research-document
OODA Scenario
OODA Scenario
A cybersecurity team detects unusual network traffic that may indicate ransomware activity.
The team faces:
- incomplete telemetry
- time pressure
- executive pressure for a rapid recommendation
- uncertainty about whether the activity is active compromise, false positive, or lateral movement precursor
- competing response options including isolate immediately, gather more evidence, or narrow containment first
The team must recommend a course of action while acknowledging uncertainty and the possibility that new evidence could change the decision quickly.