The First 48 Hours

Your IT admin sees your Slack go dark. Your calendar events aren't being accepted. Your commits stop. Your last login was days ago.

They know before your family tells the company. And in those 48 hours, before anyone is officially notified, a lot can happen:

Source code export — git clone the entire codebase • Customer data download — export CRM, user databases • Credential harvesting — copy saved passwords, API keys, admin tokens • Financial access — initiate unauthorized transactions • IP theft — download trade secrets, proprietary algorithms

You'd like to think your employees are loyal. Most are. But it takes only ONE bad actor in a moment of opportunity to cause irreversible damage.

The Leadership Vacuum Is an Invitation

Insider threat research consistently shows that unauthorized access spikes during organizational transitions — mergers, layoffs, and especially after the departure (or death) of a key leader.

Why?

• Normal oversight is disrupted • Nobody is checking the access logs • Staff assume "nobody is watching" • The person who set the security policies is the person who's gone • Emotional turmoil reduces vigilance

The longer the leadership vacuum persists, the more exposure you have.

Keep Lockdown Separate from Delayed Handoff

A 48-hour security incident needs monitored identity, endpoint, DLP, banking, and on-call controls; ZeroLatch is not designed for that timescale. Maintain an immediate incident runbook that can revoke admin access, preserve evidence, freeze financial instruments, and notify authorised leaders without waiting for a dead man's switch.

ZeroLatch can hold a longer-term copy of the runbook and succession material for an authorised recipient. Although its shortest check-in is 1 day and the safety period can be removed, lifecycle processing runs daily and it should be treated as a continuity backstop rather than a lockdown trigger.