Before you agree to watch a live intruder instead of isolating the host, what must be written down?
answer
- a watch needs an ending, decided first
- name the behaviour, not the feeling
- time box plus named authoriser
- the cut is pre-staged and rehearsed
- seconds to act when the tripwire fires
basics
~20 sThe named behaviours that trigger immediate containment, a time box with a review point, the specific scope questions the watch is meant to answer, the person who authorised it, and who is on the keyboard with the cut pre-staged and rehearsed.
solid answer
~50 sA watch without a written stop condition is not a decision, it is a delay. Before it starts, write down: the tripwires — concrete, observable behaviours that end the watch instantly, such as the operator authenticating to a payments host, staging an archive, creating an account, or touching backups; a time box with an explicit review rather than open-ended continuation; the questions the watch exists to answer, so you can tell when it has stopped paying; who authorised it by name, because someone is accepting the residual risk; who is watching continuously, with a named handover if the window crosses a shift; and the containment action itself, pre-staged and rehearsed, because a tripwire gives you seconds. The watch turns indefensible the moment it stops buying scope you lack, or the moment you could not execute the cut fast enough to matter.
go deeper
Know that watching instead of containing is only legitimate when someone senior has authorised it and a stop condition exists — and that your job in the window is continuous attention, not periodic checking.
Be able to turn 'we will watch a while' into concrete tripwires, an expiry and a rehearsed cut, and explain why each one exists.
Show that you write the terms before the watch, run the handover as a transfer of an open investigation, and can name the point at which the watch stops paying and must end early.
Own the standing version: which asset classes may never be watched rather than contained, who is empowered to authorise a watch out of hours, and how those terms were agreed before an incident rather than at 03:00.
## Why the decision needs a written form Watching a live intruder instead of containing them is a defensible choice: it is often the only way to learn how far the intrusion reaches, which credentials are in active use, and whether a second access path exists that your artefacts would never reveal. It is also the choice that looks worst in hindsight if harm lands during the window. The difference between good judgment and negligence, after the fact, is almost entirely whether the terms were set in advance and honoured. So the deliverable is short and specific, and it is written before the watch begins. ## The six things to write down **1. The stop condition, as observable behaviour.** Not "if it gets serious". Name the events: the operator authenticating to a host in the payments or settlement path; enumerating or mounting backups; creating or modifying an account or adding a credential to one; staging a compressed archive; deploying tooling to a second host; any sustained outbound transfer. Each one should be something the watcher can recognise in the telemetry they are actually looking at, in the moment, without needing a second opinion. A tripwire that requires a meeting to interpret is not a tripwire. **2. A time box, with a review rather than a default.** "Until 06:00, then the incident lead re-decides" is a control. "Until we understand the scope" is not, because that condition can never be observed to fail. The review must have a default of containment if the authoriser cannot be reached. **3. The questions the watch is buying answers to.** Typically: which accounts are they using right now, which hosts have they touched, is there a second route in, and what are they going for. Writing these down gives you the test for whether the watch is still worth its risk — if two hours of watching has answered none of them and produced no new leads, the watch has stopped paying and should end regardless of the clock. **4. The authoriser, by name.** Someone is accepting the residual risk of harm during the window, and it is not the analyst at the console. Record who, when, and what they were told — including the specific harm scenarios you raised. This is also the record that protects the analyst who followed the instruction. **5. Continuous watching, with an explicit handover.** A watch is only as good as the attention on it. Someone must be looking at the live session view for the whole window, not checking in every twenty minutes. If the window crosses a shift boundary, the handover transfers the current hypothesis, the tripwires, the authorisation and its expiry — the incoming person inherits an open investigation and a live adversary, and must be able to pull the trigger without re-deriving why. **6. The pre-staged cut.** The containment action is prepared and rehearsed before the watch starts: the isolation command ready to execute, the accounts to be disabled identified, the credentials to be rotated listed, the vendor or network contact standing by if the cut is bigger than one host, and the business owner already warned that it may happen. When a tripwire fires you have seconds, not minutes. A watch you cannot end quickly is not a watch; it is a spectator sport. ## Also worth capturing during the window Capture telemetry continuously and deliberately rather than relying on default retention — the whole point is that the window will be reconstructed later, by you and possibly by others. Log the watchers' own timeline as you go: what you saw, when, and what you concluded. Reconstructing an eight-hour watch from memory a week later is the failure mode that turns a good decision into an indefensible one. ## When the watch turns indefensible Three lines, and a candidate who names them is showing real judgment: - **It has stopped buying scope.** You are watching to confirm what you already know. Every further minute is risk with no return. - **You cannot execute the cut in time.** If the pre-staged action decayed — the authoriser went home, the network contact went off shift, the responder stepped away — the tripwire has no teeth and the watch must end. - **The potential harm crossed a line you could not argue you should have permitted.** Reaching systems whose compromise triggers regulatory obligations, customer harm, or irreversible destruction. Beyond that line, the argument "we were still learning" does not survive contact with anyone reviewing it afterwards. The crisp version: a watch is a control with an expiry, a trigger and an owner. Missing any one of the three and you are not watching, you are hoping.
- The watch window crosses a shift change. What has to travel in the handover?The current hypothesis about the intruder and what is still unknown; the tripwires verbatim; the authorisation, who gave it and when it expires; the pre-staged containment action and confirmation the incoming analyst can execute it; the timeline so far. The incoming person inherits a live adversary and must be able to pull the trigger without re-deriving the reasoning. If any of that cannot be transferred cleanly, contain rather than hand over.
- Four hours into an authorised watch, nothing new has been learned. What do you do?End it. The watch was authorised to answer specific scope questions; if it has stopped producing answers or new leads, every further minute is pure risk with no return. Report that plainly to the authoriser rather than letting the time box quietly run out — the expiry is a backstop, not the criterion. Then contain on the plan you already rehearsed.
- Why does the time box need a default action if the authoriser can't be reached?Because otherwise the watch continues by inertia, which is exactly the outcome nobody chose. The default must be containment: at expiry, if the person who accepted the risk is unavailable to re-accept it, nobody is accepting it any more. Writing that down turns an unreachable phone into a decision rather than a drift.
saying these in an interview costs you the question
- Describes the stop condition as 'if it looks serious'
- Runs an open-ended watch with no expiry or review point
- Lets the analyst at the console carry the risk decision alone
- Starts watching before the containment action is prepared
- Checks in periodically instead of watching continuously
- Reconstructs the window from memory afterwards