When responding to an incident, after analysis tells you what happened, the pressure becomes immediate: get the office back to normal. Phones are ringing, leadership wants reassurance, the public wants results. The instinct is to jump ahead to recovery.
Resist it. The first step in Phase 3 of the Incident Response Process is containment, and skipping it is how a one-day incident becomes a two-week one. Rushing to get your network back online before the incident is fully contained can allow the threat actor to continue wreaking havoc, such as encrypting all of the systems. You cannot fix what is still spreading.
The principle of containment can be applied to physical incidents as well, though they are usually so extreme – active shooter, suspicious substance in mail – that large steps are taken immediately. In this issue, we are focusing on cyber incidents, what you should know about containment, and the actions you can take as an election official.
Two Stages, Different Clocks
Short-term containment is what you do in minutes. The single most effective move is cutting the adversary’s communication path. The goal is to break their ability to continue operating inside your environment, while leaving the systems themselves running so evidence is preserved. Pulling the network cable, disabling the wireless, or shutting the switch port accomplishes containment without destroying the record.
A critical distinction: disconnect, do not power off. Powering down a compromised machine wipes the memory contents that the forensics team will need to understand what the attacker did and where they went in the system. This is the most common mistake under pressure. Before any irreversible action, coordinate with forensics or a contracted incident response firm.
From there, the rest of short-term containment follows: isolating affected machines, disabling compromised accounts, blocking malicious senders, and taking public-facing forms offline.
Long-term containment is what you do in hours or days, once the immediate spread is stopped. Stand up a temporary clean environment so critical work continues. Route a workflow to an unaffected system. Restrict access more tightly than usual until you understand the full scope. This buys time to do eradication right, instead of doing it under fire.
Actions You Can Take
- Pre-authorize containment actions. Decide in advance who can isolate a machine, disable an account, or take a public service offline without convening a meeting.
- Know your insurance policy. Know if your policy provides coverage for cyber incidents and the specific requirements to activate it. Cyber insurance policies often require the carrier to be notified within 24-72 hours from discovery of an incident and that their approved forensics, legal, and incident response vendors are used. Calling late or bringing in your own vendors may reduce or void your coverage.
If you don’t carry cyber insurance, in addition to considering cyber policy options, work with your Election Security Working Group to clarify your plan for responding to a cyber incident. Identify forensics partners and incident response firms – see step (3) below.
- Identify your forensics partners now. Double-check if your insurance carrier requires you to use a specific vendor and if you can include your security partners such as the FBI or State Fusion Center. If you do not carry cyber insurance, identify a qualified forensic partner and incident response firm in advance so you are not searching for one mid-incident. Know who to call before you pull a plug so you do not have to choose between containment and evidence preservation under pressure.
- Enhance your contact list. The insurance carrier’s hotline likely is an asset if you have cyber insurance: most provide 24/7 breach coaches who help triage the incident, coordinate forensics, and guide notifications. Put the policy number and hotline number in your Incident Response Plan contact list, and make the call early, before you commit to a containment path that locks out covered services.
If you don’t carry cyber insurance, in addition to considering cyber policy options, be sure to include the names and contact details for your forensics partners and incident response firm on your Incident Response Plan contact list. Double-check if there is required information you must provide when contacting them during an incident; note such requirements alongside their contact details.
- Keep a containment log ready. Containment actions get reversed during recovery, so track time, action, who did what, and on what machine or system. A shared or handwritten document with timestamps is fine. Memory is not.
- Decide your “take it offline” thresholds in advance. Work with your IT support to determine which services come down at which severity tier, who has the authority, and who gets notified.
- Practice at least once before you need it. A 30-minute walkthrough with IT, the incident response team, and your Election Security Working Group beats reading the plan for the first time at 7 p.m. on Election Night.
Next week we will cover eradication, the step that decides whether the incident actually ends or just pauses.
The Planning Desk is a running timeline of key election security tasks. You can find prior editions in the newsletter archive.
