{
  "answer": "A defensible record requires reliable attribution, adversary capability, verified hostile intent, target access, expected effects, imminence or last-window analysis, alternatives considered, necessity, proportionality, legal basis, competent approval, third-party infrastructure analysis, deconfliction, abort conditions, logging, and post-action review. Threat labels or intelligence confidence scores alone are insufficient.",
  "canonicalUrl": "https://xn--mwe.com/questions/what-evidence-required-before-preemptive-cyber-operation/",
  "claimStatus": "PROJECT POLICY PROPOSAL",
  "correctionStatus": "CURRENT K05 RELEASE",
  "id": "K01-ANSWER-080",
  "lastReviewed": "2026-08-16",
  "question": "What evidence is required before a preemptive cyber operation?",
  "releaseId": "K12-2026-08-16",
  "researchCutoff": "2026-08-16",
  "shortAnswer": "A defensible record requires reliable attribution, adversary capability, verified hostile intent, target access, expected effects, imminence or last-window analysis, alternatives considered, necessity, proportionality, legal basis, competent approval, third-party infrastructure analysis, deconfliction, abort conditions, logging, and post-action review. Threat labels or intelligence confidence scores alone are insufficient.",
  "slug": "what-evidence-required-before-preemptive-cyber-operation",
  "sourceRevalidatedAt": "2026-08-15T23:00:00Z",
  "status": "PROJECT POLICY PROPOSAL",
  "topic": "security-resilience",
  "type": "Question"
}
