# Third-Party Incident Response Operates Inside the Threat Model

- **Artifact ID:** CHQ-SCA-2026-006
- **Canonical source ID:** CHQ-J-2026-006
- **Version:** v1.0
- **Status:** ISSUED
- **Public record:** https://record.cybersecurityhq.com/assessments/chq-sca-2026-006
- **Machine-record SHA-256:** `fd19b6f3c43c2583edbaf6849c682861a3bc07a7905a9e19b0d93f56c6a304e7`

## Complete structured record

```json
{
  "id": "CHQ-J-2026-006",
  "title": "Third-Party Incident Response Operates Inside the Threat Model",
  "status": "ISSUED",
  "issuance_date": "2026-01-23",
  "version": "v1.0",
  "judgment_type": "SYSTEMIC",
  "classification_tag": "Third-Party Incident Response Threat Model Inclusion",
  "decision_surfaces_safe": [
    "Breach Causality Attribution (Organizational)",
    "Vendor–Operator Liability Boundary",
    "Retrospective Control Interpretation Defense"
  ],
  "decision_surfaces_unsafe": [
    "Individual Accountability Insulation",
    "Sworn Technical Assertion (Personal)",
    "Insurance Coverage Disputes",
    "Transactional Security Representation Defense",
    "Criminal Proceedings",
    "Employment and HR Accountability",
    "Vendor Product Defamation",
    "Public Communications and Investor Disclosures",
    "Retainer or Contract Negotiation Leverage"
  ],
  "load_bearing_assumptions": [
    {
      "id": "A1",
      "label": "Incident-Condition Access Alteration",
      "type": "LOAD-BEARING",
      "text": "Third-party incident response engagement introduces access paths with authorization governance characteristics, effective scope, or access control modes that differ materially from non-incident operations."
    },
    {
      "id": "A2",
      "label": "Privileged Access Path Equivalence",
      "type": "LOAD-BEARING",
      "text": "Access paths introduced under incident conditions can produce failure modes equivalent to those modeled for other privileged actors, including credential compromise, lateral movement, and sensitive data access."
    },
    {
      "id": "A3",
      "label": "Threat Model Scope Determination by Capability",
      "type": "LOAD-BEARING",
      "text": "Threat model inclusion is determined by capability class and failure mode equivalence, not by intent, trust relationship, or contractual assurances."
    },
    {
      "id": "A4",
      "label": "Governance Mode as Incident Indicator",
      "type": "CONTEXTUAL",
      "text": "Incident conditions are evidenced by governance mode shifts, effective scope expansion, or exception-mode access controls, not solely by formal incident declaration."
    }
  ],
  "core_judgment": "When third-party incident response engagement introduces privileged access paths under incident conditions that alter normal authorization governance characteristics, expand effective access scope beyond baseline operational posture, or require emergency or exception-mode access controls, those access paths must be modeled as in-scope privileged actor elements within the organizational threat model for purposes of breach causality attribution and control adequacy evaluation, irrespective of contractual terms, trust relationships, or monitoring arrangements.",
  "observability_conditions": [
    {
      "number": 1,
      "title": "Privileged Access Path Evidence",
      "text": "Third-party incident response is treated as introducing privileged access paths where the engagement results in:\n• Credentials, tokens, or access grants issued to or on behalf of IR personnel or systems that enable access to production environments, identity systems, security tooling, or data repositories\n• Deployment of IR-provided tooling, agents, or infrastructure with access to organizational resources beyond public-facing interfaces\n• Elevation of IR personnel to roles, groups, or entitlements conferring administrative, investigative, or remediation capabilities\n\nAccess path introduction is established by the presence of access-enabling artifacts at the time of engagement, not by post-hoc characterization of access scope or intent.\nContractual limitations on access do not negate the existence of access paths where technical access was granted."
    },
    {
      "number": 2,
      "title": "Incident Condition Evidence",
      "text": "Incident conditions triggering the modeling requirement are present where IR engagement introduces authorization or access characteristics that differ materially from non-incident operations, including:\n• Governance mode shift: authorization decisions made under compressed timelines, reduced approval chains, or delegation of authority outside normal governance\n• Effective scope expansion: access exceeding that normally exercised by equivalent roles or third parties under non-incident conditions, regardless of formal approval or historical permissiveness\n• Exception-mode access: break-glass procedures, emergency credentials, temporary elevated roles, or mechanisms designed for exceptional circumstances\n\nBaseline operational posture is inferred from observed normal access and authorization patterns, not solely from documented policy.\nAbsence of a formally documented baseline, or the existence of a permissive baseline, does not negate the presence of incident conditions."
    },
    {
      "number": 3,
      "title": "Threat Model Equivalence Evidence",
      "text": "IR access paths are treated as in-scope privileged actor elements where they introduce failure modes equivalent to those modeled for other privileged actors, including:\n• Credential compromise or misuse potential\n• Lateral movement capability\n• Access to sensitive data, configurations, or security controls\n• Ability to modify, exfiltrate, or impact organizational assets\n\nEquivalence is assessed by capability class, not by intent, trust relationship, monitoring, or contractual assurances.\nMonitoring, logging, oversight, or contractual controls may affect control adequacy evaluation but do not remove access paths from threat model scope."
    }
  ],
  "boundary_of_safe_citation": "This judgment governs the structural position of third-party incident responders within organizational threat models based on access path characteristics and failure mode equivalence.\n\nIt must not be cited to:\n• Defend individual testimony or provide personal insulation\n• Interpret insurance coverage or claim validity\n• Validate or invalidate transactional disclosures\n• Support criminal theories or prosecutorial standards\n• Justify or preclude employment or HR actions\n• Defame or disparage specific vendors or responders\n• Assess materiality or adequacy of public disclosures\n• Gain leverage in retainer or contract negotiations\n\nCitation outside the defined safe decision surfaces risks misapplication as vendor condemnation rather than structural observation.",
  "retirement_triggers": [
    {
      "number": 1,
      "title": "IR Access Normalization",
      "text": "Widespread production adoption of IR engagement models in which access is provisioned through standard authorization governance without governance mode shift, scope expansion, or exception-mode controls."
    },
    {
      "number": 2,
      "title": "Dedicated IR Threat Model Framework",
      "text": "Establishment of authoritative industry or regulatory frameworks that define a distinct threat model category for incident response access, superseding in-scope privileged actor treatment."
    },
    {
      "number": 3,
      "title": "Cryptographic IR Access Isolation",
      "text": "Adoption of IR engagement architectures with cryptographically enforced access isolation and non-persistent credentials such that IR access paths cannot produce failure modes equivalent to other privileged actors under breach or misuse conditions."
    },
    {
      "number": 4,
      "title": "IR Access Immutability Standards",
      "text": "Regulatory or industry standards mandating IR access architectures in which lateral movement, credential persistence, and scope expansion are architecturally impossible."
    },
    {
      "number": 5,
      "title": "Mandatory Reassessment",
      "text": "Formal reassessment required 36 months after issuance, and at 24-month intervals thereafter, to evaluate whether incident-condition access characteristics remain dominant in IR engagement practice."
    },
    {
      "number": 6,
      "title": "Practice Inflection Review",
      "text": "Immediate reassessment upon credible evidence of structural changes in IR engagement practices, access provisioning models, or threat modeling standards that materially alter the premises of this judgment."
    }
  ]
}
```
