A lot of organisations have invested heavily in Security Operations Centres and Managed Extended Detection and Response (MXDR) services, and with good reason. The sooner you spot a threat, the better chance you have of stopping it. But detection on its own is not the entire picture.
Imagine this:
A responder identifies malicious activity and recommends isolating an endpoint, disabling a compromised account or taking a server offline. Approvals are requested, evidence is debated, people try to work out who owns the decision and senior stakeholders are tracked down.
Attackers do not wait for organisations to work through their governance processes. Once they are inside, every extra minute gives them another opportunity to escalate privileges, move laterally and widen the compromise.
Effective response capability depends heavily on decisions made before the attack begins. That is what we will explore here.
The threat landscape has changed significantly. Attackers no longer need to spend weeks quietly exploring an environment before taking meaningful action. As organisations have improved their ability to detect suspicious activity, attackers have adapted by moving faster.
A compromised identity can provide access to several cloud services at once. Stolen session tokens can bypass normal authentication controls, while legitimate administrative tools can be used to blend in and move across the environment without immediately attracting attention. Speed has become one of the defining characteristics of a modern cyberattack.
The problem is that many incident response processes still operate using a much slower model. A security team detects something suspicious, checks the evidence, contacts the customer, explains the recommendation, waits for approval and escalates if nobody responds.
Every one of those steps appears reasonable in isolation. Together, though, they give the attacker valuable time. Business approval processes tend to operate at organisational speed, while attackers operate at machine speed. Rapid detection has limited value if the organisation cannot respond with the same momentum.
Organisations are naturally hesitant to have an external provider disable an executive account, isolate a production system or interrupt a critical service. This hesitation is understandable.
Containment actions can affect business operations, and they raise valid concerns around privileged access, accountability and governance. Those concerns should not be dismissed.
The word “exception” is tossed around a lot when talking about security governance.
Critical systems are excluded from automated response because they are considered too sensitive. Permissions are withheld because they do not appear necessary during normal operations. Manual approval becomes mandatory for almost every meaningful containment action.
Each exception may seem sensible when it is introduced, but over time those exceptions can create a response model that is incapable of keeping pace with the attack it is supposed to contain.
Pre-agreed authority is how you balance speed with governance. The aim is not to remove control, but to agree the boundaries before the pressure of a live incident. Organisations should define which scenarios justify immediate action, which systems are included, what responders are authorised to do and how every action will be logged, communicated and reviewed.
That gives responders the confidence to act quickly while ensuring the organisation remains in control.
I have seen this play out during a live incident response engagement.
I joined a bridge call that included all the right stakeholders, but the conversation had stopped being about the incident itself. Attention had shifted towards attendance, ownership and internal process: who needed to be on the call, who owned the decision and who had the authority to approve the next step.
Everyone wanted to make the right decision, but nobody was driving the response. While that discussion continued, the attacker was not waiting.
The immediate priority I took was to refocus everyone on what actually mattered: containing the threat before it spread any further. We requested elevated security and administrative permissions so that we could complete the investigation and carry out the necessary containment actions. Once I had explained the severity of the incident to those present, the permissions were granted within minutes – permissions that were not forthcoming for many months prior to this pivotal moment.
With the right access in place, we isolated the affected systems, completed the investigation and prevented the compromise from spreading beyond a small number of devices. The organisation ultimately made the right decision, but it made that decision during the incident, after the situation had already escalated.
That was the real lesson and it shifted my perspective on pre-agreed authority. Decisions about containment authority should be clearly outlined before an attacker is active in the environment, when people have the time and space to consider the risks properly.
During a live incident, the focus should ONLY be on executing the plan.
During a live incident response engagement, I joined a bridge call that included all the right stakeholders.
The problem was that the conversation was no longer about the incident.
Attention had shifted towards attendance, ownership and internal process. Everyone wanted to make the right decision, yet nobody was driving the response.
While everyone was figuring out the next steps, the attacker was not waiting.
The priority was to refocus everyone on what mattered most: containing the threat before it spread.
We requested elevated security and administrative permissions to complete the investigation and execute the necessary containment actions. Once the severity of the incident was understood, those permissions were granted within minutes.
With the appropriate access in place, we isolated affected systems, completed the investigation and prevented the compromise from spreading beyond a small number of devices.
Governance did not fail. The organisation ultimately made the right decision, but only after the incident had escalated. The real lesson is that decisions about containment authority should be made before an attack occurs, ensuring responders can act immediately when every minute matters.
Modern incident response needs clear leadership, trusted responders and predefined authority so action is rapid when every minute counts.
Pre-agreed authority only has value if it works under pressure. A live incident is the worst possible time to discover that responders cannot access a critical platform, that the approval process is unclear or that the only person able to authorise containment is unavailable.
That is why the response model needs to be tested before it is relied upon. Tabletop exercises and technical simulations should validate more than whether the technology produces the right alert. They should test the people, permissions, communication channels and governance processes that support the response.
A useful starting point is to review the following areas.
Now imagine the scenario.
A privileged account has been compromised. Suspicious activity is spreading across several systems and the incident lead recommends isolating a critical server immediately.
What happens next? Does the team act, or does the conversation turn towards approvals, reporting lines and internal hierarchy?
That decision should already have been made. The first time an organisation tests whether someone genuinely has the authority to contain an active threat should not be during a live incident.
Cyber incidents do not pause while organisations work out who is authorised to respond. Governance must operate at the speed of the threat.
Before an incident occurs, organisations and their security partners should agree when immediate containment is justified, what actions responders may take, what access they need, who must be informed and how each decision will be reviewed afterwards.
The organisations that respond best are not always the ones with the largest security teams or the newest technology. More often, they are the ones that have removed uncertainty before the incident begins.
They know who can make the decision, which actions are authorised, which systems can be isolated and what happens when the normal decision-maker is unavailable. That clarity allows the response team to focus on containing the threat rather than navigating internal processes.
Detection matters, but it is only the beginning. If your SOC or MXDR provider identifies a high-confidence threat, they should not have to waste valuable time searching for permission to protect your business.
A famous proverb reads: "The best time to plant a tree was 20 years ago. The second-best time is now." I would add to that: “The worst time to plant a tree is the moment when you need to harvest its fruits.”
Review your incident response model now, please.