It sounds a bit strange at first. A security team detects an attack, responds quickly, isolates the affected computer and stops the suspicious connection. Normally that sounds like a win. The security tools worked, the SOC reacted and somebody probably updated the incident ticket to show that the threat had been contained.
But cybersecurity isn't always that simple.
An attacker who gets into one laptop isn't necessarily interested in that laptop. The device might only be the starting point. Credentials could already have been stolen, an active session might still be usable, or the same account could have access to other systems. Disconnecting the laptop solves one part of the problem, but it doesn't automatically undo everything the attacker managed to do before that happened.
This becomes even more complicated in large organisations. There might be one team looking after endpoints, another managing identities, another responsible for cloud services and somebody else running the network. Internally, these are separate responsibilities with different tools and processes. For an attacker, though, they're simply different ways of getting from Point A to Point B.
That's what makes the scenario discussed in this deeper look at how a SOC can detect an attack while the organisation still ends up compromised quite interesting. Detection itself wasn't necessarily the problem. The bigger issue was what remained possible after detection.
It also makes some traditional security metrics feel a little less reassuring. A dashboard might show fast response times, thousands of alerts processed and plenty of incidents successfully closed. Those numbers are useful, but attackers aren't trying to keep tickets open. They're trying to reach valuable systems.
Maybe that's why security teams need to look beyond the alert itself. If one laptop gets compromised, the useful question isn't only whether that laptop can be isolated quickly. It's also whether the stolen identity can still login somewhere else, whether existing sessions can be killed, whether another account can be reached and how far an attacker could travel before somebody notices.
Modern security tools have become incredibly good at telling organisations that something bad is happening.
The harder part is making sure the bad thing actually stops happening.