The process of identifying who is responsible for a cyber attack or campaign.
Attribution is the process of identifying the actors responsible for cyber attacks—determining whether an attack came from a nation-state, criminal group, hacktivist, or insider. Attribution is challenging because attackers use proxies, false flags, and stolen infrastructure to hide their identity. It requires technical forensics, intelligence analysis, and often collaboration across organisations. While precise attribution is difficult, understanding attacker type helps calibrate response and defence priorities.
Why It Matters
The DSC Perspective:
Attribution helps contextualise attacks and inform response. Whether an attack is opportunistic criminal activity or targeted espionage affects how you respond and what you report. However, attribution should not delay incident response.
