skip to content

How do you make a prevented incident land as a result in a behavioral interview story?

level: seniorimportance: should knowfreq 52%

answer

  1. You cannot measure an absence directly
  2. Measure the hole, not the disaster
  3. How often did this happen before?
  4. Harvest the measurable side effects
  5. Name the behaviour change, not the feeling

basics

~20 s

Evidence the absence with what surrounds it: the size of the exposure closed, how often the thing used to happen, and what changed downstream. Prevention is shown by sizing the risk and by second-order effects, never by inventing a number for an event that never occurred.

solid answer

~50 s

A result that consists of nothing happening cannot be measured directly, so I evidence its edges. First I size the exposure: the vulnerable dependency was reachable in 9 of 23 services and findings of that severity had been sitting open 19 days on average. Second I give the recurrence history, because 'this class of thing happened three times in the previous year' is a real frequency rather than a hypothetical. Third I reach for the downstream effects that were measurable: the rota's monthly load, roughly 30 to 40 hours before, and the open queue falling from 214 to 38. What I do not do is put a figure on the breach that did not occur — that number is unfalsifiable, and claiming it is the fastest way to make a genuinely good story sound inflated.

go deeper

for a junior

Know that some results are absences and that the honest move is to describe the risk that was closed. Never attach a made-up cost to an incident that did not occur.

for a middle

Be able to name concrete evidence around the absence: how many systems were exposed, how long the gap was open, how often that class of problem had happened before.

for a senior

Show calibration — separate what you can evidence from what you can only assert, harvest the measurable side effects, and say plainly which part of the outcome has no metric.

for a principal

Own the argument that this work was worth its cost against alternatives that were not funded, and be able to defend how you decided the exposure justified the effort at the time.

## The class of results with no number Several genuinely strong outcomes leave no metric behind. An incident that did not happen. A team that stopped being blocked. Trust that made a later hard conversation possible. Security work is full of the first kind, and candidates handle it in one of two bad ways: they invent a saved-cost figure for the breach that never occurred, or they shrug and say 'it is hard to quantify' and let the story end with no evidence at all. Both waste the story. There is a third path. ## Move one: size the exposure, not the disaster You cannot measure the incident that did not occur, but you can measure the hole that was open. Which services were affected — 9 of 23. How long findings of that severity typically sat unresolved — a median of 19 days before the work, 6 after. Whether the path was actually reachable rather than theoretically present. All of these are real, checkable, and they let the interviewer size the risk themselves, which is far more persuasive than being told how big it was. This is the crucial distinction: sizing the exposure is evidence, sizing the hypothetical disaster is speculation. 'A breach here would have cost the company an enormous amount' is unfalsifiable and reads as self-promotion. 'The vulnerable path was reachable in 9 of 23 services and had been open for weeks' is a fact the listener can weigh. ## Move two: use the recurrence history If the class of event has happened before, its frequency is a legitimate number. 'We had three incidents from this pattern in the preceding period, and none since the change' is a real before/after, even though the after-value is an absence. Frequency data converts a counterfactual into something closer to a measurement, and it is often sitting in an incident log that nobody thought to look at. Where no history exists, say so. 'This had not bitten us yet, which is part of why it kept getting deprioritised' is an honest and rather compelling framing. ## Move three: harvest the second-order effects Prevention work almost always leaves measurable side effects even when the main outcome is an absence. The triage automation exists to stop things reaching production, but it also cut the rota's monthly cost from roughly 30 to 40 hours to about 7, drained the open-findings queue from 214 to 38, and pulled the median age of a high-severity finding from 19 days down to 6. None of those is the prevented incident; all of them are real and they point at it. ## Trust, unblocking, and other soft results The same discipline works for results that were never numeric to begin with. Do not assert the feeling — evidence the behaviour change that followed it. 'The team trusted me more' is unverifiable. 'After that, the two other rota members started reviewing each other's findings directly instead of routing everything through me, and the queue stopped depending on my availability' is an observable change with a consequence. Ask yourself what someone else would have noticed differently, and say that instead of naming the emotion. Unblocking has the cleanest version of this: whatever the other team could not do before, they did, and the delay before it disappeared. That is a duration, and durations are numbers. ## When to stop pushing for a number Some results genuinely have none, and forcing one is worse than admitting it. The honest closing move is to name the limitation and offer what you do have: 'There is no clean metric on the prevention side. What I can tell you is the exposure we closed and the rota load it took off the team.' A behavioral interviewer hears that as calibration. What they hear as a warning sign is a precise-sounding figure attached to an event that never happened, because that is a number that could only have been invented. ## Preparation checklist For every prevention or trust story, write four lines before the loop: the exposure you can size, the recurrence history if any, the measurable side effects, and one sentence naming what cannot be measured. That last line is not a weakness in the story — delivered deliberately, it is the line that makes the other three believable.

  • Nothing happened, so why should I believe the work mattered?
    Because the exposure it closed is measurable even though the incident is not. The vulnerable path was reachable in 9 of 23 services, findings of that severity had been sitting open for a median of 19 days, and that pattern had already produced incidents in earlier periods. I am not asking you to price a breach that never occurred; I am giving you the size of the hole and letting you weigh it.
  • How would you evidence a result like 'the team trusted me more'?
    By naming what people started doing differently. After that work, the other rota members reviewed each other's findings directly instead of routing everything through me, so the queue stopped depending on my availability. That is observable, has a consequence, and does not ask the interviewer to take a feeling on faith.
  • Would you ever estimate the cost of the incident you prevented?
    No, not as a headline result. Any figure for an event that never occurred is unfalsifiable and it makes a real story sound inflated. If pressed on materiality I would describe what the exposure allowed in concrete terms — what data was reachable, from where — and let the interviewer draw the size themselves.

saying these in an interview costs you the question

  • Pricing the breach that never happened as the headline result
  • Attaching an invented percentage to an outcome that never occurred
  • Asserting trust or morale with no observable change behind it
  • Refusing any evidence because the result was qualitative
  • Describing the exposure as theoretical without saying it was reachable

context