In a ransomware playbook, what must pre-delegated authority to disconnect the virtualisation management network specify?
answer
- delegate, do not escalate
- trigger must be observable, not interpretive
- name what must never be disconnected
- isolation keeps memory, power cuts kill it
- asymmetric: fast off, slow back on
basics
~20 sA tight observable trigger, a bounded scope with explicit never-touch systems, an isolation method that preserves evidence, a notify-within deadline, who may reconnect and on what proof, and contractual cover so the delegate actually acts.
solid answer
~50 sPre-delegation only works if the delegate can act without a judgement call they are not qualified to make. So the playbook states the trigger in observable terms — for example mass virtual-machine power-off or datastore writes issued from the hypervisor management plane outside change control — and states the scope: isolate the management network and its administrative access paths, and never the safety instrumented systems or the process control network without plant engineering. It states the method, because network isolation preserves host memory while pulling power destroys it, and the order of volatility ranks memory above disk. It states a notification obligation with a clock, names who may reconnect and against what evidence, and it is backed contractually so a co-managing provider will pull the trigger at 02:00 instead of waiting for permission. It should also acknowledge that an adversary who learns the trigger can deliberately trip it.
go deeper
Know that some containment actions are authorised in advance so a night shift can act without waking an executive, and that the authority names both what may be cut and what must never be.
Explain the mechanics: an observable trigger, bounded scope, an isolation method that preserves memory rather than destroying it, a notify clock, and separate reconnect authority.
Demonstrate that you have thought about the OT-adjacent case and the false trip: what a wrong disconnect costs a plant, who absorbs that cost, and how you bound the blast radius without removing the delegation.
Own the contractual and liability side — the pre-authorisation, the accepted cost of a false trip, and the service terms that make a provider willing to act at 02:00 rather than escalate.
## Why delegation, not escalation In a manufacturing estate co-managed 24x7 by a provider, the people watching at 02:00 are not the people who own the plant. If the only path to a disconnect is escalation, the encryption finishes before the phone tree does. Pre-delegation inverts the default: the delegate acts first and notifies immediately. That inversion is only safe if the playbook removes every judgement call the delegate cannot competently make. ## The six things it has to say **1. The trigger, in observable terms.** Not "if it looks like ransomware". Something a watch-floor operator can confirm from what is in front of them: administrative sessions to the hypervisor management plane from an unexpected source, mass virtual-machine power-off events, or datastore-level writes outside any change window, recorded in the management plane's own audit log. A vague trigger will not be pulled, because the delegate will fear being wrong. **2. The scope, including what must never be touched.** Isolate the management network, the administrative jump paths, and the credentials that reach them. Explicitly exclude what would create a safety problem: safety instrumented systems, life-safety systems, and the process control network unless plant engineering concurs. In an OT-adjacent environment the wrong disconnect is not an inconvenience; it can be a hazard, and a document that does not name the exclusions will not be trusted by the people who own the plant. **3. The method, because method decides what evidence survives.** Isolating a host at the network layer keeps it running and keeps its memory. Pulling power destroys memory, and the order of volatility ranks CPU registers and cache first, then memory, then network state, then disk — so a power cut throws away the most perishable evidence and the credentials, keys and process state living in it. Prefer switch-port or management-network isolation, and state explicitly when pulling power is nonetheless acceptable (an encryption run visibly in progress that isolation does not stop). **4. A notification obligation with a clock.** Act then notify, within a stated number of minutes, to a named list: the security lead, the plant manager, the executive on the rota. Delegation without a fast notify turns into a company that finds out at breakfast why the line stopped. **5. The reverse authority.** Who may reconnect, and against what evidence. This is asymmetric on purpose: the disconnect is delegated because it is time-critical, while reconnection is not, and reconnecting the management plane while the intruder still holds credentials to it undoes the whole action. Note that containment stops the damage; it does not remove persistence, and only eradication does. **6. Contractual backing.** A provider that fears being billed for a stopped production line will hesitate. The delegation needs a written pre-authorisation naming the role, an executive statement that the cost of a false trip is accepted, and the corresponding term in the managed-service contract. This is the part teams forget, and it is the part that decides whether the trigger is ever actually pulled. ## The adversary reads your playbook too An automated or delegated containment action is a lever, and a lever an intruder can learn about is a lever they can pull. An adversary who knows that a specific pattern causes your provider to isolate the management network can generate that pattern deliberately — producing the plant stoppage for you, or forcing the estate into a degraded state that suits them. Two mitigations, neither perfect: require two independent signals for the widest-blast-radius actions, and keep a human confirmation step for anything that reaches beyond the management plane. The honest position is that a false trip is still cheaper than encrypted datastores, so you accept the risk and bound the blast radius rather than removing the delegation. ## What good looks like A one-page authority that a night-shift operator can read in ninety seconds: this is the condition, this is what you disconnect, this is what you never disconnect, this is how, tell these people within fifteen minutes, and only this named person may put it back. Everything else — the investigation, the scoping, the recovery — happens after, with the estate no longer being encrypted while you decide.
- The provider hesitates because stopping the line costs money. What in the playbook fixes that?Written pre-authorisation naming the provider role, an executive statement that the cost of a false trip is accepted in advance, and the matching term in the managed-service contract. Hesitation is almost always a liability problem rather than a technical one, and it is fixed on paper before the incident, not on the bridge during it.
- What if the adversary deliberately triggers your pre-authorised disconnect?Treat delegated containment as an attack surface. Require two independent signals for the widest actions, keep a human confirmation for anything beyond the management plane, and keep a manual override. You still keep the delegation: a deliberately induced stoppage is recoverable, encrypted datastores across the estate largely are not.
- Does isolating the management network mean the incident is contained?It means damage is being limited. Containment and eradication are different phases: persistence, valid credentials and any foothold inside the guests all survive isolation. Reconnecting before those are addressed simply restores the intruder's access along with yours.
saying these in an interview costs you the question
- Writes the trigger as a judgement call, not an observation
- Omits systems that must never be disconnected
- Pulls power first and loses host memory
- Same person authority to disconnect and to reconnect immediately
- Assumes containment equals eradication
- Ignores that an adversary can trip the trigger deliberately