TEAM VIEW // RESPONSE SWIMLANE

Who moves, and in what order

Pick the threat. The response paints immediately, sequenced by NIST CSF 2.0 function, with a delegation fallback for lean teams.

THE ANSWER

Can your team run this response?

ConfirmedClass A4Nov 2025

Your team covers this response. All 12 roles GTG-1002 needs are selected. First move is Detection Engineer, on a signal that fires from M-A4-01.

Roles required
12
Roles required for the live response
Steps
17
Steps in the live flow, Detect to Recover
First move
Detection Engineer
First move once the signal trips
Detection trigger
M-A4-01
Control IDs for this detection

Lean team: 4 roles cover 20 of 32 steps. 12 fall to the CISO as last resort.

01THREAT SCENARIO1 OF 21

GTG-1002

Attacker tier: 4 · Nation-state
AI capability: 5 · Autonomous
WHAT TRIPS THE LIVE FLOW
Thousands of agent requests per second from one identity
M-A4-01
If this detection is not deployed, nothing below Detect happens.
Direction AIN THE WILD

The autonomy threshold. Defines tier-5 AI capability for the framework.

02YOUR ROLES12 OF 19 SELECTED

Who do you actually have?

Hybrid cloud · SIEM · EDR / XDR · CI/CD
Evaluating new capability? See Stack Lab at /stack
03THE RESPONSE17 STEPS
DetectLIVE FLOW6 steps
RespondLIVE FLOW6 steps
RecoverLIVE FLOW5 steps

16 handoffs across the live flow. No steps are covered by another role.

04THE FULL SWIMLANEALL FUNCTIONS

Overview: role coverage by CSF function

Counts show how many steps each role holds in each function for the selected class (A4). Click a column header, or a function above, to zoom into that function's numbered flow.
RoleGovernIdentifyProtectDetectRespondRecoverTotal
CISO / Head of Security2no stepsno stepsno steps1no steps3
CRO / Board Risk3no stepsno stepsno stepsno steps14
SOC Managerno stepsno stepsno steps1no steps12
Tier 1 Analystno stepsno stepsno steps1no stepsno steps1
Tier 2 Analystno stepsno stepsno steps1no stepsno steps1
Threat Hunterno stepsno stepsno steps1no stepsno steps1
Incident Responderno stepsno stepsno stepsno steps112
Detection Engineerno stepsno stepsno steps1no steps12
Cloud Security Engineerno steps1no stepsno steps1no steps2
Network / Security Engineerno stepsno steps1no steps1no steps2
Data Owner / Privacy11no stepsno steps114
IAM / Identity Ownerno steps1211no steps5
05LEAN TEAM FALLBACK4 ROLES

Most teams do not staff every role a standard names. The same steps, the same controls, on the team you actually have.

CRO / Board Risk5 STEPS COVERED
  • Govern1
    Register AI-orchestrated intrusion and AI-system compromise as named enterprise risks (NIST AI RMF Govern)
  • Govern2
    Set autonomy limits and decision rights across the six domains (IMDA MGF v1.5 dim 1)
  • Govern6
    Singapore CII operators: initiate board-level AI-threat review per CSA CII directive (5 May 2026)
  • Govern7FROM GRC / Compliance
    Assemble the regulator evidence pack: MAS AIRG readiness (post-consultation, not final), IMDA MGF v1.5 mapping, CTM status for CII-touching capability
  • Recover7
    Approve control and policy updates, close the loop into Govern
SOC Manager7 STEPS COVERED
  • Identify4FROM Threat Intel Lead
    Map catalogued threats to your estate using MITRE ATLAS and OWASP LLM and Agentic Top 10
  • Identify6FROM Threat Intel Lead
    Run tabletop against the selected threat class with domain owners observing (this is where roles learn each other's steps)
  • Detect2FROM Tier 1 Analyst
    Triage: validate the signal, enrich with agent identity, tool, prompt hash, operator
    M-B2-04
  • Detect6
    Declare incident, open the bridge, assign responders
  • Respond1FROM Incident Responder
    Lead containment per CoSAI AI IR Framework V1.0: disable agent, operate kill switch
  • Recover1FROM Incident Responder
    Recover agents to clean baselines, validate trust boundaries before re-enable
  • Recover6
    Run lessons-learned, update runbooks and the detection backlog
Detection Engineer3 STEPS COVERED
  • Detect1
    Detections live: rate signature over 1,000 req/sec, expired-CSP-domain egress, agent config change
    M-A4-01, M-B1-03, M-B5-02
  • Detect4FROM Threat Hunter
    Pivot on indicators: illogical tool-execution chains, token-usage spikes (M-Trends 2026 heuristics)
  • Recover5
    Convert incident learnings into new detections and close coverage gaps
IAM / Identity Owner5 STEPS COVERED
  • Identify2
    Enumerate machine and agent identities and their privileges
  • Protect3
    Least privilege per tool, short-lived per-tool credentials, external authorisation (target system enforces, not the LLM)
    M-B2-01, M-B2-02, M-B5-01
  • Protect4
    Human-in-the-loop gates for consequential actions (IMDA MGF v1.5 dim 2)
    M-B2-03
  • Detect5
    Confirm agent identity anomaly, prepare token and grant revocation
    M-B5-02
  • Respond2
    Revoke agent tokens, rotate credentials, disable OAuth grants
    M-B5-01
CISO / Head of Security12 STEPS COVERED
Last resort. These steps reach no selected role in their fallback chain.
  • Govern3
    Publish NIST AI RMF plus IR 8596 crosswalk (IR 8596 is Initial Preliminary Draft, flag as draft-dependent)
  • Govern4
    Require AI use-case intake to cite AI 600-1 risks and Manage actions
  • Govern5FROM Data Owner / Privacy
    Classify data reachable by agents and set data-handling limits
  • Identify1FROM Cloud Security Engineer
    Inventory agentic platforms and every MCP server in the toolchain
    M-B4-02
  • Identify5FROM Data Owner / Privacy
    Map which agents can read sensitive data and CRM records
  • Protect6FROM Network / Security Engineer
    Egress allow-lists deny-by-default, DNS blocking of consumer LLM endpoints where policy requires
    M-A3-01, M-B1-03
  • Detect3FROM Tier 2 Analyst
    Scope tool-invocation chain across SIEM, EDR, and cloud, confirm exfil path
    M-A4-02
  • Respond3FROM Cloud Security Engineer
    Isolate affected workloads and cloud planes, block egress paths
    M-B4-03
  • Respond4FROM Network / Security Engineer
    Block C2 and exfil domains, enforce egress cutoff
    M-A3-03
  • Respond6FROM Data Owner / Privacy
    Assess data exposure and breach-notification obligations
  • Respond7
    Own regulator notification and external comms decisions
  • Recover4FROM Data Owner / Privacy
    Confirm data integrity, execute privacy notifications if required

Role widgets

One dashboard card per selected role, sharpened for the current threat.
CISO / Head of Security
My priorities now
  • Own regulator notification and external comms decisions
  • Publish NIST AI RMF plus IR 8596 crosswalk (IR 8596 is Initial Preliminary Draft, flag as draft-dependent)
  • Require AI use-case intake to cite AI 600-1 risks and Manage actions
Telemetry to watch
  • Risk and incident status dashboards
  • Signal for this threat: Thousands of agent requests per second from one identity (M-A4-01)
Top detections
  • Consume detections owned by Detection Engineering and IAM
Escalation rules
  • Own regulator notification and board escalation
Outputs I must produce
  • Board and regulator briefings
  • Risk decisions and policy updates
CRO / Board Risk
My priorities now
  • Register AI-orchestrated intrusion and AI-system compromise as named enterprise risks (NIST AI RMF Govern)
  • Set autonomy limits and decision rights across the six domains (IMDA MGF v1.5 dim 1)
  • Singapore CII operators: initiate board-level AI-threat review per CSA CII directive (5 May 2026)
  • Approve control and policy updates, close the loop into Govern
Telemetry to watch
  • Enterprise risk register status
  • Board-level incident and exposure reporting
  • Signal for this threat: Thousands of agent requests per second from one identity (M-A4-01)
Top detections
  • Consume detections owned by Detection Engineering and IAM
Escalation rules
  • Escalate risk-appetite breaches to the board risk committee
Outputs I must produce
  • Risk-register entries
  • Autonomy policy and decision-rights approvals
SOC Manager
My priorities now
  • Declare incident, open the bridge, assign responders
  • Run lessons-learned, update runbooks and the detection backlog
Telemetry to watch
  • Queue health and MTTD dashboards
  • Signal for this threat: Thousands of agent requests per second from one identity (M-A4-01)
Top detections
  • Consume detections owned by Detection Engineering and IAM
Escalation rules
  • Escalate to CISO on major-incident thresholds
Outputs I must produce
  • Incident bridge notes
  • Coverage and MTTD reporting
Tier 1 Analyst
My priorities now
  • Triage: validate the signal, enrich with agent identity, tool, prompt hash, operator
Telemetry to watch
  • Alert queue for agent anomalies
  • Egress and rate-spike alerts
  • Signal for this threat: Thousands of agent requests per second from one identity (M-A4-01)
Top detections
  • First-line agent-anomaly triage use-case
Escalation rules
  • Escalate confirmed agent anomaly to T2 within triage SLA
  • Escalate suspected active exfil straight to IR
Outputs I must produce
  • Triage tickets with enrichment
  • Escalation records
Tier 2 Analyst
My priorities now
  • Scope tool-invocation chain across SIEM, EDR, and cloud, confirm exfil path
Telemetry to watch
  • Correlated SIEM, EDR, and cloud events
  • Tool-invocation chains
  • Signal for this threat: Thousands of agent requests per second from one identity (M-A4-01)
Top detections
  • Tool-invocation-chain investigation use-case
Escalation rules
  • Declare incident to IR on confirmed blast radius
  • Loop in IAM to revoke agent tokens
Outputs I must produce
  • Investigation report with blast radius
  • Containment action log
Threat Hunter
My priorities now
  • Pivot on indicators: illogical tool-execution chains, token-usage spikes (M-Trends 2026 heuristics)
Telemetry to watch
  • Behavior-baseline deviations
  • LLM-API C2 indicators
  • Signal for this threat: Thousands of agent requests per second from one identity (M-A4-01)
Top detections
  • Illogical tool-execution chain hunt
  • Token-usage spike hunt
Escalation rules
  • Hand validated findings to Detection Engineering and IR
Outputs I must produce
  • Hunt report and new detection candidates
Incident Responder
My priorities now
  • Lead containment per CoSAI AI IR Framework V1.0: disable agent, operate kill switch
  • Recover agents to clean baselines, validate trust boundaries before re-enable
Telemetry to watch
  • Consolidated incident telemetry
  • Signal for this threat: Thousands of agent requests per second from one identity (M-A4-01)
Top detections
  • Consume detections owned by Detection Engineering and IAM
Escalation rules
  • Escalate major incident to CISO for regulator and comms decisions
Outputs I must produce
  • Incident report
  • Containment and eradication record
Detection Engineer
My priorities now
  • Detections live: rate signature over 1,000 req/sec, expired-CSP-domain egress, agent config change
  • Convert incident learnings into new detections and close coverage gaps
Telemetry to watch
  • Action-level tool-invocation logs
  • SIEM and EDR detection telemetry
  • Signal for this threat: Thousands of agent requests per second from one identity (M-A4-01)
Top detections
  • Detection for Thousands of agent requests per second from one identity
  • ATLAS-tagged rule for the affected class
Escalation rules
  • Notify SOC Manager on new detection gaps
Outputs I must produce
  • Deployed detections with ATLAS tags
  • Detection-gap backlog
Cloud Security Engineer
My priorities now
  • Isolate affected workloads and cloud planes, block egress paths
  • Inventory agentic platforms and every MCP server in the toolchain
Telemetry to watch
  • Agent-platform and cloud audit logs
  • Workload and egress flow logs
  • Signal for this threat: Thousands of agent requests per second from one identity (M-A4-01)
Top detections
  • Anomalous agent action in cloud plane
  • Expired or new CSP-domain egress
Escalation rules
  • Escalate cloud-plane containment needs to IR
Outputs I must produce
  • Cloud containment evidence
  • Platform config baselines
Network / Security Engineer
My priorities now
  • Block C2 and exfil domains, enforce egress cutoff
  • Egress allow-lists deny-by-default, DNS blocking of consumer LLM endpoints where policy requires
Telemetry to watch
  • Outbound LLM-API traffic signatures
  • DNS and egress logs
  • Signal for this threat: Thousands of agent requests per second from one identity (M-A4-01)
Top detections
  • LLM-API C2 traffic detection
Escalation rules
  • Escalate egress-cutoff impact to SOC Manager
Outputs I must produce
  • Egress and segmentation change records
Data Owner / Privacy
My priorities now
  • Assess data exposure and breach-notification obligations
  • Map which agents can read sensitive data and CRM records
  • Classify data reachable by agents and set data-handling limits
  • Confirm data integrity, execute privacy notifications if required
Telemetry to watch
  • Data-access and DLP logs for agent identities
  • Signal for this threat: Thousands of agent requests per second from one identity (M-A4-01)
Top detections
  • Consume detections owned by Detection Engineering and IAM
Escalation rules
  • Escalate breach-notification obligations to CISO and legal
Outputs I must produce
  • Data-exposure assessment
  • Notification recommendation
IAM / Identity Owner
My priorities now
  • Revoke agent tokens, rotate credentials, disable OAuth grants
  • Confirm agent identity anomaly, prepare token and grant revocation
  • Least privilege per tool, short-lived per-tool credentials, external authorisation (target system enforces, not the LLM)
  • Human-in-the-loop gates for consequential actions (IMDA MGF v1.5 dim 2)
  • Enumerate machine and agent identities and their privileges
Telemetry to watch
  • Agent identity request-rate baselines
  • OAuth grant and consent logs
  • Agent configuration change events
  • Signal for this threat: Thousands of agent requests per second from one identity (M-A4-01)
Top detections
  • Agent config-change rule (AML.T0081)
  • Rate-spike rule (over 1,000 requests per second)
Escalation rules
  • Escalate token or consent compromise to IR and SOC Manager
Outputs I must produce
  • Credential and grant revocation log
  • Identity baseline updates

Incident RACI and handoffs

Activities derived from class A4. R responsible, A accountable, C consulted, I informed. This is the live-incident assignment view; steady-state accountability lives in the framework document's standing RACI.
ActivityCSFCISOCRO / BoardSOC MgrT1T2HunterIRDet EngCloud SecNet EngData OwnerIAM
Register AI risk and set autonomy limitsGovernRARIIIIIIIIC
Inventory affected assets, agents, MCP, identitiesIdentifyIACRR
Harden runtime and identity for this vectorA delegated: App Owner to Cloud SecProtectICRRR
Build and tune detections for the threat signature: Thousands of agent requests per second from one identityDetectIRRACC
Triage and validate alertsDetectIARRC
Contain and eradicateRespondIIRARRR
Assess data exposure and notificationRespondCIRA
Recover to a clean baselineRecoverIARC
Lessons learned and control updateRecoverRARCCCCRCCCC
Incident handoff sequence
Triage
T1
to
Investigate
T2
to
Contain
IR
to
Eradicate
IR
to
Recover
IR
to
Lessons learned
SOC Mgr

Threat-driven adaptation

Signal to anchor: Thousands of agent requests per second from one identity (M-A4-01).
Monitor and harden are control-backedInvestigate are hypotheses to testMitigate are response actions
Class A4AI as autonomous attack orchestrator (GTG-1002, GTG-2002)
Identity
Monitor Single agent identity issuing thousands of requests per second
Harden Scoped per-tool credentials, external authorisation
Investigate Agent acting beyond human operational tempo
Mitigate Revoke tokens, disable agent
M-A4-01AML.TA0015
Network
Monitor Physically impossible request rates and multi-target fan-out
Harden Rate limiting on agent-initiated traffic
Investigate Map campaign breadth across targets
Mitigate Egress cutoff
M-A4-01
Data
Monitor Bulk access and exfil across many systems
Harden DLP and least data reach per agent
Investigate Determine blast radius and data classes
Mitigate Contain data paths, revoke access
M-A4-02
Cloud
Monitor Multi-source correlated intrusion across SIEM and EDR
Harden Cross-plane segmentation
Investigate Reconstruct autonomous tactical chain
Mitigate AI-assisted SOC response
M-A4-02M-A4-03

Assumptions and gaps

Stated so the reader can challenge them. First-run defaults apply where inputs were not provided.
Environment assumptions
  • Hybrid cloud deployment model.
  • SIEM present.
  • EDR or XDR present.
  • CI/CD pipeline present and in scope.
  • Standard SOC tooling: SIEM plus EDR or XDR plus cloud logs.
  • Tiered analyst model (T1/T2) shown as default; tierless SOCs should map T1/T2 steps to their analyst pool and deselect the tiers.
Delegation model (how lean orgs are handled)
  • When a step's owning role is not selected, the step is never dropped. It cascades down a fallback chain to the next qualified selected role and renders with a "delegated from" tag.
  • Fallback chains follow competence adjacency and are recommended defaults, not standards-derived. Organizations should override them to match their structure.
  • CISO is the accountable owner of last resort. Deselecting CISO can leave steps unresolvable, and the flow flags this explicitly.
  • Delegation load indicator: when one role absorbs 3 or more delegated steps in a single function, the flow recommends staffing or MSSP coverage. MAS AIRG proportionality permits lighter frameworks, not absent ownership.
  • Delegated steps are equally mandatory. The Standard/Subtle display toggle changes emphasis only, never scope.
Currently delegating from
  • Threat Intel Lead: steps cascade to Hunter first.
  • Platform / IT Ops Owner: steps cascade to Cloud Sec first.
  • Application Owner: steps cascade to AI Platform first.
Fact, consensus, hypothesis
  • Fact: GTG-1002 is a catalogued, primary-sourced entry (Confirmed).
  • Consensus: monitor and harden items map to named controls and standards.
  • Hypothesis: investigate items are starting hypotheses, not confirmed findings.
  • This class touches the Data domain, so a data-exposure and notification activity is included in the incident RACI.
Division of labor across views
  • Tab A answers sequence: who acts in what order within each CSF function.
  • Tab D answers incident assignment: R/A/C/I when the alarm is live.
  • The standing accountability RACI (framework document) answers steady-state ownership.
Delegation fallback chains are recommended defaults, not standards-derived. Which roles this page marks essential is derived from step ownership in Detect, Respond and Recover, and that derivation is this framework's, not standards-derived. Steps and controls trace to the v2.4 catalog and named public standards. Re-verify standard and CVE status before audit citation.
Steady-state ownership //Steady-state ownership (who owns each domain year-round) lives in the framework document, Section 2.4.