skip to content

The breached provider refuses to share the logs that would show whether its account touched your estate — what do you do?

level: principalimportance: nice to knowfreq 32%

answer

  1. you cannot compel; decide anyway
  2. state the assumption in writing
  3. sort remediation by regret
  4. ask narrowly about your own tenant
  5. unprovable is not the same as clear

basics

~20 s

Stop waiting for evidence you cannot compel. Set an explicit working assumption that the access was used, remediate on that basis, escalate commercially for narrow tenant-specific artefacts, and report the residual uncertainty plainly rather than as an all-clear.

solid answer

~50 s

I decide under an assumption instead of blocking on a third party. The working assumption is stated in writing — treat the access as used unless evidence says otherwise — and remediation follows it: re-issue or delete the identity, rotate every credential it could read, review what it created, and cut standing access down to just-in-time with recorded sessions. Most of that is work worth doing regardless, so the cost of being wrong is small. In parallel I escalate through the commercial relationship rather than the technical one, and I ask for narrow artefacts about my own tenant — session start and end times, the affected credential set, their determination window — not their incident report; suppliers who refuse the latter often provide the former. I record the refusal in writing. Then I tell leadership what I checked, what I fixed, and what stays unprovable, and I never let that be written up as 'no compromise'.

go deeper

for a junior

Understand that a supplier's assurance is not evidence about your estate, and that when nobody can prove what happened the safe default is to assume the access was used and change the credentials it could reach.

for a middle

Be able to list what remediation actually covers a possibly-abused support identity: re-issue the account, rotate the secrets within its reach, and revoke live sessions and tokens rather than only resetting a password.

for a senior

Show that you sequence by regret — cheap irreversible-anyway actions now, expensive irreversible ones gated on evidence — and that you keep asking narrowly for tenant-specific artefacts while the investigation continues.

for a principal

Own the decision under an uncooperative third party: state the working assumption, escalate commercially rather than technically, refuse an unsupportable all-clear while still giving leadership something to act on, and convert the episode into contractual evidence and access terms at renewal.

## The constraint that makes this a leadership question You cannot subpoena a supplier mid-incident, and if the contract has no audit or evidence clause you have no lever that works on the timescale you need. So the question is not how to obtain the logs. It is how to make a defensible decision without them, at a cost the business will accept, and how to describe the result honestly afterwards. ## Move one: name the assumption and remediate against it Write the assumption down explicitly — *the provider's access is treated as used by an unauthorised party during the stated window unless evidence establishes otherwise* — because an unstated assumption is one nobody can challenge and nobody can revisit later. Then sort remediation by regret. Actions that are worth doing whether or not the tip is true come first and need no evidence to justify: - re-issue or delete the supplier identity and any accounts it created; - rotate every credential inside its reach — vault entries, shared local administrator passwords, service accounts, API keys and cloud roles; - revoke live sessions and tokens as well as passwords, since a password change alone does not end an existing session, refresh token, ticket or OAuth grant; - remove standing privilege and replace it with just-in-time grants and recorded sessions; - turn on the collection you wished you had before the tip arrived. Actions that are expensive and irreversible — mass reimaging, taking production down, a full estate rebuild — stay gated behind evidence. That split is the whole argument: it lets you act decisively on an unverifiable claim while keeping the cost bounded, and it is exactly what a board wants to hear you reasoned about. ## Move two: escalate commercially, and ask narrowly The technical contact has already said no; the escalation path is the account relationship, and the ask should be reframed. 'Send us your logs' invites refusal because it sounds like a request for their internal incident material. Ask instead for artefacts that are arguably about *your* tenant: - session start and end times, source addresses and account names for connections into your environment during the window; - which credential or engineer identity was affected, and whether it was one that held access to you; - the window they have determined, and how it was bounded; - confirmation that any credential of yours held in their systems has been rotated. Put the request and the refusal in writing. That record matters later — for the contract renewal, for your own governance, and for anyone who asks afterwards why you assumed rather than knew. Where a customer relationship allows it, a joint call between their incident lead and yours often unblocks metadata that email will not. ## Move three: describe the residue honestly The reporting trap is a sentence like 'no evidence of compromise was found', which a reader will hear as 'no compromise occurred'. Say the three parts separately: 1. what was checked, with its coverage and retention bounds; 2. what was done, and what it means the access can no longer achieve; 3. what remains unprovable, and what would change the picture — for example, the provider releasing session records, or a second report arriving. Refusing to sign an unsupportable assertion is part of the job, and so is not leaving the business with nothing. The constructive version of 'I cannot say we were not compromised' is 'here is what we can support, and here is what we changed so that the unknown matters less'. Where regulated or contractual assertions are involved, that wording is drafted with the people who own those obligations rather than by the SOC alone. ## Move four: fix the structure at renewal This situation is a procurement outcome as much as a security one, and the fix is written into the next contract: a notification obligation with a stated deadline, an evidence and audit clause naming the artefacts you may request during an incident, supplier session logs exported into your own platform by default so you are never dependent on their goodwill, no standing administrative access, and a right to suspend access without penalty. Argue for those with this specific case as the exhibit — an unresolvable investigation is far more persuasive to a commercial owner than an abstract control requirement. ## The failure modes Waiting for the report, and doing nothing while the surviving evidence expires. Accepting a supplier's 'no customer data was affected' as your scope, when they are describing their systems and not yours. Concluding that an unverifiable claim is therefore not a claim. And quietly upgrading your own inability to find anything into a clean bill of health.

  • How much assume-compromise remediation is worth doing when the report may be wrong?
    Everything whose cost you would accept anyway: re-issuing the supplier identity, rotating the credentials it could read, revoking live sessions and tokens, removing standing privilege, and improving collection. Those are cheap relative to the exposure and defensible even if the tip evaporates. Hold back the expensive irreversible actions — mass reimaging, taking production offline — until evidence justifies them, and say explicitly that this is the line you drew.
  • Leadership wants to state that no customer data was affected — how do you respond?
    Decline that wording and offer a supportable substitute. Say what was examined and its limits, what was remediated, and what cannot be excluded on the evidence available. 'No evidence of compromise' will be read as 'no compromise', so it should not stand alone. Where the statement carries regulatory or contractual weight, it is drafted with the people who own those obligations rather than signed off by the security team alone.
  • What do you change in the supplier relationship afterwards?
    Write the gap out of the next contract: a notification obligation with a deadline, an evidence clause naming what you may request during an incident, supplier session logs exported into your own platform by default, no standing administrative access, and the right to suspend access without penalty. Use this unresolved case as the exhibit — commercial owners move on a concrete failure far faster than on a control catalogue.

saying these in an interview costs you the question

  • Waits for the supplier's report before acting
  • Accepts 'no customer data affected' as your scope
  • Reports no evidence of compromise as no compromise
  • Treats an unverifiable claim as no claim at all
  • Rotates the password but not sessions and tokens
  • Never records the refusal in writing

context