From IOCs to Answers: Six Questions That Make Incident Response Defensible – Jacob Wellnitz

Incident response teams are very good at finding things: IP addresses, hashes, process trees, authentication events, suspicious commands, malware, and countless other forensic artifacts.

But finding evidence and answering an incident are not the same thing.

During a serious cyber incident, technical findings must eventually support decisions made by executives, counsel, insurers, regulators, and the organization responsible for getting the business running again. A pile of IOCs may prove that something happened, but it does not necessarily explain what happened, how far it went, what can actually be supported by the evidence, or what remains unknown.

In From IOCs to Answers: Six Questions That Make Incident Response Defensible, Jacob Wellnitz draws on experience from hundreds of incident response investigations to present a practical framework for approaching investigations from the questions that ultimately need to be answered.

The session explores how investigative scope, evidence preservation, technical analysis, and communication intersect during real-world incidents. It also examines one of the hardest disciplines in incident response: knowing when the evidence supports a conclusion, when it does not, and how to communicate that distinction without turning assumptions into facts.

Whether investigating ransomware, identity compromise, cloud incidents, business email compromise, or a more complex intrusion, the objective is the same: move beyond simply finding indicators and produce conclusions that can withstand scrutiny after the immediate crisis has passed.

Attendees will leave with a practical way to think about structuring investigations, communicating findings, and turning technical evidence into answers that decision-makers can actually use.