Application owners refuse to sever a batch flow an intruder would also use: how do you decide, and who accepts the residual?
answer
- it is a purchase, and not your budget
- observe first, then argue about a list
- price the flow in destinations kept reachable
- narrow along several dimensions before deleting
- a refusal must end in writing with a name
basics
~20 sTurn the refusal into a priced choice. Show how many destinations that single flow keeps reachable, offer narrowed versions instead of all or nothing, and if the owner still refuses, write the residual reach down and have them accept it by name.
solid answer
~50 sContainment is bought with severed flows, so a refusal is a purchase decision that belongs to the owner of the business flow, not to me. I make it decidable: run observe-only first so we argue about a concrete list of connections that would have been denied, then price the entry in reach, for example that it alone keeps 140 of the 180 destinations reachable from the batch tier. Then offer a ladder rather than a binary: narrowed to named source hosts, to named destinations instead of a tier, to one port and direction, to the batch window, with an expiry. Most refusals are refusals of the all-or-nothing version. If it is still no, the outcome is a written residual accepted by name with a review date, quoted in the board pack beside the reach numbers.
go deeper
Know that segmentation work involves negotiating with the teams whose traffic you are about to block, and that exceptions are recorded rather than granted informally.
Be able to describe the observe-only period and why arguing from an actual list of would-be denials beats arguing from a diagram.
Show the narrowing ladder: source, destination, port, direction, time window and expiry, and how much reach each rung removes without stopping the business flow.
Own the fact that the decision belongs to the flow's owner, that your job is to price it and record the residual by name, and that you choose which refusals are worth escalating.
## The decision is not a security decision The control is subtractive, so every unit of containment is paid for by a legitimate flow that stops working. That makes the question *how much reach is this business flow worth* and that question does not belong to the security architect. What belongs to the architect is making it decidable: producing the number, offering real options, and ensuring that whatever is chosen is recorded with a name against it. ## Make the argument concrete before you make it An argument about a hypothetical break is unwinnable. Run enforcement in observe-only for a full business cycle, including month-end and quarter-end for a payments back-office, and publish exactly which connections would have been denied, with counts and times. Two things then change. The owner is arguing about a list rather than a fear, and you frequently discover the flow they were defending is not the one that actually matters, or that it comes from three hosts rather than the whole tier. ## Price the flow in reach Express the ask in the leaf's own arithmetic. *Severing this entry removes 140 of the 180 destinations still reachable from the batch tier. Keeping it means an intruder holding the batch account's session reaches those 140 with the account's full rights, because nothing in this project changes what the account may do there.* That sentence gives the owner a real quantity to weigh against their outage risk. Equally, if the honest number is three destinations out of 180, say that too and withdraw the request. Spending organisational credit on a three-destination cut is how a programme loses the argument it actually needs to win. ## Offer a ladder, not a binary Most refusals are refusals of *delete it*. The negotiable dimensions, roughly in order of how easily they are granted: 1. narrow the source to named hosts instead of a whole tier; 2. narrow the destination to named systems instead of a tier; 3. narrow to the specific service port and one direction; 4. narrow to the batch window rather than permanently open; 5. attach an expiry and a named owner so the entry has to be renewed rather than inherited. Each rung removes destinations from the closure without stopping the business flow, and the sum of several rungs is often most of the containment the outright cut would have bought. ## When the answer is still no Then the flow stays and the residual reach is accepted, explicitly, by someone who can accept it. That means a named owner rather than a team, the reach it preserves stated in the same numbers you used to ask, a review date, and a place it is recorded that a board can read. This is the part architects skip, and it is the part that matters: an unrecorded refusal becomes, after the next incident, a failure of the security function; a recorded one is a business decision that was made with the number in front of it. It also changes what you may say afterwards. The board pack cannot claim containment while the widest exception in the estate stands. It says reach fell from 180 to 40, that 140 of the removal was declined and by whom, and that the declined portion carries this residual. ## Keep the register from rotting Exceptions granted under rollout pressure outlive the rollout. Two disciplines keep them honest: every entry carries an owner and an expiry so renewal is a decision rather than inertia, and each renewal restates the destinations the entry keeps reachable, so the price is re-read every time. A register that only grows is indistinguishable from no register, and it is the usual reason a second segmentation programme is needed five years after the first. ## What an interviewer is listening for That you know the decision is not yours, that you can put a number on it, that you offer narrowing instead of a binary, that you accept a no without either capitulating silently or escalating everything, and that you leave a written residual behind. A candidate who says they would simply enforce it has never run one of these; a candidate who says they would drop it has bought nothing.
- The owner says nobody knows what actually uses that flow. What do you do?That is an argument for measurement, not for permanence. Time-box an observation window that covers the real business cycle, publish the callers with names and volumes, then re-ask with facts attached. Meanwhile the entry stays but carries an expiry, so the unknown does not quietly become a permanent grant that outlives everyone who remembers why it exists.
- How do you stop the exception register becoming a list nobody reads?Keep it small and make renewal cost something. Every entry names an owner, an expiry and the destinations it keeps reachable, so renewing is a business decision with a quantity attached rather than a signature. If the register grows every quarter and never shrinks, the programme has stopped buying containment and is only recording its absence.
- When should you not push for the cut at all?When the reach removed is small and the flow is critical. If severing an entry removes three destinations out of 180 from a payments batch path, the containment bought does not justify the outage risk or the credibility spent. Say the number, withdraw the request, and keep the argument for the entry that carries a hundred destinations.
saying these in an interview costs you the question
- Presents the cut as a mandate with no cost stated
- Accepts the refusal silently and records nothing
- Grants a permanent exception with no owner or expiry
- Claims containment in the board pack while the exception stands
- Escalates every refusal instead of the ones that carry real reach