skip to content

Twenty hours into a declared intrusion the scope doubles — why is upgrading the severity grade easier than downgrading it?

level: seniorimportance: should knowfreq 56%

answer

  1. different burdens of proof
  2. findings raise it, proof lowers it
  3. silence is not narrowing evidence
  4. write the triggers at declaration
  5. an unobservable window is not a clean one

basics

~20 s

Upgrading rests on positive evidence: new reach you can point at. Downgrading requires proving the earlier reach never existed, and a missing log record is not that proof — the logging may have been off, expired, or blind to the technique.

solid answer

~50 s

The two moves have different evidential burdens. An upgrade is triggered by something you found: a second assumed role, a table with a higher classification label in the query records, a host inside a regulated boundary. That is positive evidence and it settles the matter. A downgrade asks you to assert that reach you previously credited was never real, and the usual candidate — no further records, no more alerts — is silence rather than evidence. Silence can mean the auditing was not enabled, the retention expired, or the technique writes no record at all. A downgrade is legitimate only on positive narrowing evidence: the transitive role set enumerated and empty, complete query records for the window, sampled contents confirming a lower classification. Practically, the way to make hour twenty painless is to write the regrade triggers into the declaration itself, so the upgrade is a lookup rather than a debate, and to regrade the whole assessment rather than adding a delta to the old one.

go deeper

for a junior

Know that a severity grade set early is provisional, that it moves when new reach is found, and that 'we have not seen anything else' is not a reason to lower it.

for a middle

Be able to explain why an absent log record or an unfired detection cannot narrow scope, and to give one example of evidence that genuinely could.

for a senior

Show that you pre-declare regrade triggers, redo the whole assessment on an upgrade rather than annotating it, and can state the exact evidence behind any downgrade you propose.

for a principal

Be ready to defend a standing convention for regrades — who may move a grade, what must be recorded, and how a downgrade is communicated to people who were mobilised on the higher one.

## Two moves, two burdens of proof A severity grade on a declared intrusion is a claim about reach. Moving it up and moving it down are not symmetric operations, and understanding why is most of what an interviewer is testing here. **Upgrading is cheap because it runs on positive evidence.** At hour twenty a second assumed role appears in the picture. That role's grants cover datasets the first grade never accounted for. The new reach is a fact you can point at, and the grade follows it immediately. Nothing about the earlier grade has to be wrong for the new one to be right — it was correct on the scope known at the time, and scope grew. **Downgrading is expensive because the evidence usually offered for it is silence.** The sentences that show up are *we have seen no further activity*, *no additional alerts have fired*, *there are no query records for that account*. None of these is evidence about the intruder. A detection that does not fire tells you a rule did not match records it saw; it does not tell you the behaviour did not happen. An empty audit trail tells you no record was written, which is a claim about your collection. Retention that expired before the window even opened tells you nothing at all. Grading down on any of these is grading down on your own blind spot. What *does* support a downgrade is positive narrowing evidence. The transitive role-assumption and group set was enumerated and turned out empty, so the reach really was the direct grants. The query records are complete for the whole window — coverage verified, not assumed — and show a bounded set of objects. The reachable schema's contents were sampled and confirmed to be of a lower classification than the catalogue label suggested. Each of these is something you established and can restate under questioning. ## The grade is load-bearing, so regrades have consequences A grade is not a label; it is an instruction that other people have already begun executing. It sets evidence-preservation scope, staffing and shift coverage, whether a retained response firm is engaged, whether a legal notification assessment is running, and which contractual clauses are in play. That produces two operational rules. First, an upgrade is not an increment. When the scope doubles, redo the assessment rather than adding to it: the timeline is rebuilt to include the new identity, containment is re-planned because the plan you had covered a smaller footprint, preservation is widened before anything else destroys evidence, and the notification assessment is redone against the newly reachable datasets. Treating an upgrade as an annotation on the old grade is how organisations end up with a SEV number that no longer matches anything anyone is actually doing. Second, a downgrade is a communication event with a memory. People who were pulled in on the strength of the higher grade, and any external party told about it, will remember. Downgrade only on evidence you can restate, record the basis and who decided, and keep the earlier grade visible in the record with the reason it changed rather than quietly overwriting it. ## Pre-decide the triggers at declaration time The reason hour twenty turns into an argument is that nobody wrote down in advance what would move the number. Write the regrade triggers into the declaration as named, checkable conditions: any second identity appearing in the chain; any query against a table carrying a named classification label; any session from outside expected network paths; any host inside the regulated boundary; any evidence of persistence. Then a trigger firing is a lookup rather than a negotiation with a tired incident lead at 22:00, and the grade moves on the evidence rather than on whoever is most insistent in the channel. ## Retention caps what you can ever settle One more asymmetry deserves stating. If retention on the first weeks of records has already expired, you cannot ever disprove reach in that window. The honest response is to grade that window on reach — the grants as they stood — say explicitly that the window is unobservable, and never let it read as clean. An unobservable window is not a quiet one, and the difference between those two sentences is the difference between a grade you can defend six months later and one you cannot. ## What a strong answer sounds like Name the asymmetry, name the evidential test on each side, give one concrete legitimate downgrade, and describe pre-declared triggers. The candidate who says *we would re-evaluate as we learn more* has not answered the question; the one who says *upgrades follow findings, downgrades follow proof, and silence is neither* has.

  • What regrade triggers would you write into the declaration itself?
    Named, checkable conditions: a second identity appearing in the chain, any query against a table carrying a specified classification label, any session from outside the expected network paths, any host inside the regulated boundary, any evidence of persistence. Pre-deciding them turns hour twenty into a lookup instead of an argument.
  • The grade is upgraded — what concretely has to be redone rather than extended?
    Evidence preservation is widened first, before anything overwrites it. Then the timeline is rebuilt to include the new identity, containment is re-planned for the larger footprint, staffing and coverage are reset, and the notification assessment is redone against the newly reachable datasets. An upgrade is a reassessment, not an annotation.
  • Retention expired on the first two weeks of records. How does that affect the grade?
    It caps what you can ever disprove. Grade that window on reach — the grants as they stood — and state in the basis that it is unobservable rather than clean. Any later summary that presents the gap as an absence of activity is a claim the evidence cannot support.

saying these in an interview costs you the question

  • Downgrades because no further alerts have fired
  • Treats an upgrade as an increment on the old assessment
  • Presents an unobservable retention gap as a clean window
  • Leaves regrade criteria undefined until the moment they are needed
  • Overwrites the earlier grade without recording why it changed

context