Skip to content
Risks of Public Cyber Attribution Discussed at RSAC 2026

Risks of Public Cyber Attribution Discussed at RSAC 2026

First seen 25 Mar 2026, 20:47 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 26, 2026 at 20:20 UTC
  • •Public attribution of cyberattacks can lead to diplomatic and reputational risks.
  • •Attribution is often probabilistic, not definitive, complicating public statements.
  • •Companies must consider strategic objectives before publicly blaming threat actors.

At the RSAC 2026 Conference, experts highlighted the complexities and risks associated with publicly attributing cyberattacks to specific threat actors. The panel emphasized that attribution is often probabilistic rather than definitive, with Brett Callow noting that naming a hacking group can lead to diplomatic retaliation or other consequences. Mike Egan pointed out that companies may mistakenly believe that attributing attacks to nation-states absolves them of responsibility, potentially increasing customer anxiety. Megan Stifel stressed the importance of strategic objectives in attribution decisions, as public statements can significantly impact a company's narrative and regulatory obligations. The discussion revealed that the rush to attribute can lead to unintended blowback and complicate the narrative surrounding cyber incidents.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 197d ago How this analysis works

Timeline

2026-03-24
Panel discussion on cyber attribution at RSAC 2026 Conference
2026-03-25
Articles published discussing the panel's insights

More articles in this cluster (2)

Following this threat?

Track Salt Typhoon and NotPetya in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed