A desk head refuses to let you isolate a trading workstation with a live intruder on it. What now?
answer
- not your risk to accept, or theirs
- price both sides in their terms
- the choice is rarely binary
- escalate to who can accept the loss
- agree the override line before the incident
basics
~20 sNeither the SOC nor the desk head owns that call alone. Price both outcomes, escalate to the executive accountable for the firm's risk, offer a bounded watch with tripwires or a move to a spare workstation, and record who decided what and when.
solid answer
~50 sTreat it as a risk-acceptance decision that only someone empowered to accept it can make. Your job as incident lead is to make the choice explicit and priced: minutes of desk downtime and the revenue attached, against a hands-on operator whose next reachable systems include payments, with the regulatory and customer exposure that carries. The desk head can argue the first number; they cannot unilaterally accept the second for the firm, so escalate to the named executive who can. Meanwhile offer the options that are not binary: move the trader to a spare workstation and cut this one, or run a bounded watch with written tripwires and a pre-staged cut. Record the decision, the person, the time and what they were told. If this is the first use of that escalation path, the real defect is that the override line was never agreed beforehand.
go deeper
Know that you do not make this call: escalate to the incident lead with what you observed, and keep collecting while the decision is being made.
Be ready to supply the facts the decision needs — what the host can reach, what the intruder has done so far, what containment would and would not stop — without editorialising the business side.
Show that you offer non-binary options, pre-stage the cut while the argument runs, and can state the security risk precisely enough for a non-technical owner to weigh it.
Own the authority question itself: who may accept this risk, what the default is when they are unreachable, which behaviours are never overridable, and how that matrix gets agreed with the business before an incident forces it.
## What kind of problem this actually is The instinct is to argue about whether security or the business wins. That framing loses the argument and misdescribes the situation. Nobody in the room owns this decision: the analyst does not, the incident lead does not, and the desk head does not either. What is being proposed is that the firm knowingly accept a period of continued adversary access in exchange for continued revenue. Accepting risk on behalf of the firm is an executive act, and the lead's job is to route it to the person who can perform it — quickly, with the tradeoff stated in terms they can act on. ## Price both sides, honestly The business side is knowable and you should not guess at it: ask the desk head what an outage costs, and how long. "The desk is mid-session, cutting it now means N minutes dark and these positions unmanaged" is a real number and treating it as an obstacle rather than an input is how security loses standing. The security side has to be stated with the same discipline, and this is where weak answers hand-wave. Not "there is a hacker on the machine" but: an operator is working interactively; from this host the reachable systems include X and Y; if they reach the payments path the exposure is customer funds and a regulatory notification with a clock attached; and every minute we watch, they choose the next move, not us. Say what you know and what you do not — overstating certainty to win the argument destroys the credibility you will need in the next incident. ## Do not present it as a binary The strongest move is usually to dissolve the choice: - **Move the work, not the risk.** What is revenue-bearing is the trader's ability to trade, not this specific chassis. A spare workstation, a different session, a colleague covering the book for twenty minutes — the desk head often has an option you do not know about, and asking produces it. - **Bounded watch with a hard trigger.** If scope genuinely is unknown and watching buys it, propose a written window with tripwires that fire the cut instantly, a named expiry, and the containment pre-staged. Now the desk head is agreeing to a control, not to an open-ended gamble, and you have made their preference survivable. - **Partial containment.** Constrain the blast radius without going fully dark: allowlist the trading application's destinations while cutting everything else. It is weaker than isolation and must be described as weaker, but it is sometimes the honest middle. ## Escalate properly If the desk head still refuses and no middle option works, escalate — without theatre. Go to the accountable executive with a one-paragraph statement: what is happening, the two options, the cost of each, your recommendation, and the decision needed now. Say that the desk head has been consulted and objects, and why; ambushing them makes an enemy for every future incident. And know the floor. Some behaviours are not available for business override: reaching client money systems, a regulatory reporting trigger, active destruction. Those thresholds should be written in the response plan and agreed in advance, so that at 03:00 you are invoking an agreement rather than inventing an authority you do not have. ## Write it down Whichever way it goes, record it: the decision, who made it, when, what they were told about the risk, and the conditions attached. This is not blame-shifting — it is what lets the firm review a genuinely difficult call afterwards, and what protects both the analyst who followed the instruction and the executive who made a reasonable call on incomplete information. ## The real finding If you are having this argument for the first time during a live intrusion, the incident response plan is incomplete. The output of this incident is a standing agreement with the business: which asset classes may be contained unilaterally by the SOC, which require an owner's agreement, who can be reached out of hours, what the default is if they cannot be reached, and which behaviours override the conversation entirely. Getting those decided while nobody is under pressure is worth more than winning this particular argument. A candidate who ends there — turning a 03:00 standoff into a pre-agreed containment authority matrix — is showing the judgment the question is actually testing.
- The executive is unreachable and the operator is still active. What is your default?Contain. If nobody empowered to accept the risk can be reached, nobody is accepting it, and the safe default has to be the one that stops harm — which is why the default belongs in the response plan rather than in your judgment at the time. Document the attempts to reach them, the time, and the basis for acting. An unanswered phone is a decision made by absence, and the plan should have decided which way it falls.
- How do you avoid this becoming a standing fight with the business after the incident?Convert it into an agreement while nobody is under pressure: a containment authority matrix naming which systems the SOC can isolate unilaterally, which need the owner, who is reachable out of hours, the default when they are not, and the behaviours that override the conversation. Bring the desk head into writing it — people defend rules they helped set, and the argument you had becomes the evidence for why the rule is needed.
- The desk head asks why you can't just watch until the market closes. How do you answer?By making the terms explicit rather than refusing outright. Watching until close may be acceptable if it is bounded by tripwires that fire the cut instantly, someone is on the live session continuously, the containment is pre-staged, and a named executive has accepted the residual risk. What is not acceptable is watching because containment is inconvenient — the difference is whether the watch is still buying scope you lack.
saying these in an interview costs you the question
- Isolates anyway, asserting security overrides the business
- Accepts the refusal and simply keeps monitoring with no terms
- Presents the risk without pricing the business cost
- Treats the desk head's refusal as the final word without escalating
- Overstates certainty about the intruder's intent to win the argument
- Leaves no record of who accepted the risk and when