The value of attribution after a breach is lost in the debate, but it’s also a critical proactive exercise to understand adversaries before they impact the business. A security leader needs to distill events into a story for the executives and the board, and a briefing devoid of attribution leaves everyone asking why? A businesss goals are quite different one of the primary objectives is to minimize operational risk. General attribution provides opportunities for operational security practitioners to learn and institute new plays to improve malicious activity detection efficacy.”]
Source: https://www.csoonline.com/article/3028907/does-attribution-matter-to-security-leaders.html