Control need · Live incident containment

In a live incident, the only question is how fast can you cut the path.

Detection tells you something is wrong. Containment decides what it costs. If severing a connection means logging into a console, finding the right rule and hoping the change applies, containment is already competing with the attacker for time.

  • Written for executives
  • Incident response context
  • Leads to Blueprint CP-02
  • Provable severance
The connection state today

Containment depends on someone doing the right thing quickly

Severance methodConsole and rule change
Who can actA small number of people
Out of hoursEscalation and delay
Proof of severanceConfiguration screenshots

Need → Control → Blueprint → Modules

Corridor of offline storage racks inside a Firevault bunker
01What is exposed

During an incident, delay is the exposure.

The technical damage is usually decided in the first hour. These are the things that are exposed while the response is still being organised.

01

The minutes before containment

Between detection and effective severance, the attacker keeps moving. Every additional route that stays live extends the eventual scope.

Scope growth
02

The authority to act

Cutting a connection has business consequences, so people hesitate. Without a pre-agreed action, the decision escalates while the clock runs.

Decision delay
03

The recovery position

If recovery copies are still reachable while the incident is live, the organisation can lose the thing it needs to restore from.

Recovery at risk
04

The record of what happened

Regulators, insurers and boards ask what was severed and when. Configuration history is a weak answer to a question about physical state.

Evidence gap
02Why the exposure exists

Containment was designed as a procedure, not as a capability.

Most incident response plans describe who should be called. Far fewer describe a mechanism that physically removes a connection in seconds and proves it afterwards.

The honest position

The plan assumes calm. Incidents are not calm.

Response documents are written in daylight by people with time. They are executed at night by people who are tired, incomplete in number and unsure how far the compromise has already reached. Anything that depends on flawless execution under those conditions will occasionally fail.

Control the path, protect the asset.
Reason 01

Severance is a manual act

Pulling a path apart usually means editing configuration on the very estate that is under attack.

Reason 02

Nobody wants to be wrong

Disconnecting a business system has a cost, so people wait for certainty that never arrives in time.

Reason 03

Control planes share the estate

If the tools used to contain an incident sit inside the affected environment, they may already be compromised.

Reason 04

Out of hours is the norm

Incidents are timed deliberately for weekends and holidays, when the fewest people are available to act.

Reason 05

Evidence is an afterthought

Preserving logs competes with restoring service, and service usually wins.

Reason 06

The plan is rarely rehearsed physically

Tabletop exercises test the conversation. They seldom test whether the path can actually be severed.

03Which path needs controlling

Containment is a list of connections you have already agreed to cut.

Deciding this in advance is what removes hesitation on the night. Each of these is a business decision, taken once, in daylight.

The path or relationshipWho uses itHow it behaves todayWhat Control governs
Internet and external boundaryPublic services and remote usersSevered by rule change under pressureCut physically on signal, restored on approval
Affected zone to the rest of the estateApplications and users in that zoneDepends on segmentation holdingIsolated at hardware level while the incident runs
Third-party and supplier linksVendors and managed service providersOften forgotten during the first hoursClosed automatically as part of the containment action
Recovery copies and evidenceResponse and forensics teamsReachable from the affected environmentHeld with no live path, released under multi-party approval
The Blueprint covers how these actions are triggered, sequenced and reversed, together with the evidence each step produces. This page is here to get the list agreed.
04What physical Control changes

Containment becomes an action, not a project.

The point of physical Control during an incident is that severance is immediate, unambiguous and does not rely on the health of the systems under attack.

Connection state today

Containment by configuration

The response team edits the environment while the attacker is inside it, then tries to confirm the change took effect.

  • Severance takes as long as the console and the approval chain allow
  • Actions are performed on infrastructure that may be compromised
  • Supplier and remote paths are handled last, if at all
  • Proof of containment is a configuration record
  • Restoring service and preserving evidence pull in opposite directions
Connection state with Control

Containment by physical severance

Pre-agreed paths are broken on signal from a control plane that sits outside the affected estate, and the state is visible rather than inferred.

  • Named paths severed immediately, including out of hours
  • A control plane that does not depend on the compromised environment
  • Supplier and remote links closed as part of the same action
  • A physical state that can be shown to insurers and regulators
  • Evidence and recovery copies preserved outside the blast radius
Prevention fails occasionally. Containment has to work every time.Connected when approved. Disconnected by default.
05The Control philosophy

Control the path, protect the asset.

Control treats connectivity as something to be governed deliberately. In an incident, that means the severance decision is made in advance and executed physically.

01

Start with the path, not the tool

Every incident that spreads does so along a connection that was already there. Control begins by naming that connection in plain language, before anyone talks about products.

02

Make the default state disconnected

A path that exists only when it is needed cannot be used at three in the morning by someone who should not have it. Disconnection is the resting state, not the emergency response.

03

Open on approval, close on schedule

When work genuinely needs a connection, Control opens it for a named person, a stated purpose and a fixed period, then closes it again without anyone having to remember.

04

Prove it physically, not on paper

A policy says the path should be closed. Physical control shows that it is. That difference is what auditors, insurers and boards are actually asking about.

How this fits together

Your need sets the direction. Control sets the rule. The Blueprint sets the architecture.

NeedControlBlueprintModules and Firebreak
06Where this goes next

The Blueprint for this need is CP-02 Contain Active Breaches

With the containment list agreed, the Blueprint sets out how those actions are wired, triggered and reversed, and what each step leaves behind as evidence.

CP-02 · Lead layer FIRE

Contain Active Breaches

When prevention fails, containment must be physical, immediate and provable.

Modules the Blueprint leads with

Applied to live incident containment and recovery. The Blueprint page carries the architecture, the zone detail and the deployment sequence.

Why it is worth exploring

What you get from the Blueprint that this page does not cover

  • How severance is triggered, by whom and under what authority
  • The out-of-band control plane that stays reachable during an incident
  • Sequencing so containment does not destroy the evidence you need
  • How normal service is restored in a controlled, approved order
  • The audit record produced for regulators, insurers and the board
A different job

This page is about severing paths while an incident is running. Preserving the data and evidence you will rebuild from is a different job, and it belongs in Offline Secure Storage rather than in a containment plan.

Protect the copies you rebuild from
Questions

What boards ask about containment.

The questions that come up when an incident response plan is reviewed rather than written.

Severance actions are defined in advance, scoped to named paths and held under authority controls. The intention is to remove hesitation about agreed actions, not to give anyone a general off switch.
Need → Control → Blueprint

Agree the containment list. Then design how it fires.

CP-02 Contain Active Breaches sets out the architecture, the triggers and the evidence trail behind physical containment.