How to prepare for and plan your organisation's response to severe cyber threat: a guide for CNI
Pages
Page 26 of 26
Counterfactuals
Why use counterfactuals?
Counterfactuals – or counterfactual analysis – is asking ‘what if’ questions of events that have happened and ask what hasn't happened. This helps organisations uncover hidden vulnerabilities, challenge assumptions, and improve decision-making. By exploring alternative outcomes, counterfactuals support more robust risk assessments, incident reviews, and scenario planning, ultimately enhancing your readiness for future threats.
When should I use them?
Counterfactuals can be used when trying to understand the risks your organisation faces when there is limited information on past incidents. They can also help build a better picture of the interactions and dependencies in a cyber system, and how different risks around – say – safety, security and reputation are interconnected and can arise from similar incidents.
What do I need?
- Information about the past incident or other scenario you want to investigate. If information on cyber incidents is unavailable then information on cyber near-misses, or other harmful incidents such as safety incidents, can be used as a starting point.
- This can be carried out individually or as a group. It can be extremely useful to involve representatives of the different potential risks (for example business and safety), to help investigate how losses can spread from one area of responsibility to another.
- Paper, whiteboard, or other way to take notes.
The process
- Describe how the original event – real or imagined – unfolded, defining each of the steps which led to the outcome.
- Choose the categories of change you will be investigating. These are all the things which could have been different on the day and may have affected the outcome. Choose ones that are relevant to the scenario and could be plausibly different, defining the range of difference that will be useful to explore. Examples include:
- people’s choices
- time/day
- location
- coinciding events
- socio-political environment
- human error/luck
- technology, for example if you started with a safety event, change some of the technology involved in the incident, and explore how a cyber attack on those systems could have created similar results
- serendipity
- environmental factors
- service availability
- a factor is decreased
- a factor is increased
- Define losses that are important to you in this context. These will help frame the impact of the different scenarios. They can be very general, such as financial losses, reputational damage, or people injured.
- For each step of the original incident, apply one of the feasible changes, and see how that might affect the outcome. What might have happened if the incident was on a Friday instead of a Tuesday? What might have happened if the analyst on duty hadn’t noticed something strange was happening and decided to investigate?
- For each new scenario follow the steps of the attack until you reach one of your defined losses. You will generally be looking for scenarios that result in a similar or greater loss than the original event, as this provides new risk information. A reduced loss is less useful, unless the change is one that you can control and introduce as a security measure.
- Repeat until you have explored all feasible scenarios.
Next steps
- The new scenarios can either be kept in narrative format, telling the story of each alternative version of the original event, or feed into your other risk processes.. The type of output will depend on how you prefer to use incident information.
- These scenarios can be used to aid risk decision making, providing additional information to analyse your as-is system, as well as potential mitigations.


