If you ask most operational leaders what they expect from a Managed Security Service Provider during a cyber incident, the answer is usually simple: act quickly and fix the problem.
The reality is a bit more complicated.
In the middle of a live or suspected cyber-attack, the difference between decisive action and the wrong action can be measured in seconds. But here’s the catch. If you haven’t explicitly agreed what your provider is allowed to do on your behalf, you’re leaving a critical gap in your operating model.
And that gap tends to show up at exactly the wrong moment.
The dilemma: act or wait?
When an incident unfolds, your provider faces an immediate decision. Do they take action to contain the threat, or do they wait for customer approval?
If they wait, the attack may spread. With every passing minute, the risk of lateral movement, data exfiltration, or ransomware detonation increases. If they act without clear authority, they risk taking steps you may not have approved, such as isolating critical servers, disabling senior users, or blocking key systems. All of which can have a very real operational impact.
Neither outcome is ideal.
Yet this is exactly where many firms end up, because the boundaries were never clearly agreed in advance.
What “good” looks like
Best practice is straightforward. Firms and their security providers should explicitly agree, document, and approve the specific containment and remediation actions that can be executed without delay.
This removes ambiguity and allows your provider to move quickly, within clearly defined guardrails.
At Lanware, we formalise this through a simple but important set of principles:
- Customers delegate authority for specific containment and remediation actions required to prevent, mitigate, or respond to a suspected or actual cyber incident
- Those actions must be clearly defined, documented, and approved in advance
- The provider commits to notifying the customer immediately when such actions are taken, including the reasons and any recovery steps required
- Any automated response, such as SOAR playbooks that could impact service availability, requires prior customer approval before deployment
This creates the right balance between speed and control, which is exactly what you need in a high-pressure situation.
What should be agreed?
While every environment is different, most organisations should pre-approve actions such as:
- Isolating compromised devices from the network
- Disabling or locking user accounts suspected of compromise
- Quarantining malicious emails or files
- Blocking malicious IP addresses, domains, or traffic
- Taking systems or services offline where there is a clear risk to the wider environment
The important point is not just listing these actions, but agreeing when and how they can be used.
Why this matters for operational leaders
This is not just a technical concern. It is a governance and risk issue.
Regulators, clients, and boards will expect you to demonstrate control during a cyber incident. That includes showing that your third-party providers are operating within a clearly defined and approved framework.
Without that, you risk two equally uncomfortable outcomes:
- Too little action taken, allowing the incident to escalate
- Too much action taken, causing avoidable disruption to the business
Neither is easy to explain after the event.
A simple test
If you’re unsure whether this is covered, ask your provider a simple question:
“In the first 15 minutes of a suspected attack, what are you allowed to do without asking us?”
If the answer is vague, based on assumptions, or buried in small print, it’s worth tightening this up. Because in cyber security, clarity beats good intentions every time.
And when the moment comes, you want your provider to move fast… but never outside the lines.




