A single misclicked email can drain £10M. That’s not just a punchy opener – it’s the reality for Capita PLC and Capita Pension Solutions Limited, who recently faced a £14 million penalty after a cyber incident that exposed over 6.6 million personal data records. Let’s break down why containment decisions matter, and how a few hours’ hesitation can turn a cyber incident into a headline-grabbing disaster.
The Anatomy of a Delay
Capita’s cyber incident wasn’t just about a clever attacker or a technical loophole. It was about what happened after the breach was detected. The ICO report spells it out:
“The time that elapsed between the creation of the P2 Alert at 08:00 on 22 March 2023 and the issuance of the quarantine command at 18:07 on 24 March 2023 was 58 hours and 7 minutes. Capita’s target response to this alert had therefore been missed by 57 hours and 7 minutes.” (ICO Penalty Notice, p.62)
That’s nearly two and a half days where the attacker roamed free, escalating privileges and exfiltrating data. This is a classic case of a Cyber Incident where the difference between “handle” and “hesitate” is measured in millions.
Why Containment Is a Team Sport
Containment isn’t just about having the right tech – it’s about people, process, and clarity. The Capita case shows what happens when SOC teams are stretched thin:
“Capita is understood to have had 1 SOC analyst per shift in place at the time of the Incident in March 2023… it is a significant concern that SOC was so poorly resourced.” (ICO Penalty Notice, p.66)
If you’re running a Ransomware Response, speed is everything, that means:
- Clear protocols: Everyone should know who’s authorised to make containment decisions and what steps to follow.
- Empowered teams: SOC analysts and IT responders need the authority and tools to act without delay.
- Automation: Where possible, automate containment actions to avoid manual bottlenecks.
The Cost of Hesitation
The ICO’s verdict is blunt:
“Had Capita responded to the P2 Alert promptly… the Threat Actor would have been contained, and the data exfiltration would not have occurred.” (ICO Penalty Notice, p.66)
This was a High Risk scenario, classed as “catastrophic” not just for the technical loss, but for the reputational and regulatory fallout. The longer an attacker remains uncontained, the greater the risk to data, reputation, and compliance.
Turning Lessons into Action
So, what can we learn from this case study?
Organisations should:
- Review and rehearse containment protocols regularly. Tabletop exercises and simulations help teams practise decision-making under pressure.
- Ensure SOCs are adequately staffed and resourced. One analyst per shift is not enough for large, complex environments.
- Automate containment where feasible. Modern endpoint detection and response tools can quarantine devices and disable accounts in real time.
- Clarify authority and escalation paths. There should be no ambiguity about who can make critical decisions during an incident.
TL;DR
Capita’s penalty notice is a wake-up call. Rapid containment isn’t a luxury -it’s a necessity. The difference between a contained cyber incident and a headline-grabbing breach is often just a few hours’ decisive action. If you’re not sure your team can act fast, it’s time to run a tabletop and find out.


