During a confirmed ransomware outbreak, malware is spreading laterally across a flat manufacturing network that also runs safety-critical industrial control systems. The incident response team can isolate the affected segment immediately, but doing so will halt a production line mid-cycle in a way that could damage equipment. What should most influence the information security manager's containment decision?
- AThe estimated cost of replacing the encrypted servers, since this quantifies the financial loss the containment action is meant to prevent.
- BWhether the forensic team has finished capturing volatile memory from every affected host, because evidence preservation always precedes any containment step.
- CThe wording of the cyber-insurance policy, which determines whether the insurer will reimburse losses from the production stoppage.
- DThe relative business and safety impact of continued lateral spread versus an abrupt production halt, so containment limits overall harm rather than shifting it. Correct
Why A is wrong: Replacement cost is an after-the-fact recovery figure; containment timing must weigh the live spread and the safety impact of stopping the line, not the price of hardware already affected.
Why B is wrong: Evidence preservation matters, but treating it as an absolute precondition that delays containment lets the malware keep spreading; preservation is balanced against, not placed ahead of, limiting impact.
Why C is wrong: Insurance terms inform later cost recovery and are tempting because executives ask about them, but they do not govern the operational judgement of how to contain an actively spreading incident safely.
Why D is correct: Correct: containment is about limiting net scope and impact, and in an environment with safety-critical systems the manager must compare the harm of continued spread against the harm of the isolation action itself before acting.