skip to content

Finance rejects the restore point that predates the intrusion — who owns that call and how do you frame it?

level: principalimportance: nice to knowfreq 33%

answer

  1. certain loss versus unquantified risk
  2. frame it, do not try to win it
  3. the accountable owner signs
  4. refuse the binary — split data from platform
  5. counsel, insurer and regulator can narrow it

basics

~20 s

The trade is certain business loss against residual adversary presence, so the accountable business owner takes it, not the responder. Your job is to state honestly what each option costs, offer the middle paths, and record what was accepted.

solid answer

~50 s

This is a risk-acceptance decision wearing a technical costume, and responders get into trouble by trying to win it rather than to frame it. I put two honest statements on the table: the pre-intrusion point means a known, quantifiable loss of business records; the later copy means an unquantified chance of redeploying the intruder's work into a system we just cleaned. Then I offer the middle ground, because the poles are rarely the real choice — restore the clean point and reconcile the gap from sources the intruder did not control, or rebuild the platform from known-good media and carry only validated data forward. If the business still wants the later copy, that is theirs to accept, with compensating controls attached and a review date. I record what was accepted, by whom, and on what evidence.

go deeper

for a junior

Understand that choosing a restore point after an intrusion has a business cost, and that the security concern has to be explained in terms the business can weigh.

for a middle

Be able to describe the middle options — rebuilding the platform from known-good media while importing only validated data, or reconciling the gap from sources outside the compromised system.

for a senior

Show that you separate the risk statement you own from the acceptance decision you do not, and that you attach compensating controls and a review date when the business takes the riskier path.

for a principal

Own the framing end to end: who signs, what counsel, the insurer and any regulator constrain, what the written record must contain, and the fact that some systems will never be restored and that decision must be made explicitly.

## Why this argument happens After a long intrusion the clean restore point is old, and "old" has a price tag that someone in the business can compute exactly: weeks of transactions, orders, case records, ledger entries. The security side's objection to the newer copy has no comparable number. Certain loss argues far more loudly than uncertain risk, which is why the conversation goes badly if the responder tries to win it on volume. ## Whose decision is it? The person accountable for the business consequence owns the decision. The responder owns the honesty of the inputs. That division matters for three reasons: the responder cannot price weeks of lost revenue or a missed regulatory filing; the business owner cannot price the chance of reintroducing an implant; and if the organisation later has to explain the choice, an accepted risk with a named owner is a defensible record while a technical veto is not. What the responder must not do is soften the input to make the decision easier. "The later copy is probably fine" is not a finding. The honest statement is narrower and more useful: this copy was written while the intruder had privilege on this system; here is what we know they did on systems like it; here is what we would be unable to detect if they had done it here. ## The poles are rarely the real choice Most of the value a senior responder adds is in refusing the binary: - **Restore clean, reconcile forward.** Restore the pre-intrusion point and rebuild the gap from sources outside the compromised system — an upstream system, a payment processor, a partner's records, a data warehouse or reporting copy, exports and statements. Slower, but it produces records you can stand behind. - **Split data from platform.** Rebuild the application and operating system from known-good media and configuration, then import only *data* from the later copy after validation. The intruder's work lives in executables, scheduled jobs, configuration, accounts and permissions — not usually in the business rows. This resolves a surprising number of these arguments outright. - **Stage it.** Bring the service back on the clean point so the business is operating, and reconcile or import the gap over the following days rather than blocking return to service on the argument. - **Accept with conditions.** If the later copy is genuinely the only path, attach the conditions that make it survivable: credentials for that system replaced, the entry path closed, application-layer review of what changed during the window, heightened monitoring for a defined period, and a scheduled review at which the acceptance is revisited. ## Sequencing, and the owners who all want to be first The same conversation repeats over order of return, and again the responder's criterion is not revenue. Things come back in trust-dependency order: identity and the administrative tier first, then the management and security plane that will build and watch everything else, then business systems by dependency — each rebuilt from known-good sources onto a network segment that has been rebuilt too, with nothing reconnecting to the old one. Service owners will argue for their system's position; the argument is winnable only if the criterion was written down and agreed before the queue formed, ideally in the recovery plan rather than in the incident. And some systems never come back. There is always a set of servers whose owner cannot justify the rebuild, whose function was superseded, or whose data is recoverable from elsewhere. Explicitly deciding to decommission them is a good outcome, not an admission of defeat — what is bad is leaving them undecided, because an unrestored, unremediated system that quietly gets reconnected months later is a path back. ## Constraints from outside the room Three parties can narrow the choice, and a principal-level answer knows to check them early. Counsel may need the untrusted copy preserved as evidence rather than overwritten. The insurer may condition cover on following defined steps. A regulator or a customer contract may require an assertion about integrity of restored records that the later copy makes impossible to sign. Any of these can turn a business preference into a non-option, so they belong in the framing rather than as a late surprise. ## What the record should say When the decision is taken, write it down while it is fresh: the options presented, what each was assessed to cost, what evidence supported the risk statement, which option was chosen, by whom, what compensating controls were attached, and when the acceptance is reviewed. That record is what makes the decision defensible to a board, an insurer or a regulator months later — and it is what stops the compensating controls from quietly lapsing once the crisis energy fades.

  • How do you make the security side of the trade concrete enough to argue against a revenue number?
    By replacing "it might be unsafe" with specifics: this copy was written while they held privilege on this system, here is what they did on comparable systems, here is what we would be unable to see if they had done it here, and here is what a second intrusion through that path would cost us in downtime and notification. Uncertainty stated precisely competes far better than uncertainty stated vaguely.
  • The business accepts the later restore point. What conditions do you attach?
    Credentials and keys for that system replaced, the entry path closed, an application-layer review of changes made during the intrusion window, heightened monitoring on that host and its egress for a defined watch period, and a named review date at which the acceptance is reconsidered. All of it written down with the accepting owner named, so the controls do not lapse when attention moves on.
  • Several service owners each insist their system returns first. What criterion settles it?
    Trust dependency, not revenue. Identity and the administrative tier come back first, then the management and security plane that builds and monitors everything else, then business systems in dependency order, each onto rebuilt infrastructure. The criterion has to be agreed in the recovery plan before an incident, because arguing it for the first time under pressure means the loudest owner wins.

saying these in an interview costs you the question

  • Treats the restore point as a purely technical decision to veto
  • Says the later copy is probably fine rather than stating what is unknown
  • Offers only the two extremes and no middle path
  • Lets the business accept the risk with nothing written down
  • Sequences return to service by revenue rather than trust dependency

context