A company's written IR policy requires notifying the legal team before taking containment actions on any system. During an active ransomware outbreak, the IR team is containment-ready but the legal team is unreachable for 2 hours. What should the IR team do?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because IR plans should include escalation paths for scenarios where the standard notification chain is unavailable; the CISO or alternate authority can provide emergency authorization, and documented actions with a paper trail satisfy legal requirements. Active ransomware spreading across the network constitutes an emergency that justifies emergency authorization procedures.
Full explanation below image
Full Explanation
B is correct because IR plans should include escalation paths for scenarios where the standard notification chain is unavailable; the CISO or alternate authority can provide emergency authorization, and documented actions with a paper trail satisfy legal requirements. Active ransomware spreading across the network constitutes an emergency that justifies emergency authorization procedures. A is wrong because 2 hours of unrestricted ransomware spread can cause catastrophic business impact; good IR planning anticipates this. C is wrong because inaction during active spread is negligent and causes avoidable harm. D is wrong because engaging the ransom channel during spread does not stop encryption and may expose negotiation strategy.