WEEK 35 · DETECTION

Take the operator delay out of every containment action that can only annoy somebody.

Every control in the chain performed to spec, the SOC hit its SLA, and the files left anyway, because the approval step is the only component still running at human speed.

The humans took too long.

That's the finding, and the rest of the chain is worth walking precisely because nothing else in it went wrong. The user clicked the link, the malware downloaded, it called out and got the scripts, it infected the endpoint and took files. The XDR saw it immediately. It filed an alert, the SOC read that alert inside the SLA, and the SOC escalated for action.

Every control performed. The files left anyway.

Now put the published numbers against that sequence. CrowdStrike clocked average eCrime breakout time at 29 minutes last year, a 65 percent jump in speed over 2024, and the fastest breakout they have ever recorded ran 27 seconds. In one intrusion they documented, the data started moving four minutes after initial access.

Four minutes. Find your approval step in that window.

In one I know of, the approval came back 52 minutes after the escalation went out.

The analyst does skilled work and gets to the right answer quickly, and then the playbook stops, because it runs in recommend-only mode. The escalation goes to whoever holds containment authority, and in a lot of programs that name lives on a rotating spreadsheet nobody has updated since somebody changed teams in the spring. Now assume the best case. The approver gets it, reads it, and approves it without hesitating, and the loop still takes longer to run than the attack took.

Ask why the gate is there and you'll get a story, and the story is usually true. Somebody isolated a domain controller during business hours once and took out a chunk of the company before lunch. The gate went in as the fix, and for that specific problem it was the right fix.

Then nobody narrowed it. Containment actions require approval, all of them, and one bad afternoon has been pricing the entire playbook library ever since at the value of the worst thing that ever happened inside it. So the quarantine on a marketing intern's mailbox waits behind the same signature as severing a payment path.

Sort by what a false positive actually costs and the library comes apart into two piles fast. Isolating a user endpoint costs that person a few minutes and a help desk ticket you'll hear about in the morning. That's the whole downside. The other pile is real, and it has earned the gate it has.

Run that sort regardless of bias or past. Judge each action on what it costs today, not on the incident that put the gate there and not on how badly the vendor demo went in the bake-off. Then take all the easy ones, especially the ones that only ever touch a user endpoint, and take the operator delay out of them. A pilot on one playbook proves nothing you don't already know and buys another quarter of the same delay.

So, here's the MondayMove

Audit every containment action you own for where automation can close the loop, regardless of bias or past, then turn the approval step off all the easy ones. Start with user endpoints. All of them, this week.

It's better to disrupt a user for a few moments than to spend a quarter on the cleanup of a data exfiltration.

Friday Follow-Up

The pile nobody turns off.

Building the two piles is analysis. Turning the gate off is a decision with a name attached, and that is where I expect most teams to stop this week.

MondayMove gives you one concrete action every Monday. FridayFollowUp closes the loop.

Each Friday, a short dispatch on what practitioners actually found when they ran the week's move: where they got stuck, what surprised them, and what to do next. Not sanitized case studies. Field notes. Practitioner to practitioner.

Audit and act where it matters. That was Monday, stated plainly: sort every containment action by what a false positive costs, then take the operator delay out of all the easy ones. Here is where I expect it to break.

The word endpoint is the first place it stalls. It feels obvious for about twenty minutes, right up until somebody raises the workstation in the lab that runs a nightly job, or the laptop belonging to the person who signs the budget. The list stops being clean, the meeting starts negotiating, and an afternoon of work turns into a standing agenda item.

Then the audit happens and the act doesn't. Two piles get built, somebody makes a deck out of them, and the approval step stays exactly where it was, because building the piles is analysis and turning the gate off is a decision with a name attached. That's the failure mode I would watch hardest. Nobody defends a deck.

Expect the bias to arrive as a flat sentence rather than an argument. Someone says we can't automate isolation, and what they mean is that we couldn't automate isolation in 2019, on a platform nobody here runs anymore. Ask when that assessment got made. Half the time nobody in the room can answer, which is your answer.

The service desk conversation is the one I expect to surprise people most. Walk over and ask which machines generate a phone call inside four minutes of going dark. They will answer immediately, without looking anything up, and they will be right, and somebody on your team will spend the rest of the week wondering why that list has never been written down anywhere.

One prediction I actually enjoy. Somewhere out there a team is going to find that the approval step was never the slow part, that the SOAR integration has read access and never got write, and the gate everyone has been arguing about has been decorative for two years.

For the pile you did not automate, write the one condition that would change your mind and put a date on revisiting it. Otherwise that pile is permanent and all you did this week was formalize it. Start the weekly read today even if you only turned off one thing. Ten actions, twenty minutes, right or wrong written next to each one.

Take all the easy ones.

Keep going. See what a week can do.

No correct answers here. This is practitioner-to-practitioner. The more honest the responses, the more useful this gets for everyone reading on Monday morning.

See you then.

Discussion