Who decides that a credential exposure is an incident, and who tells the counterparty whose service it opened?
answer
- not the finder's call
- threshold written before the night
- declaring does not wait for scoping
- one named voice outward
- their record is the only usage evidence
basics
~20 sNot the engineer who found it. A named decision-maker declares against a threshold agreed in advance, and a single named voice contacts the counterparty — which is also how you obtain the usage record only they can see.
solid answer
~40 sTwo decision rights sit above the on-call engineer and both should be settled before the night they are needed. The first is the declaration: a named role decides, against a written threshold, and it must not wait for scoping to finish, because scoping is work the declaration pays for. The second is the outward contact: one named voice speaks to the counterparty, using a channel and an addressee agreed ahead of time, rather than whichever engineer has their support portal open. That contact is not a courtesy — the counterparty holds the only record of what was actually called with the credential, so telling them is how the investigation gets its evidence. The engineer's job is to contain, preserve and hand over facts, not to grade the event.
go deeper
Know that grading an exposure is not the finder's job. Contain, preserve what you saw, and escalate to whoever owns the decision rather than deciding how serious it is yourself.
Explain why the declaration threshold is written in advance and why it is applied before scoping finishes, and what kind of evidence can justify a later downgrade.
Show the outward message you would send the counterparty and what you ask for in it, and explain why their usage record makes that contact part of the investigation rather than a courtesy.
Own the threshold itself: where you set it, how you judge the setting by what it suppresses, and how you keep one voice outward without the process becoming the reason people fix exposures quietly.
At 2am the hardest part of a credential exposure is rarely technical. It is that two decisions have to be made by people who are not the person holding the evidence. ## Why the finder is the wrong decider The engineer who found the value is the worst-placed person to grade it, for three reasons that have nothing to do with competence: - **They are inside the incentive.** If the leaked credential came from a carrier their own team maintains, grading it is self-assessment under pressure. - **They hold one side of the picture.** They can see what the value could reach; they usually cannot see what the organisation has already promised anyone about events of this kind. - **Grading is a distraction from containment.** Every minute spent debating severity is a minute not spent scoping and not spent finding the route. The workable split is: the finder contains, preserves and reports facts; a named decision-maker grades. That role must be reachable at 2am, which is a staffing decision, not a policy sentence. ## A threshold decided in advance The threshold has to be written down before the night it is used, because at 2am everyone argues towards the outcome that lets them go back to bed. A serviceable default is blunt: *a credential that was valid and readable by an uncontrolled audience is an incident until scoping shows otherwise*. Two properties matter more than the exact wording: 1. **It does not wait for scoping.** Declaring is what buys the people who do the scoping. Waiting for scope before declaring inverts the dependency and is the most common way an exposure is quietly handled by one tired person. 2. **It can be downgraded on evidence, not on effort.** "We replaced it quickly" is effort. "The value was never valid" or "it carried no rights anywhere" is evidence. | Decision | Who owns it | What it must not wait for | |---|---|---| | Is this an incident? | A named decision-maker, on call | Completed scoping | | Contain now or preserve first? | The same decision-maker, advised by the finder | A meeting | | Contact the counterparty | One named voice, using a pre-agreed channel | The investigation finishing | | Tell parties further downstream | The role that owns external communication | The counterparty's own findings | ## Telling the counterparty is an investigative step This is the part that gets mis-filed as etiquette. The service on the other end holds the only record of what was actually called with the exposed credential, and in most arrangements you do not see it by default. So the contact is doing three jobs at once: it asks them to withdraw acceptance of the old value on their side, it asks for the usage record over the exposure interval, and it discharges whatever obligation you have to tell them. Delaying it until the investigation is complete delays the investigation, because the evidence is theirs. It still goes through one voice. A single addressee, agreed in advance, prevents three engineers opening three threads with three different accounts of scope — which, from the counterparty's side, reads as an organisation that does not know what happened. What that voice sends should be narrow and checkable: which credential, when it became public, what it was entitled to, what you have done, and precisely what you are asking them for. ## Who tells anyone further downstream If the rights the credential carried reach material belonging to other people, a second decision appears, and it belongs to whoever owns external communication rather than to security or to engineering. Two rules keep it honest: say what the credential *could* reach and what the records *do* show, as separate statements; and never let the first outward message be one that a later, better-scoped message has to contradict. The gap between "exposed" and "demonstrably used" is exactly the gap that unobserved intervals create, and stating which side of it you are on is the difference between a communication that survives and one that gets re-issued. ## The failure modes worth pre-empting - **The quiet fix.** One engineer replaces the value, closes the page and tells nobody, and the organisation loses the record, the route and the chance to ask for the usage evidence. - **The threshold argued at 2am.** No written default, so the grading depends on who is awake. - **The many voices.** Several people contact the counterparty separately with different scopes. - **Waiting for certainty.** Contact is delayed until the scope is final, which is the moment their retention window is most likely to have expired. The principal-level judgment is where to set the threshold at all. Set it low and you pay in fatigue and in people learning to route around the process; set it high and a scoped, real exposure is handled as hygiene by whoever happened to find it. The test of the setting is not how many declarations it produces but whether the ones it suppresses are ones you would have been content to read about later.
- Why should the declaration not wait until scoping is finished?Because declaring is what staffs the scoping. Waiting inverts the dependency and leaves one tired person doing an estate-sized job alone at 2am. Declare on the blunt condition — a valid credential was readable by an uncontrolled audience — and allow a downgrade later on evidence, such as the value never being valid or carrying no rights, rather than on how fast it was replaced.
- What exactly should the single outward message to the counterparty contain?Which credential, when it became publicly readable, what it was entitled to do on their side, what you have already done, and the specific asks: stop accepting the old value, and send the record of every call accepted with it over that interval, with sources and their retention boundary. Narrow and checkable beats apologetic and vague; they are being asked for evidence, not reassurance.
- How do you set the declaration threshold without drowning in declarations?Judge the setting by what it suppresses, not by what it produces. A threshold is too high the first time a genuinely scoped exposure is closed quietly by whoever found it; too low when teams start routing around the process to avoid the overhead. Write the default, review it against the exposures of the last year, and keep the downgrade path cheap so a fast declaration costs little.
saying these in an interview costs you the question
- The engineer who found it should grade it.
- Tell the counterparty once the investigation is closed.
- Declaring has to wait until scoping is complete.
- Any engineer may open a thread with the counterparty.
- We replaced it fast, so nobody outside needs telling.