Simulated containment actions only. No production systems are modified.
INC-2041
Finance endpoint compromise
Switch scenario · resets workflow
Critical
Step 5 · Decision

Containment Options

Four containment strategies, each scored for fit and weighed against business continuity, evidence integrity and recovery. Route any option into the approval workflow — nothing executes against real systems.

B

Targeted Containment

Recommended

Surgically isolate the compromised endpoint and identity while explicitly protecting the payroll processing path.

80
fit score
Recommended actions
  • Network-isolate FIN-EP-204 (management channel retained) after memory capture.
  • Disable P. Martin's account; rotate credentials and revoke tokens.
  • Disable the mailbox forwarding rule and quarantine the inbox rule set.
  • Pin svc-finbatch under monitoring so payroll batch can still run.
Security benefit

Removes the most probable propagation routes while preserving payroll.

Business impact

Moderate — P. Martin offline; payroll path deliberately kept intact.

Evidence impact

Low/Moderate — memory + logs captured before isolation.

Recovery impact

Moderate — credential reset and endpoint review required.

Confidence84/100
Risk of delay71/100
Approvals required
IR LeadIncident CommanderBusiness Owner
Rollback plan

Re-enable account post-investigation; remove isolation; restore delegated access.

3 approvers
D

Staged Containment

Time-boxed phased plan: contain the identity and endpoint now, verify lateral movement, then decide whether to escalate before the payroll window.

72
fit score
Recommended actions
  • Stage 1 (now): revoke sessions, disable mailbox rule, capture endpoint memory.
  • Stage 2 (+30m): isolate FIN-EP-204; confirm/deny FIN-FS-01 compromise.
  • Stage 3 (decision gate): escalate to aggressive only if payment access is confirmed.
  • Hold payroll go/no-go review at T-2h with Business Owner.
Security benefit

Balances containment with evidence quality and payroll continuity.

Business impact

Low→Moderate, scaling only if the threat is confirmed to spread.

Evidence impact

Low — sequencing protects volatile artifacts at each stage.

Recovery impact

Moderate — scoped to whichever stages are actually triggered.

Confidence79/100
Risk of delay55/100
Approvals required
IR LeadIncident CommanderBusiness Owner
Rollback plan

Each stage is independently reversible from its pre-stage snapshot.

3 approvers
A

Minimal Containment

Lowest-disruption posture: increase monitoring and revoke the active session without isolating the endpoint or breaking the payroll path.

53
fit score
Recommended actions
  • Revoke P. Martin's active sessions and force re-authentication.
  • Disable the suspicious mailbox forwarding rule (after snapshotting it).
  • Raise endpoint + identity alerting to high-fidelity watch.
Security benefit

Cuts the live session and the exfil channel with minimal collateral.

Business impact

Negligible — payroll and payments remain available.

Evidence impact

Low — preserves most volatile artifacts in place.

Recovery impact

Trivial — session/token changes only.

Confidence58/100
Risk of delay42/100
Approvals required
IR LeadIncident Commander
Rollback plan

Re-enable accounts/rules from snapshot; clear elevated alerting.

2 approvers
C

Aggressive Containment

Maximal blast-radius reduction: broad isolation across finance assets and a freeze on the payment path, accepting business disruption.

43
fit score
Recommended actions
  • Isolate FIN-EP-204 and FIN-FS-01; sever SMB sessions.
  • Disable P. Martin and svc-finbatch; suspend payment-initiation entitlements.
  • Temporarily freeze the payment gateway path pending verification.
  • Force org-wide reauthentication for the finance group.
Security benefit

Greatest reduction in spread and fraud risk across finance.

Business impact

High — payroll run at risk; payments frozen; finance group disrupted.

Evidence impact

Moderate — fast teardown risks losing some volatile artifacts.

Recovery impact

High — multi-system restoration and revalidation needed.

Confidence47/100
Risk of delay35/100
Approvals required
IR LeadIncident CommanderCISOBusiness OwnerLegalExecutive
Rollback plan

Staged restoration with payroll prioritized; lift payment freeze after gateway review.

6 approvers

Side-by-side comparison

DimensionAMinimal ContainmentBTargeted ContainmentCAggressive ContainmentDStaged Containment
Fit score53/10080/10043/10072/100
Confidence58/10084/10047/10079/100
Risk of delay42/10071/10035/10055/100
Security benefitCuts the live session and the exfil channel with minimal collateral.Removes the most probable propagation routes while preserving payroll.Greatest reduction in spread and fraud risk across finance.Balances containment with evidence quality and payroll continuity.
Business impactNegligible — payroll and payments remain available.Moderate — P. Martin offline; payroll path deliberately kept intact.High — payroll run at risk; payments frozen; finance group disrupted.Low→Moderate, scaling only if the threat is confirmed to spread.
Evidence impactLow — preserves most volatile artifacts in place.Low/Moderate — memory + logs captured before isolation.Moderate — fast teardown risks losing some volatile artifacts.Low — sequencing protects volatile artifacts at each stage.
Recovery impactTrivial — session/token changes only.Moderate — credential reset and endpoint review required.High — multi-system restoration and revalidation needed.Moderate — scoped to whichever stages are actually triggered.
ApprovalsIR Lead, Incident CommanderIR Lead, Incident Commander, Business OwnerIR Lead, Incident Commander, CISO, Business Owner, Legal, ExecutiveIR Lead, Incident Commander, Business Owner
Rollback planRe-enable accounts/rules from snapshot; clear elevated alerting.Re-enable account post-investigation; remove isolation; restore delegated access.Staged restoration with payroll prioritized; lift payment freeze after gateway review.Each stage is independently reversible from its pre-stage snapshot.