Detection is only the beginning.
Many organisations have invested in Security Operations Centres (SOC) and Managed Extended Detection and Response (MXDR) services to spot threats sooner. But early detection alone does not reduce business risk, the real test of resilience is how quickly you can contain an active threat and protect operations before disruption occurs.
This is where many response processes begin to fail. A responder spots malicious activity and recommends isolating an endpoint, disabling a compromised account or taking a server offline. Progress then slows as approvals are requested, evidence is debated and decision-makers are tracked down.
Meanwhile, the attacker continues moving through the environment.
Attackers do not wait while organisations work through governance. Once inside, every minute gives them more opportunity to escalate privileges, move laterally and widen the compromise.
Effective incident response depends on decisions made before an attack begins.
Pre-agreed authority does not remove governance or hand over unrestricted control. It means defining in advance when immediate containment is justified, who can act, and what controls keep every action accountable.
When the evidence is clear, responders should be able to contain the threat at once, not wait for permission while the attack continues.
The threat landscape has changed dramatically. Attackers no longer spend weeks quietly exploring before acting. As detection improves, adversaries have adapted by moving faster.
A compromised identity can open access to multiple cloud services at once. Stolen session tokens can bypass authentication. Attackers use legitimate admin tools to blend in and move quickly towards their goals.
Speed has become a defining characteristic of modern cyber attacks.
The sad reality is that many response processes still follow a slower model. Security teams detect suspicious activity, check the evidence, contact the customer, explain the recommendation, wait for approval and escalate if needed before taking action.
Each step appears reasonable in isolation. However, collectively, they provide attackers with valuable time.
Business approval processes often operate at organisational speed. Meanwhile, attackers operate at incident speed. This means that rapid detection means little if you cannot respond with the same urgency.
The hesitation is understandable, no organisation wants an external provider disabling executive accounts, isolating production systems or interrupting critical services without oversight. Containment actions affect business operations and raise valid concerns about privileged access, accountability and governance.
These concerns are entirely valid. Over time, organisations introduce exceptions to reduce disruption. Examples of these are the following:
Pre-agreed authority solves the challenge of not keeping pace with modern cyber attacks without compromising governance.
The goal is to set clear boundaries before an incident. Then, define which threat scenarios justify immediate action, which systems are included, what containment is authorised and how every action will be logged, communicated and reviewed.
During a live incident response engagement, I joined a bridge call that included all the right stakeholders.
The problem was that the conversation was no longer about the incident.
Attention had shifted towards attendance, ownership and internal process. Everyone wanted to make the right decision, yet nobody was driving the response.
While everyone was figuring out the next steps, the attacker was not waiting.
The priority was to refocus everyone on what mattered most: containing the threat before it spread.
We requested elevated security and administrative permissions to complete the investigation and execute the necessary containment actions. Once the severity of the incident was understood, those permissions were granted within minutes.
With the appropriate access in place, we isolated affected systems, completed the investigation and prevented the compromise from spreading beyond a small number of devices.
Governance did not fail. The organisation ultimately made the right decision, but only after the incident had escalated. The real lesson is that decisions about containment authority should be made before an attack occurs, ensuring responders can act immediately when every minute matters.
Modern incident response needs clear leadership, trusted responders and predefined authority so action is rapid when every minute counts.
Pre-agreed authority only delivers value if it works under pressure. An incident is the worst time to discover responders lack access to critical systems, approval paths are unclear or key decision-makers are unavailable.
Regular testing helps uncover these gaps before they affect a real response. Tabletop exercises and technical simulations should validate not only the technology but also the people, processes and governance supporting incident response.
Use the following checklist to assess whether your organisation is ready:
Now imagine the scenario.
A privileged account has been compromised. Suspicious activity is spreading across multiple systems. The incident lead recommends isolating a critical server immediately.
Does the team act? Or does the discussion turn to approvals, hierarchy and process?
That decision should already have been made. The first time your organisation tests its authority to contain an active threat should not be during a live incident.
Cyber incidents do not pause while organisations determine who has authority to respond. Governance must match the speed of today’s threats.
Before an incident, organisations and their security partner should agree when immediate containment is justified, what actions responders can take, what access they need, who must be informed and how every decision will be reviewed.
The organisations that respond best are rarely those with the largest security teams or the newest technology. Rather, they are the ones that remove uncertainty before an incident begins.
If your SOC or MXDR provider identifies a high-confidence threat, they should not waste valuable minutes seeking permission to protect your business.
Review whether your incident response model gives trusted responders the authority, access and playbooks they need to act decisively when it matters.