Keep up to date with the trending topics
from our industry experts

Who pulls the plug? Agreeing cyber response actions before it’s too late

Written by Henry Duncombe

Wednesday, 22 July, 2026

Webinar:

The true cost of AI: A reality check for fund managers

23rd September 2026

AI now comes with a meter running. Join our expert panel to explore how consumption-based pricing is reshaping AI adoption and how to prove it’s delivering measurable value.

If you ask most operational leaders what they expect from a Managed Security Service Provider during a cyber incident, the answer is usually simple: act quickly and fix the problem.

The reality is a bit more complicated.

In the middle of a live or suspected cyber-attack, the difference between decisive action and the wrong action can be measured in seconds. But here’s the catch. If you haven’t explicitly agreed what your provider is allowed to do on your behalf, you’re leaving a critical gap in your operating model.

And that gap tends to show up at exactly the wrong moment.

The dilemma: act or wait?

When an incident unfolds, your provider faces an immediate decision. Do they take action to contain the threat, or do they wait for customer approval?

If they wait, the attack may spread. With every passing minute, the risk of lateral movement, data exfiltration, or ransomware detonation increases. If they act without clear authority, they risk taking steps you may not have approved, such as isolating critical servers, disabling senior users, or blocking key systems. All of which can have a very real operational impact.

Neither outcome is ideal.

Yet this is exactly where many firms end up, because the boundaries were never clearly agreed in advance.

What “good” looks like

Best practice is straightforward. Firms and their security providers should explicitly agree, document, and approve the specific containment and remediation actions that can be executed without delay.

This removes ambiguity and allows your provider to move quickly, within clearly defined guardrails.

At Lanware, we formalise this through a simple but important set of principles:

  • Customers delegate authority for specific containment and remediation actions required to prevent, mitigate, or respond to a suspected or actual cyber incident
  • Those actions must be clearly defined, documented, and approved in advance
  • The provider commits to notifying the customer immediately when such actions are taken, including the reasons and any recovery steps required
  • Any automated response, such as SOAR playbooks that could impact service availability, requires prior customer approval before deployment

This creates the right balance between speed and control, which is exactly what you need in a high-pressure situation.

What should be agreed?

While every environment is different, most organisations should pre-approve actions such as:

  • Isolating compromised devices from the network
  • Disabling or locking user accounts suspected of compromise
  • Quarantining malicious emails or files
  • Blocking malicious IP addresses, domains, or traffic
  • Taking systems or services offline where there is a clear risk to the wider environment

The important point is not just listing these actions, but agreeing when and how they can be used.

Why this matters for operational leaders

This is not just a technical concern. It is a governance and risk issue.

Regulators, clients, and boards will expect you to demonstrate control during a cyber incident. That includes showing that your third-party providers are operating within a clearly defined and approved framework.

Without that, you risk two equally uncomfortable outcomes:

  • Too little action taken, allowing the incident to escalate
  • Too much action taken, causing avoidable disruption to the business

Neither is easy to explain after the event.

A simple test

If you’re unsure whether this is covered, ask your provider a simple question:

“In the first 15 minutes of a suspected attack, what are you allowed to do without asking us?”

If the answer is vague, based on assumptions, or buried in small print, it’s worth tightening this up. Because in cyber security, clarity beats good intentions every time.

And when the moment comes, you want your provider to move fast… but never outside the lines.

If you are interested in learning more, then please speak to one of our experts.

Our services

Our 4 pillars for a complete choice of managed IT services - all tailored to the needs of financial services firms in London and the UK.

Finance Forward 365

Microsoft modern workplace & cloud technology for digital transformation.

Compliant Teams

Increased productivity & collaboration with call recording whilst reducing costs.

Cyber Security

Keep your data secured against rapidly changing threats within Financial Services.

Power BI

Business Intelligence transformation and support tailored for Financial Services.

The LanWIRE

Join the community for financial services businesses

  • Stay updated with technology and cyber security trends
  • Network with your industry peers
  • Get invites to webinars and exclusive events
  • Gain access to useful tools and templates

The LanWIRE

Join the community for financial services businesses moving to the Microsoft Cloud

Q