How should containment decisions be justified?¶
Containment decisions should be justified by the active risk, available evidence, likely consequences and reasonable alternatives.
Avoid this assumption: A technically effective action is automatically proportionate. Shutting down systems, disabling accounts or isolating networks may stop harm but also destroy evidence and disrupt essential services.
State what harm is occurring or credibly threatened.
Identify the evidence supporting that assessment, including alerts, live activity, user reports, logs or specialist advice.
Record the systems, people, services and data at risk.
Consider less destructive options, such as isolating one device, revoking one session, restricting one account or blocking one destination.
Record why those alternatives were insufficient, unavailable or too slow.
Consider the evidential cost, including loss of sessions, memory, network visibility, cloud access, unsaved data or provider records.
Consider the operational cost, including safety, continuity, communications, customer impact and legal obligations.
Record who made the decision, their authority, the time and the information available at that point.
Do not judge the decision solely with hindsight.
Where urgent action is taken before full advice is available, document why delay was not reasonable.
Review whether the action achieved the intended purpose and whether further containment is needed.
Do not allow a temporary emergency measure to continue indefinitely without review.
Record what information was unavailable at the time and whether that uncertainty increased or reduced the need for immediate action.
Operational takeaway¶
Justify containment by linking the chosen action to a defined risk, recorded evidence, rejected alternatives and the expected balance between harm reduction, continuity and evidential loss.