim-shaming is a real problem in cybersecurity. I cannot think of a type of crime that tolerates the level of shaming we see in cybercrime. It would be considered widely disgusting to accuse the victim of any other crime of "asking for it" by not trying harder to avoid an attack. The worst part of this epidemic is that it is largely done inside our own craft. Vendors (like me) are quick to accuse victims of neglecting to take my advice (and buy my products) to avoid these crimes. Frustrated peers across the industry blame the organisations for failing to invest in proper staffing and controls. New to the conversation is the use of AI to "magically" address problems that cybersecurity veterans know must be handled with fundamentals and do not need trick plays.
Two things I have read this year made me stop treating this as a manners problem.
The first is a study published in the Journal of Cybersecurity in 2024 by Gareth Mott and colleagues, drawn from 83 participants across interviews and workshops, and titled with a line from one of them: "There was a bit of PTSD every time I walked through the office door." The researchers found post-traumatic stress, suicidal ideation, heart attacks and strokes among people who worked ransomware incidents. They also found the organisational response to all of it summarised in a phrase I have heard in more than one SOC: suck it up and sort it out. The paper's blunt conclusion is that a ransomware event is a whole-of-organisation crisis rather than an IT problem, and that we systematically under-report the human half of the damage.
The second is older and it is criminology rather than cybersecurity. In 1957, Gresham Sykes and David Matza described five "techniques of neutralisation," the stories offenders tell themselves so that a crime feels acceptable while they commit it. One of the five is denial of the victim: they had it coming. Researchers at Orange Cyberdefense have documented extortion crews using precisely that technique in their own leak-site copy, reframing the organisation they just attacked as negligent and therefore deserving.
Here's the thing. That is the same sentence our industry says. Different tone, better vocabulary, identical structure. When we tell a breached company that it should have patched faster or bought the thing we sell, we are reciting the attacker's script back to the victim. I do not think most of us have noticed that, and I include myself in that.
In my last installment I laid out the fear of over-discovery that prevents reporting. I made the argument that not baking law enforcement into all areas of cybersecurity leaves us with a "shoebox" of evidence, which forces law enforcement to choose between invading the privacy of the victim and skipping the investigation.
Victim-shaming is a real problem, but I posit that deterrence is part of its correction. If the arm-chair quarterbacks are left with only two candidates to blame, law enforcement or the victim, most of the blame is going to land on the victim organisation, because the victim is the only one in the room. Bring the culprit into the picture and the anger has a better target. That requires attribution, and attribution requires reporting. On its own it is not the solution to victim-shaming, but it is a motion that, handled correctly, shifts the ire from the victim to the criminal.
And the shift is measurable in both directions. When Dutch researchers surveyed entrepreneurs about ransomware in 2025, about 92% of those who had not been hit said they would call the police. About 18% of those who had actually been hit did. The two reasons the victims gave were that they handled it themselves and that they believed the police would do nothing. Shame does not appear in that list as its own line item because it does not have to. It shows up as the calculation.
Fear of Police
In "Handcuffs Over AI" I pointed out that unsafe neighbourhoods stop talking to police because, at least in part, of bad experiences in working with police. I tell my law enforcement friends that if they show up at the site of my car accident, I expect them to take statements and write up the accident. I do not expect them to follow me home and go through all of my things.
Likewise, I tell my friends in industry that if you took some (but not all) of your receipts through the year and stored them in trash bags, then put those trash bags on trucks, then at the end of the year dumped the bags on your accountants and said "file our taxes," you would find that your accountants start blocking your calls.
The last three decades have produced repeated failures on both sides of that exchange. Industry does not treat signal as evidence, and so it creates a haystack for law enforcement to go through if it ever calls. An understaffed law enforcement team forced to dig through unorganised and fragmented sources is going to have to write subpoenas that are too broad, because industry has been careless about establishing a chain of custody. Then the too-broad subpoena confirms the victim's fear of over-discovery, and the victim tells the next three peers who ask that reporting was not worth it.
The understaffing is not hypothetical. British inspectors found police forces "overwhelmed and ineffective" on digital forensics, with a backlog of more than 25,000 devices waiting for examination. Researchers at University College London describe months-long backlogs across the investigative process, driven in part by how much undifferentiated material organisations hand over. Every trash bag we deliver makes the queue longer for the next victim.
It is worth saying plainly that law enforcement has already told us what it wants. The Justice Department's Computer Crime and Intellectual Property Section published Best Practices for Victim Response and Reporting of Cyber Incidents in 2015 and updated it in 2018. It is short, it is free, and almost no product I know of is built to produce what it asks for. That is not a communication failure on their side.
By not building a sustainable pipeline of evidence from the SOC to the precinct, we have created and exacerbated the problem. The antidote is to first fix the pipeline, then execute on it, to create the opportunities that let trust between law enforcement and industry be re-established. Trust is not restored by a summit or a memorandum of understanding. It is restored by a hundred boring handoffs that go well.
I also mentioned in my last installment that a large share of the burden for solving this belongs to vendors. We need to build tools that produce better evidence pipelines, and those pipelines need to reduce both risk and work.
Work Explosion
This takes me to the third solid point Gopal made. If we start putting more Work Collections into the inbox of law enforcement, that must increase the workload on both sides of the handoff. Given that both sides are under-resourced, that is a serious objection.
It is a vendor problem to solve first. The evidence pipeline should be very nearly automated at the reporting organisation. Even without any use of AI, this is possible today. The major vendor problem is the one described above: there are few organisations that trust such a workflow, because few have ever seen one work. IC3 already standardises much of what it receives through its complaint application, and it aggregates related complaints into referrals rather than investigating each one in isolation. By extending those standards to carry richer, structured data, FBI workflows improve too, and the required human labour goes down. If reliable evidence can be ingested, organised, corroborated and deduplicated before it reaches a Special Agent's desk, that agent gets higher conviction rates for lower resource expenditure.
There is a second-order effect here that I think is the real answer to the objection. Structured reports merge. Unstructured ones do not. Ten thousand trash bags describing the same actor is ten thousand separate investigations, which is why it never happens. Ten thousand structured submissions describing the same infrastructure is a handful of actor-level cases carrying ten thousand exhibits, and the merging is machine work rather than agent work. The volume that looks like a burden at intake is the thing that produces the case at the other end.
The other, and arguably most important, impact on workloads is at the systems level. As deterrence improves through reporting and prosecution, the number of incidents to report begins to fall. That decrease in crime is directly proportional to the decrease in work needed to address it.
That claim used to be theory. It is now measured. When international law enforcement seized 49 DDoS-for-hire domains in December 2022, researchers at Cambridge, Edinburgh, Strathclyde and the University of Illinois Chicago tracked what happened to global attack volume. It fell by 20% to 40%, with a statistically significant effect on the attack types booters are known for, and the sites that came back lost 80% to 90% of their traffic. Underground chatter showed operators and customers recalculating their own safety. I will give you the uncomfortable half as well, because it matters: the effect decayed after roughly six weeks. Which is the argument for sustained volume rather than against it. One spectacular case is not a deterrence programme. A steady, cheap, industrialised flow of prosecutable referrals is.
Lastly, not all submissions are treated the same by law enforcement. A high-quality submission of forensically defensible artifacts is not the same thing as a shoebox of random signals, and the difference is written down. The Justice Manual, section 9-27.220, tells federal prosecutors to commence prosecution where the conduct constitutes a federal offence and "the admissible evidence will probably be sufficient to obtain and sustain a conviction." Section 9-27.230 then lists what makes the federal interest substantial, and that list includes the deterrent effect of the prosecution and the interests of the victim.
Read that as an engineer. The gate is a test of admissibility and probable sufficiency. It is not a timestamp. The shoebox does not lose because it arrived late in the queue. It loses because nobody can tell from it whether the evidence would survive a motion.
The rules of evidence go further than most of our craft realises. Federal Rules of Evidence 902(11), 902(13) and 902(14) let a qualified custodian authenticate electronic records by signed certification instead of by putting a foundation witness in a chair. That has been true since 1 December 2017. It is nine years of labour savings sitting on the table, and it is available to any organisation whose systems can describe how their own records are made and kept. Most cannot, which is a vendor failure and not a legal one.
Probabilistic Poisoning
The last objection needs more attention than I will give it here today, but I will agree that probabilistic processing by agentic AI has strong potential to poison deterministic data for use in law enforcement and cybersecurity. I discussed some of that in "Why Lossless Cybersecurity Analytics Require Deterministic Pipelines."
I argue that the core problem is that because we do not have evidentiary pipelines, probabilistic guessing became acceptable in our SOCs. If we never have to think about a successful prosecution of our attackers, we can just make high-quality guesses about the situation and about our response to it. I am not against probabilistic processing. Even detectives have to form hypotheses and test them. But it cannot replace the hard work of proving a case (see "Which Detective Would You Hire?").
Deterministic data, like the readout from a radar gun or a breathalyzer, can be reliably defended in court. While agentic AI can assist in explaining data, forming hypotheses or choosing which step to execute next, court cases need deterministic data.
I want to note that the courts have arrived at the same line independently, and recently. The Advisory Committee on Evidence Rules has proposed a new Federal Rule of Evidence 707 covering machine-generated evidence. As published, it would require machine-generated evidence offered without an expert witness to satisfy the reliability standards of Rule 702, the rule that governs expert testimony. And it expressly does not apply to "the output of simple scientific instruments." Thermometers. Scales. Radar guns. The comment period closed on 16 February 2026 and the committee took the proposal back up in May.
Sit with that for a moment. A federal rules committee, working the problem from the courtroom end, drew the boundary in exactly the same place I have been drawing it from the SOC end: the instrument reading is one kind of thing, and the machine's opinion about what the reading means is another kind of thing entirely. The first walks into court. The second has to earn its way in.
Which gives us a design rule that costs nothing to adopt and is worth adopting whether or not you ever call the police. Never let a machine's inference travel in the same field as a machine's observation. Keep the readout and the guess in separate columns, and label which is which. If you cannot tell them apart in your own data model, that is the first thing to fix, and the courtroom is only one of the reasons.
Wrap Up
Gopal's four objections are all real, and three of them are ours to fix rather than law enforcement's. We shame victims because the criminal is not in the room, and the criminal is not in the room because we never produced the evidence that would put him there. We hand over trash bags and then act surprised at the breadth of the subpoena that comes back. We build tools that guess, because guessing is sufficient when nobody downstream ever has to prove anything.
None of that is a hard technical problem. Every piece of it is a decision our craft has quietly made and could quietly unmake.
SOCs that skip to guessing are going to stay stuck in the quagmire of going it alone, in a world that gets no safer.
Gopal, as always, thank you. Corrections and arguments welcome at [email protected].