When an intrusion is declared, which functions beyond the security team join, and what does each decide?
answer
- declaration is not a security-only event
- who can authorise something disruptive
- counsel sets the legal posture early
- HR when the subject is an employee
- every addition widens who knows
basics
~20 sA declared intrusion adds legal counsel, privacy, HR when the subject is an employee, communications, an executive who can authorise disruptive action, and often a forensic firm retained through counsel. Security keeps the facts; they own the decisions.
solid answer
~50 sDeclaring an intrusion turns 'is this malicious?' into 'what does the organisation do about it?', and most of those calls are not the security team's. Counsel decides whether the response runs under legal privilege, retains outside specialists, and advises on notification and contractual duties. Privacy or the data protection officer covers both whether personal data was reached and whether examining a named person's telemetry is itself lawful. HR joins the moment the subject is an employee or contractor, because the case is now also an employment process. Communications owns what is said and to whom. An accountable executive authorises what security cannot decide alone: cutting a revenue system, disabling a senior person's access, spending on a retainer. A retained DFIR firm adds capacity and independence, engaged through counsel. Security supplies facts and options to all of them and keeps ownership of the technical investigation.
go deeper
Be ready to name the functions and one thing each decides: counsel the legal posture, privacy the lawfulness and personal-data scope, HR the employment process, communications the messaging, an executive the disruptive action. Do not claim security decides all of it.
Explain the sequencing and the reason behind it: why counsel and an authorising executive belong in early, why HR arrives the moment the subject is internal, and why every addition trades speed for a wider circle that knows.
Show that you supply facts and options rather than opinions on liability, that you keep need-to-know tight when the subject may be an insider, and that you can run this without stalling for approvals you do not actually need.
Own the pre-agreed version: a plan that names the executive decision-maker, defines when counsel is engaged by default, and sets who is on the circle for an internal-subject case before anyone is emotional about it.
## Why a declared intrusion stops being a security-team problem Triage is a security activity. Declaration is not. The moment someone with authority says *an adversary is or was inside*, the questions on the table change: does this have to be reported, to whom and by when; is the evidence going to be argued over later; is the person we are investigating sitting three desks away; who is allowed to take a production system down; who talks to the customer. None of those are technical questions and none of them are the analyst's to answer. This is the clearest structural difference between a security incident and an outage: an outage response is staffed with engineers, while an intrusion response is staffed with engineers *plus* functions that exist to manage legal, employment and disclosure risk. ### Legal counsel Counsel is usually the first non-security addition, and often the earliest. Counsel decides whether the response is directed by lawyers so that reports and advice may be protected from later disclosure, retains outside forensic specialists under that engagement, reads the contracts to see what you promised customers about notification, and owns the interpretation of regulatory duties. Counsel does not run the technical work and should not be treated as a rubber stamp collected afterwards; the protective effect of involving them depends on their involvement being real and early. ### Privacy / data protection The privacy function wears two hats at once. Outward: was personal data reached, whose, and does that drive a notification analysis. Inward: is *your investigation* a lawful and proportionate use of personal data. Reading one named employee's mailbox, endpoint telemetry or HR-system audit trail is itself processing of that person's data, and in several jurisdictions it needs a documented basis, a defined scope and a limit on who sees it. ### HR When the subject is an employee or contractor, the case is simultaneously a security investigation and an employment matter. HR owns the employment relationship, the disciplinary route, and frequently owns the very records you want to read, because HR-system data belongs to HR. HR also tells you the facts that change your whole read of the alert: that the person resigned last Tuesday, that they are on notice, that they have already been told their access will be reviewed. ### Communications Communications owns what is said externally and internally. The security team's job is to supply what is defensible and to say plainly what is still unknown, not to draft the statement or decide the audience. ### An accountable executive Somebody has to be able to say yes to things that hurt: take the order-entry system offline, disable a director's account, sign a six-figure retainer, tell the largest customer before the contract requires it. Security can recommend all of these; it cannot unilaterally accept the business consequence. A response plan that never names this person stalls at exactly the moment speed matters. ### A retained DFIR firm External forensic responders bring capacity, specialist tooling and an independence that matters when the findings will be contested. They are commonly engaged *through* counsel rather than contracted directly by security, so their work is produced to inform legal advice. ### What does not change Security keeps the technical investigation, the timeline and the containment options. Adding counsel does not mean lawyers decide which host to pull, and adding HR does not mean HR reads the logs. The pattern is: security owns the facts and the technical options; these functions own the decisions that carry legal, employment or disclosure consequences. ### Sequencing and need-to-know Not everyone joins at once. Counsel and a decision-making executive belong in early, because privilege posture and authority are needed from the start. HR joins the moment the subject is internal. Privacy joins once personal data is plausibly in scope. Communications joins before anything leaves the building. The retained firm joins when scope exceeds what the team can cover. Every addition also widens who knows. In an insider case this is a live risk rather than a formality: the subject may know the person you just added, and a leaked hint gives them time to delete a cloud copy, wipe a personal device or resign on their own terms. Keep an explicit, named distribution list, use a channel the subject cannot read, and add people because a decision needs them, not because they are senior.
- Who do you pull in within the first hour, and who can wait until morning?Counsel and an executive who can authorise disruptive action come in immediately, because the legal posture and the authority to act are needed from the start. HR joins as soon as the subject looks internal. Privacy joins once personal data is plausibly in scope. Communications joins before anything is said outside. The retained forensic firm joins when scope outruns the team's capacity, not automatically.
- What is the risk of adding people quickly when the subject may be an insider?Each addition widens the circle that knows. If the subject is an employee, a friendly word from someone you added gives them time to delete cloud copies, wipe a personal device or change their story. Keep a named, explicit distribution list, run the case in a channel the subject has no access to, and add each person because a decision requires them.
- Does adding counsel mean the lawyers now run the response?No. Counsel owns the legal posture: privilege, notification advice, contractual duties, and who is engaged externally. Security keeps the technical investigation, the timeline and the containment options. Where the two collide, for example counsel wanting an account left live to preserve evidence while security wants it cut, the plan should name a single accountable executive who breaks the tie.
Triage is the paramedic deciding this patient is really injured. Declaration is the hospital admitting them: suddenly there is a surgeon, an insurer, a records clerk and a next of kin, each owning a different decision.
saying these in an interview costs you the question
- Says the security team runs the whole response alone
- Treats counsel as paperwork collected after the investigation
- Broadcasts the case widely before knowing who the subject is
- Assumes any security ticket is automatically privileged
- Confuses this with paging another engineering team for help
- Expects HR or legal to make technical containment decisions