The humans took too long.
That's the finding, and the rest of the chain is worth walking precisely because nothing else in it went wrong. The user clicked the link, the malware downloaded, it called out and got the scripts, it infected the endpoint and took files. The XDR saw it immediately. It filed an alert, the SOC read that alert inside the SLA, and the SOC escalated for action.
Every control performed. The files left anyway.
Now put the published numbers against that sequence. CrowdStrike clocked average eCrime breakout time at 29 minutes last year, a 65 percent jump in speed over 2024, and the fastest breakout they have ever recorded ran 27 seconds. In one intrusion they documented, the data started moving four minutes after initial access.
Four minutes. Find your approval step in that window.
In one I know of, the approval came back 52 minutes after the escalation went out.
The analyst does skilled work and gets to the right answer quickly, and then the playbook stops, because it runs in recommend-only mode. The escalation goes to whoever holds containment authority, and in a lot of programs that name lives on a rotating spreadsheet nobody has updated since somebody changed teams in the spring. Now assume the best case. The approver gets it, reads it, and approves it without hesitating, and the loop still takes longer to run than the attack took.
Ask why the gate is there and you'll get a story, and the story is usually true. Somebody isolated a domain controller during business hours once and took out a chunk of the company before lunch. The gate went in as the fix, and for that specific problem it was the right fix.
Then nobody narrowed it. Containment actions require approval, all of them, and one bad afternoon has been pricing the entire playbook library ever since at the value of the worst thing that ever happened inside it. So the quarantine on a marketing intern's mailbox waits behind the same signature as severing a payment path.
Sort by what a false positive actually costs and the library comes apart into two piles fast. Isolating a user endpoint costs that person a few minutes and a help desk ticket you'll hear about in the morning. That's the whole downside. The other pile is real, and it has earned the gate it has.
Run that sort regardless of bias or past. Judge each action on what it costs today, not on the incident that put the gate there and not on how badly the vendor demo went in the bake-off. Then take all the easy ones, especially the ones that only ever touch a user endpoint, and take the operator delay out of them. A pilot on one playbook proves nothing you don't already know and buys another quarter of the same delay.
So, here's the MondayMove
Audit every containment action you own for where automation can close the loop, regardless of bias or past, then turn the approval step off all the easy ones. Start with user endpoints. All of them, this week.
It's better to disrupt a user for a few moments than to spend a quarter on the cleanup of a data exfiltration.
Discussion