• Home
  • Blog
  • Stories from the SOC: Why Cyber Incident Response Needs Pre-Agreed Authority
Blog Banners
Stories from the SOC: Why Cyber Incident Response Needs Pre-Agreed Authority
8:09

Detection is only the beginning.

A lot of organisations have invested heavily in Security Operations Centres and Managed Extended Detection and Response (MXDR) services, and with good reason. The sooner you spot a threat, the better chance you have of stopping it. But detection on its own is not the entire picture. 

Imagine this:

A responder identifies malicious activity and recommends isolating an endpoint, disabling a compromised account or taking a server offline. Approvals are requested, evidence is debated, people try to work out who owns the decision and senior stakeholders are tracked down.

Attackers do not wait for organisations to work through their governance processes. Once they are inside, every extra minute gives them another opportunity to escalate privileges, move laterally and widen the compromise.

Effective response capability depends heavily on decisions made before the attack begins. That is what we will explore here. 

The Modern Attack is Machine Speed 

The threat landscape has changed significantly. Attackers no longer need to spend weeks quietly exploring an environment before taking meaningful action. As organisations have improved their ability to detect suspicious activity, attackers have adapted by moving faster.

A compromised identity can provide access to several cloud services at once. Stolen session tokens can bypass normal authentication controls, while legitimate administrative tools can be used to blend in and move across the environment without immediately attracting attention. Speed has become one of the defining characteristics of a modern cyberattack.

The problem is that many incident response processes still operate using a much slower model. A security team detects something suspicious, checks the evidence, contacts the customer, explains the recommendation, waits for approval and escalates if nobody responds.

Every one of those steps appears reasonable in isolation. Together, though, they give the attacker valuable time. Business approval processes tend to operate at organisational speed, while attackers operate at machine speed. Rapid detection has limited value if the organisation cannot respond with the same momentum. 

“Governance is my friend,” said the Attacker 

Organisations are naturally hesitant to have an external provider disable an executive account, isolate a production system or interrupt a critical service. This hesitation is understandable.

Containment actions can affect business operations, and they raise valid concerns around privileged access, accountability and governance. Those concerns should not be dismissed.  

The word “exception” is tossed around a lot when talking about security governance.

Critical systems are excluded from automated response because they are considered too sensitive. Permissions are withheld because they do not appear necessary during normal operations. Manual approval becomes mandatory for almost every meaningful containment action.

Each exception may seem sensible when it is introduced, but over time those exceptions can create a response model that is incapable of keeping pace with the attack it is supposed to contain.

Pre-agreed authority is how you balance speed with governance. The aim is not to remove control, but to agree the boundaries before the pressure of a live incident. Organisations should define which scenarios justify immediate action, which systems are included, what responders are authorised to do and how every action will be logged, communicated and reviewed.

That gives responders the confidence to act quickly while ensuring the organisation remains in control.

Anecdote: I Ignored Governance to Facilitate Response 

I have seen this play out during a live incident response engagement.

I joined a bridge call that included all the right stakeholders, but the conversation had stopped being about the incident itself. Attention had shifted towards attendance, ownership and internal process: who needed to be on the call, who owned the decision and who had the authority to approve the next step.

Everyone wanted to make the right decision, but nobody was driving the response. While that discussion continued, the attacker was not waiting.

The immediate priority I took was to refocus everyone on what actually mattered: containing the threat before it spread any further. We requested elevated security and administrative permissions so that we could complete the investigation and carry out the necessary containment actions. Once I had explained the severity of the incident to those present, the permissions were granted within minutes – permissions that were not forthcoming for many months prior to this pivotal moment. 

With the right access in place, we isolated the affected systems, completed the investigation and prevented the compromise from spreading beyond a small number of devices. The organisation ultimately made the right decision, but it made that decision during the incident, after the situation had already escalated. 


That was the real lesson and it shifted my perspective on pre-agreed authority. Decisions about containment authority should be clearly outlined before an attacker is active in the environment, when people have the time and space to consider the risks properly. 

During a live incident, the focus should ONLY be on executing the plan. 

When Governance Delays Response

During a live incident response engagement, I joined a bridge call that included all the right stakeholders.

The problem was that the conversation was no longer about the incident.

Attention had shifted towards attendance, ownership and internal process. Everyone wanted to make the right decision, yet nobody was driving the response.

While everyone was figuring out the next steps, the attacker was not waiting.

The priority was to refocus everyone on what mattered most: containing the threat before it spread.

We requested elevated security and administrative permissions to complete the investigation and execute the necessary containment actions. Once the severity of the incident was understood, those permissions were granted within minutes.

With the appropriate access in place, we isolated affected systems, completed the investigation and prevented the compromise from spreading beyond a small number of devices.

Governance did not fail. The organisation ultimately made the right decision, but only after the incident had escalated. The real lesson is that decisions about containment authority should be made before an attack occurs, ensuring responders can act immediately when every minute matters.

Modern incident response needs clear leadership, trusted responders and predefined authority so action is rapid when every minute counts.

What Pre-Agreed Authority Should Include

Pre-agreed authority only has value if it works under pressure. A live incident is the worst possible time to discover that responders cannot access a critical platform, that the approval process is unclear or that the only person able to authorise containment is unavailable.

That is why the response model needs to be tested before it is relied upon. Tabletop exercises and technical simulations should validate more than whether the technology produces the right alert. They should test the people, permissions, communication channels and governance processes that support the response.

A useful starting point is to review the following areas.

  1. Validate Responder Access – Confirm that responders have the permissions they need to investigate and contain credible threats without having to request emergency access. Do not assume those permissions can simply be arranged during an incident. Test them and make sure they work.
  2. Test Containment Actions – Verify that responders can isolate endpoints, disable accounts, revoke sessions and block malicious activity as expected. A playbook saying an action is possible is not the same as proving it works in your environment. 
  3. Review Escalation Paths – Make sure incident severity levels, decision-makers and escalation routes are clearly defined and understood. It should be obvious who owns the decision during normal working hours, but also who owns it at 2:00 on a Sunday morning. 
  4. Confirm Communication Plans – Identify alternative communication channels in case the organisation’s normal email or collaboration platforms are unavailable or compromised. You do not want to design the communication plan while also trying to work out whether the attacker can read the conversation. 
  5. Exercise Executive Decision-Making – Leadership teams should understand when pre-agreed authority applies and what actions responders are authorised to take. They need to be comfortable supporting rapid containment without restarting the entire approval process during the incident. 
  6. Review & Improve – Every exercise should result in practical actions. Update the playbooks, resolve access issues, clarify responsibilities and remove unnecessary exceptions. The goal is not to prove the process works perfectly, but to find the gaps before an attacker does. 

Now imagine the scenario.

A privileged account has been compromised. Suspicious activity is spreading across several systems and the incident lead recommends isolating a critical server immediately.

What happens next? Does the team act, or does the conversation turn towards approvals, reporting lines and internal hierarchy?

That decision should already have been made. The first time an organisation tests whether someone genuinely has the authority to contain an active threat should not be during a live incident. 

Decide Before the Attacker Does

Cyber incidents do not pause while organisations work out who is authorised to respond. Governance must operate at the speed of the threat. 

Before an incident occurs, organisations and their security partners should agree when immediate containment is justified, what actions responders may take, what access they need, who must be informed and how each decision will be reviewed afterwards.

The organisations that respond best are not always the ones with the largest security teams or the newest technology. More often, they are the ones that have removed uncertainty before the incident begins.

They know who can make the decision, which actions are authorised, which systems can be isolated and what happens when the normal decision-maker is unavailable. That clarity allows the response team to focus on containing the threat rather than navigating internal processes.

Detection matters, but it is only the beginning. If your SOC or MXDR provider identifies a high-confidence threat, they should not have to waste valuable time searching for permission to protect your business.  

A famous proverb reads: "The best time to plant a tree was 20 years ago. The second-best time is now." I would add to that: “The worst time to plant a tree is the moment when you need to harvest its fruits.” 

Review your incident response model now, please. 

Book a 30-minute cyber preparedness discussion to assess whether your incident response model gives responders the authority, access and governance they need to contain threats without delay. 

Share this post

Related Articles