A plant manager refuses to sign any firewall rule deletion. How do you still retire reach an intruder could inherit?
answer
- his risk is measured, yours is not
- change the ask, not the argument
- disable is not delete
- let the owners claim, not you guess
- the veto and the exposure sit apart
basics
~20 sChange what the plant manager is being asked to approve: reversible disables at a time he chooses, owners claiming the rules they need, narrowing where deletion is refused, and the residual exposure escalated to whoever owns both risks.
solid answer
~60 sHe is not being irrational: he owns a stopped production line and you own a hypothesis, and nothing in the change you proposed shifts that. So change the proposal rather than repeat it. Make the action reversible — disable in place with the rule retained, an agreed rollback measured in minutes, executed at a time he picks, ideally at the start of a shutdown window when the line is already down and the rare flows are being exercised in front of you. Invert the burden with a claim exercise: publish the unowned list with its evidence, ask teams to claim what they need, and disable the unclaimed on a stated date, which leaves his veto intact but stops the default being silence. Where deletion is refused, narrow — cutting a permit to the addresses and ports actually in use captures most of the exposure for a smaller ask. Whatever survives, write it up as reach in his language and get it accepted, dated and owned by someone above both of you.
go deeper
Know that a firewall rule can be disabled rather than deleted, which makes a change reversible in one step if something stops working.
Be able to explain why the person who owns production availability weighs an outage very differently from an unproven security exposure, and what makes a change proposal easier to approve.
Show that you would time the change to a shutdown window, agree a rollback and a watcher, and use narrowing where deletion is refused.
Own the structural point: the veto and the exposure sit with different people, so the outcome you drive for is a named owner and a dated acceptance, not an override.
## Understand the refusal before you try to move it The plant manager's incentives are clean and public: an unplanned line stop costs a measurable amount per hour, it is attributed instantly, and it is his. Your risk is unmeasured, undated and belongs to nobody in particular. If you go back with the same request and a better slide deck, he refuses again and you have spent your credibility. Every technique below works by changing the shape of the decision, not by arguing harder about the same one. ## 1. Make the action reversible, and let him set the clock Most rulebases support disabling a rule without removing it. That converts "delete" into "stop enforcing for a period, with the line intact and a one-step restore". Then negotiate the three things he actually cares about: - **When.** He picks the window. The strongest slot is the start of a shutdown or turnaround: the line is already down, engineering and vendors are on site and exercising exactly the rare flows you are worried about, and anything that breaks breaks in front of people who can identify it. - **How fast it comes back.** Commit to a rollback time and rehearse it. "Restored within ten minutes of a phone call" is a number he can plan around. - **Who is watching.** Somebody named, reachable, on shift for the duration. A reversible change with an owner and a rollback is a fundamentally different ask from a permanent deletion, and it is the single change that most often unlocks a refusal. ## 2. Invert the default with a claim exercise Today the default is silence: nobody has to do anything for a rule to survive. Publish the unowned list — each entry stating source, destination, ports, hit evidence and counter epoch in plain language — and ask teams to **claim** the rules they need by a date, after which unclaimed rules are disabled on the reversible terms above. This does not remove his veto; he can claim anything he wants. What it removes is the ability of the whole organisation to keep a grant alive by not answering emails. It also produces the thing you actually want more than deletions: named owners. ## 3. Narrow when you cannot remove A rule that permits `enterprise` to `plant-servers`, any port, is a different object from one permitting three source hosts to one destination on one port. Narrowing is a much smaller ask — the flow keeps working by construction if you narrow to what is genuinely in use — and it removes most of the reach. If he will not let you delete, ask what he will let you shrink. A rulebase of the same length with a tenth of the reach is a real security outcome, even though it makes no progress on any rule-count metric. ## 4. Price the exposure in his language "Legacy rule, no owner, zero hits" is invisible to him. "Any laptop on the enterprise network can open any port on the line-control historian, and nothing is watching that path" is not. Translate each surviving permit into what somebody who got onto the office network could do to his plant. That is the only version of the risk he is equipped to weigh against a production stop, and some of the rules he was defending stop being worth defending once he can see them. ## 5. Escalate the split, not the person The structural problem is that the veto and the exposure sit with different people. He can refuse; he does not carry the consequence of refusing. That is not a fight to have with him — it is a decision that belongs to whoever owns both sides: the site director, the operations risk committee, whoever signs for both plant availability and plant security. Bring them a short list, the reach each item grants, what you propose, and what you need decided. Do not bring a request for an override; bring a request for an owner. ## 6. Accept the residual honestly If, after all this, some rules stay, that is a legitimate outcome — provided they are now a dated, itemised, signed acceptance rather than sediment. The failure state is not "rules remained". The failure state is that nobody chose them and nobody knows they exist. Converting silent decay into an owned decision is most of the value; the deletions are the remainder. ## What interviewers listen for Candidates who have not done this argue about the technical case. Candidates who have done it talk about reversibility, timing, who is on shift, who claims, who signs, and what happens to the rules that survive. The test is whether you can make progress against a refusal you cannot overrule — and whether you know that shrinking reach counts even when the rule count does not move.
- Why schedule a rule disable at the start of a shutdown window rather than on a quiet weekend?Because a shutdown is when the rare flows actually run. Engineering tooling, vendor remote sessions and diagnostic access all appear in that window, with the people who own them on site. If a disable breaks something, it breaks in front of someone who can name it within minutes — which is both the safest failure and the best evidence you will ever get about what that rule carried.
- The claim exercise produces no responses at all for forty rules. What does that tell you?That there is no owner, not that there is no need — silence is exactly what an orphaned but live flow looks like. Treat unclaimed as a trigger for the reversible disable, staged by reach with the highest first, and with the rollback and watcher agreed in advance. The absence of a claimant raises the priority and does not lower the care.
- You cannot remove a broad permit, but you can narrow it. How do you decide the new scope?From the device's own per-rule connection records if they were enabled, since the hit counter is a single number and does not decompose into sources or ports. Where those do not exist, narrow in stages a reasonable person can defend — destination first, then ports, then sources — each step reversible on the same terms, so the risk of each cut is small and visible.
- What do you take to the site director rather than to the plant manager?Not an override request. A short itemised list of what each unowned permit lets someone on the enterprise network do to the plant, what you propose for each, and the decision you need: accept, fund the work, or authorise the reversible disables. The point is to place the residual risk with the one person who owns both plant availability and plant security.
saying these in an interview costs you the question
- Escalates for an override instead of for an owner
- Repeats the same deletion request with more urgency
- Deletes quietly at the weekend and hopes
- Measures success in rules removed rather than reach removed
- Presents the risk in firewall terms to a production audience
- Treats acceptance of residual risk as a failure rather than an outcome