
The containment paradox: Why your ransomware playbook has the wrong people in charge
I have sat in on a version of the same incident post-mortem in three sectors over the past two years. The script does not vary much. At 4:47 a.m. on a Saturday, an on-duty SOC analyst sees a ransomware payload spreading across three servers in the data center. The playbook says isolate. They hit the switch. Sixteen minutes later the CFO is on the phone: Those three servers were the production payment gateway. The malware would likely have reached a dozen more endpoints. The isolation took down revenue for fourteen hours. The Monday morning question from the board is not how the attacker got in. It is who, in the organization, was authorized to make a decision of this commercial magnitude at ...