The minutes before containment
Between detection and effective severance, the attacker keeps moving. Every additional route that stays live extends the eventual scope.
Scope growthDetection tells you something is wrong. Containment decides what it costs. If severing a connection means logging into a console, finding the right rule and hoping the change applies, containment is already competing with the attacker for time.
Need → Control → Blueprint → Modules

The technical damage is usually decided in the first hour. These are the things that are exposed while the response is still being organised.
Between detection and effective severance, the attacker keeps moving. Every additional route that stays live extends the eventual scope.
Scope growthCutting a connection has business consequences, so people hesitate. Without a pre-agreed action, the decision escalates while the clock runs.
Decision delayIf recovery copies are still reachable while the incident is live, the organisation can lose the thing it needs to restore from.
Recovery at riskRegulators, insurers and boards ask what was severed and when. Configuration history is a weak answer to a question about physical state.
Evidence gapMost incident response plans describe who should be called. Far fewer describe a mechanism that physically removes a connection in seconds and proves it afterwards.
Response documents are written in daylight by people with time. They are executed at night by people who are tired, incomplete in number and unsure how far the compromise has already reached. Anything that depends on flawless execution under those conditions will occasionally fail.
Control the path, protect the asset.Pulling a path apart usually means editing configuration on the very estate that is under attack.
Disconnecting a business system has a cost, so people wait for certainty that never arrives in time.
If the tools used to contain an incident sit inside the affected environment, they may already be compromised.
Incidents are timed deliberately for weekends and holidays, when the fewest people are available to act.
Preserving logs competes with restoring service, and service usually wins.
Tabletop exercises test the conversation. They seldom test whether the path can actually be severed.
Deciding this in advance is what removes hesitation on the night. Each of these is a business decision, taken once, in daylight.
The point of physical Control during an incident is that severance is immediate, unambiguous and does not rely on the health of the systems under attack.
The response team edits the environment while the attacker is inside it, then tries to confirm the change took effect.
Pre-agreed paths are broken on signal from a control plane that sits outside the affected estate, and the state is visible rather than inferred.
Control treats connectivity as something to be governed deliberately. In an incident, that means the severance decision is made in advance and executed physically.
Every incident that spreads does so along a connection that was already there. Control begins by naming that connection in plain language, before anyone talks about products.
A path that exists only when it is needed cannot be used at three in the morning by someone who should not have it. Disconnection is the resting state, not the emergency response.
When work genuinely needs a connection, Control opens it for a named person, a stated purpose and a fixed period, then closes it again without anyone having to remember.
A policy says the path should be closed. Physical control shows that it is. That difference is what auditors, insurers and boards are actually asking about.
With the containment list agreed, the Blueprint sets out how those actions are wired, triggered and reversed, and what each step leaves behind as evidence.
When prevention fails, containment must be physical, immediate and provable.
Applied to live incident containment and recovery. The Blueprint page carries the architecture, the zone detail and the deployment sequence.
This page is about severing paths while an incident is running. Preserving the data and evidence you will rebuild from is a different job, and it belongs in Offline Secure Storage rather than in a containment plan.
Protect the copies you rebuild fromThe questions that come up when an incident response plan is reviewed rather than written.
CP-02 Contain Active Breaches sets out the architecture, the triggers and the evidence trail behind physical containment.