Decide these before the incident
Settle these in advance and refer to them during the response. Working out who can authorize taking production offline while the file shares are encrypting spends the only time that matters on a phone tree.
Who authorizes what
Structure from p. 97. The role names and containment tiers are placeholders. Replace them with yours before anyone relies on this.
| Decision | Authority | Delegate | Record required |
|---|---|---|---|
| Declare an incident | Incident commander | Senior analyst on duty | Ticket with declaration time and rationale |
| Isolate an endpoint | SOC or IR analyst | None needed | Containment decision record |
| Isolate a server or service | Service owner with incident commander | Incident commander alone if the owner is unreachable inside the response window | Containment decision record with impact assessment |
| Shut down production, or anything touching regulated services | Named executive | CISO after hours, ratified next business day | Containment decision record plus executive approval |
| Expand scope to other business units | Incident commander, CISO notified | None | Scope expansion entry with the trigger |
| Exit the loop, technical closure | Incident commander on eradication validation | Senior analyst with written approval | Signed technical closure record |
| Accept residual risk | CISO or named risk owner | Board-level executive for significant incidents | Signed risk acceptance naming the risks |
| Notify a regulator | Legal counsel with the CISO | General counsel | Decision log with timeline and regulator named |
| Speak to media or the public | Communications lead with legal sign-off | CEO for material incidents | Approved statement under version control |
| Pay a ransom | Written position agreed in advance, then named executive with counsel | None | Decision log naming counsel and carrier consulted |
When containment cannot wait
Table 17, p. 227. Map each trigger to an approved action during preparation.
| Trigger | Indicators | Approved action |
|---|---|---|
| Active destruction | Encryption spreading across shares, event logs wiped, database tables dropped | Isolate immediately |
| Exfiltration | Large transfers to cloud storage, bulk queries against personal data, archives sent to external sites | Contain urgently to cap exposure |
| Safety or critical systems | ICS, medical devices, payment processing, other safety-critical infrastructure | Act immediately and accept the loss of intelligence |
| Regulatory clock | Data or services under HIPAA, PCI DSS, GDPR, NIS2, DORA, CRA, or a local equivalent | Contain rapidly to limit affected records |
Which containment posture
Table 16, p. 223. Deceptive containment is drawn from the same chapter's step-by-step reference.
| Situation | Posture |
|---|---|
| Destruction or ransomware underway | Active, required |
| Regulated data with a compliance clock | Active, required |
| Safety-critical or high-availability system at risk | Active, required |
| Attacker shows awareness of defenders | Active, strongly favored |
| Short dwell time, limited monitoring maturity | Active, strongly favored |
| Extended dwell time, mature monitoring | Adaptive, strongly favored |
| Unknown scope, uncertain sophistication | Adaptive, preferred |
| Commodity malware on a low-value asset | Passive, possible |
| Controlled deception environment | Passive or deceptive, possible |
Risk levels and what they trigger
Levels from p. 171. The trigger column is mine, and the thresholds should be yours.
| Level | Meaning | What it triggers |
|---|---|---|
| Low | Minor anomaly, minimal impact | Analyst handles it, logged only |
| Medium | Worth investigating, operations unaffected | Incident commander informed, daily update |
| High | Confirmed incident affecting operations or data integrity | Team activated, decision makers briefed, update cadence set |
| Critical | Major incident | Executive escalation, immediate containment authority granted, counsel engaged |