The incident note that was quicker than the incident
An AI Reality case study - Cybersecurity and Trust
Fictional composite | Free reader edition, 1 October 2026
This is a fictional composite. The people, company, timeline, excerpts and results are invented. Real-world sources at the end illustrate separate risks, not this event.
Tuesday, 6:40 am: the alert
A vendor alert said an unusual login had accessed the customer-support export service. Logs showed a successful token use and a download request. They did not show whether the file contained customer records or merely test data. The security lead was tracing the token; the support team asked whether to stop exports. Nadia had less than three hours before a board update.
A colleague offered a shortcut their team had used before. They pasted a short timeline and several raw log excerpts into a commercial AI assistant to turn rough notes into a readable report. Its draft said: “No customer data exposure identified. Access contained. Normal service may continue.” The note looked ready to send. The colleague was trying to help; Nadia herself had asked for an early summary. But the draft had moved from “we have not checked the file” to a sentence a reader could take as “the file was checked and there is no exposure.” The token had been revoked, not necessarily every path closed. The assistant account's handling of the pasted excerpts had not been checked either.
At 8:10 the security lead verified that a test export had run; the downloaded file's contents remained unknown. The board secretary needed the pack, communications wanted a line for callers, and the incident team wanted two hours to preserve logs and inspect the file without making a public promise to undo. The template allowed green, amber or red impact labels. Green suggested customer impact had been checked; red suggested harm had occurred. Blank looked evasive. Nadia could use “impact unconfirmed” with a time for update, if the board would accept a departure from the template.
Exhibit 1. What was observed by 8:10
| Time | Evidence available | What it supports | What it does not support |
|---|---|---|---|
| 6:40 | Vendor alert and successful token-use line | A credential was used for this service | Who used it or why |
| 7:05 | Download request in the log | A request was made | The contents or completed delivery of the file |
| 7:40 | Token revocation recorded | That token should no longer work | No other credential or export path was active |
| 8:10 | Security lead's check: test export ran | At least one export ran | Whether it held customer data; whether other requests ran |
These times and artefacts are invented. “A test export ran” does not itself mean the exported content was only test records. Ask what file, log and chain of custody would answer that question.
Exhibit 2. The draft and the owner
| Draft sentence | Responsible status at nine | Owner of the next check |
|---|---|---|
| “No customer data exposure identified.” | No conclusion yet; contents unexamined | Incident lead inspects the file and checks relevant exports |
| “Access contained.” | Token revoked; origin and other paths unknown | Security lead checks origin and further activity |
| “Normal service may continue.” | Support export path needs targeted review | Operations and incident leads decide the bounded service rule |
| Raw logs already pasted into AI assistant | Destination and data handling unknown | Data owner reviews account, excerpt content and provider terms |
Nadia owns the board wording. That does not let her certify technical facts she has not been given. A correct later file result would not make the earlier wording evidentially sound.
A documented parallel, not Nadia's incident
Cisco Talos Incident Response described experimental AI-assisted reporting for a fictional tabletop exercise. It found that polished reports drawn from raw notes could contain significant inaccuracies and unusual conclusions. That is why Nadia must compare each sentence of the polished note with the log evidence. Cisco also discusses the separate risk of uploading organisational material to public AI services; that is why the pasted log excerpts need their own account and data-route review. Cisco did not report this fictional event or establish that customer records were exposed here. https://blogs.cisco.com/?p=491499
The OAIC advises due diligence when using commercial AI products with personal information, including access, security and intended use. It helps frame Nadia's question about the pasted logs; it does not prove those logs contained personal information or were retained. https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/guidance-on-privacy-and-the-use-of-commercially-available-ai-products
The case in numbers
The timings come from the case timeline or follow from it. Three figures are invented teaching assumptions, and the last column marks them so you can replace them with your own.
| Measure | Figure | Why it matters | Basis |
|---|---|---|---|
| Alert to board update | About 2 hours 20 minutes (6:40 to 9:00) | Less than three hours to say something true | Derived from the timeline |
| Alert to token revocation | 60 minutes (6:40 to 7:40) | Revoking one token is not the same as closing every path | Derived from Exhibit 1 |
| Alert to confirmation that a test export ran | 90 minutes (6:40 to 8:10) | Still no answer on what the file held | Derived from Exhibit 1 |
| Time left to approve the board note at 8:35 | 25 minutes | The decision is made under time pressure | Stated |
| Time the incident team asked for | 2 hours | To preserve logs and inspect the file before any promise | Stated |
| Draft sentences the evidence at nine fully supports | 0 of 3 | Each sentence says more than anyone had checked | Derived from Exhibit 2 |
| Raw log excerpts pasted into the assistant | 6 | What was pasted cannot be unpasted | Invented |
| Time to produce the AI draft, against a hand-written timeline | About 4 minutes, against about 40 | The shortcut saves about 36 minutes, which is why it tempts | Invented |
| Customer records the export service can reach | About 12,000 | The scale at stake if the file holds customer data. It is not a count of exposed records | Invented |
The draft saved about 36 minutes and gave the board a sentence nobody could stand behind. Neither number says whether any customer was affected, and nothing on this page does.
Critical evaluation
| Question | Working answer | What remains open |
|---|---|---|
| What happened? | Token use and an export are confirmed; an AI draft turned partial evidence into settled wording. | File contents, token origin and exact excerpts pasted. |
| What does the result support? | One token revoked, one test export ran. | Other credentials, requests and customer impact. |
| What could explain it another way? | Legitimate test, stolen token or log artefact could fit parts of the timeline. | Which explanation survives independent file and log checks. |
| What test comes next? | Preserve logs, inspect the downloaded file, check assistant account and terms. | Notification threshold and wider containment decision. |
DECISION MAP
Alert/log -> AI draft -> board note. The dangerous handoff is not the existence of a draft but the promotion of an unverified inference into the board's status. In parallel, raw logs -> commercial assistant is a data route the team has not authorised. These are two different decisions.
Figure 1. Two paths: claim verification and data handling. The diagram locates the handoffs; the choice table below compares actions.

Decision room: 8:35 am
Nadia must approve the board note within twenty-five minutes. The board may authorise more investigation, and support needs direction now. How does she word uncertainty, which export activities may continue, and who can sign off AI-input handling?
| Choice | Immediate gain | Immediate cost | Second-order risk |
|---|---|---|---|
| A. Use the polished note and keep raw-log drafting | Fast, coherent board narrative and no workflow pause | Assumes facts and data terms not checked | Unverified “no exposure” becomes the working truth and more logs enter an unchecked route |
| B. Hold the board note and pause all AI drafting | No further confident claim; time for investigation | Board lacks the facts needed for interim decisions; useful safe drafting also stops | Silence prompts unofficial guesses and may delay targeted containment |
| C. Send a bounded update; pause raw-log input only | Board gets observed facts, named unknowns and a noon update | Nadia rewrites under time pressure and assigns specific reviews | Correctable claims, but only if owners actually deliver the promised checks |
A more severe file finding could justify B or wider containment; a known approved, redacted drafting route could narrow the pause. Choose a route, write two board sentences and a data-handling rule, and name what evidence at noon would change them. Stop before reading the separate teaching epilogue.
OPERATING PRINCIPLE
An early incident update earns trust by saying what is not known, not by sounding finished.
Separate teaching epilogue: open only after choosing a path
Nadia did not choose C because it was a comfortable middle. A required repeating claims the security lead could not support and feeding an unreviewed assistant more raw material. B withheld even the facts the board needed for the investigation. She asked the security lead to verify token and file status, the data owner to preserve the prompt and inspect the assistant account, and communications to keep its wording provisional. She replaced the colour label with “impact unconfirmed”, explaining why no colour yet represented the evidence.
At nine the board heard what was confirmed, what remained unknown, who was checking it and when the next note would come. One director asked whether support should stop. The incident lead recommended targeted checks on the export path rather than a blanket claim that all support work was safe or unsafe. The board accepted a noon update and asked for a documented threshold for notifying customers. Nadia paused raw-log entry to the commercial assistant, not all human writing or future use of approved redacted material.
By the thirty-day review, the investigation had established that the file contained test records, not customer records. That later finding did not justify the earlier “no exposure” draft. The team introduced a note template that separated observation, inference, customer impact and next verification. It also recorded what was pasted into the assistant; a later policy cannot undo that paste. At ninety days AI drafting resumed only for approved, redacted material, with a named reviewer and evidence attached. The first draft sometimes took longer; the board could now see what was actually verified. A different factual finding at noon could have required wider containment and notification. The process is valuable only if it changes with the evidence.
Sources and evidence limits
Original fictional composite reader/guide drafted 29 September 2026. Source context checked: Cisco Talos IR https://blogs.cisco.com/?p=491499 ; OAIC https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/guidance-on-privacy-and-the-use-of-commercially-available-ai-products ; ACSC https://www.cyber.gov.au/business-government/secure-design/artificial-intelligence/engaging-with-artificial-intelligence ; NIST Generative AI Profile https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-generative-artificial-intelligence . Those sources do not authenticate the invented incident. Almost Magic Tech Lab Pty Ltd.
Facilitator guide
A private 90-minute session kit: run sheet, stakeholder questions, model analysis, transfer worksheet and quality check.
Request the facilitator guide