Cybersecurity · August 2026

Who is allowed to pull the plug at 11pm on a Friday?

All the security tooling in the world only matters if somebody is allowed to act decisively at the moment it lights up.

In August, T-Mobile's chief security officer described how his team handled a state-sponsored intrusion on the company's network. The group behind it, known as Salt Typhoon, had compromised telecom and infrastructure providers across the country. T-Mobile caught the activity early. Four people from the security team got in a car, drove to a data center near headquarters in Bellevue, found the compromised server, and cut the cable connecting it to the network with a pair of scissors. The frayed length of yellow cable now hangs framed at their offices.

Knowing in advance who is allowed to break something in order to save everything else is a control.

It is a great story, and it is worth being precise about it: the cable was cut back in 2024. What happened in August 2026 was the public telling of it. The lesson has not aged, though, and it is not the lesson most people take from it.

The tooling was never the hard part

T-Mobile is a large company with a serious security budget. They had the telemetry. They saw the activity. What actually ended the intrusion was a decision, made quickly, by people who did not have to ask anyone for permission first.

That is the part smaller organizations consistently get wrong. A great deal of attention goes into detection, alerts, dashboards, and reports, and almost none goes into the question of what happens in the twenty minutes after an alert turns out to be real.

The question worth answering before you need it

If we found an active intruder in your network at 11pm on a Friday, who makes the containment call? Is it you? Your office manager? Your IT provider? And does that person already have the authority to disconnect a server, disable an account, or take a site offline without first assembling a meeting?

For most small organizations we talk to, the honest answer is that nobody has thought about it. The implicit plan is that someone will call the owner, the owner will be asleep, and the intruder will keep working until Monday.

What a workable answer looks like

  • One named person, and one named backup, who can authorize containment at any hour
  • A written and agreed understanding that containing an incident may mean downtime, and that downtime is the acceptable outcome
  • Contact details that work at 11pm, meaning mobile numbers, not office extensions
  • A short list of actions that are pre-approved: isolating a machine, disabling an account, blocking an address

None of that costs money. It costs an hour of thinking, once, while nothing is on fire.

Decisiveness is a control

We tend to think of security controls as products. Some of the most valuable ones are agreements. Knowing in advance who is allowed to break something in order to save everything else is a control, and it is one of the few that works at full strength on a Friday night when nobody senior is reachable.

If you are not sure who holds that authority in your organization today, that is the gap to close first, ahead of any new tool. It is also one of the things we work through with clients as part of layered security planning.

Get started

Questions about your own setup?

A free assessment turns general guidance into specific next steps for your organization. No pressure, no obligation.