Containment beating interruption is the thing I would put first rather than last.
Once an agent runs in a throwaway container with its own scoped credential and no path to anything unrecoverable, the question stops being how fast you can stop it. A bad run costs money and time and nothing else, and you can afford to be asleep.
The credential scoping is the half people skip. A single shared key means revoking it during an incident takes down everything else that was using it, so you hesitate, and hesitation is the whole problem.