> You’re not going to turn the business off because somebody’s inbox got compromised, or because there’s some unexplained event in the SIEM,
duh, those get handled several pages before "press the red button" is even discussed. You think "turn off the business" is the only page in the playbook?!
> and those are the sort of events you’re actually going to have to respond to.
Tell that to SolarWinds.
You need a IR plan that has appropriate responses to the threats you are facing. But at the scale and impact of a company like SolarWinds it's actually rather reassuring to have a "stop the world" backstop because your threat model absolutely includes catastrophic levels of risk.
And "you won't be incentivized to push the button"? Come on. When things get to "state level adversary on your network, using your software to attack DHS and the Treasury" bad, you're going to absolutely push the button because in a few months when your CEO is answering questions in Congress they'll want to be able to talk about something that went right.