skip to content

Counsel wants a suspected insider's account left live to gather evidence; the CISO wants it disabled now. Who decides?

level: principalimportance: should knowfreq 38%

answer

  1. two remits, neither contains the other
  2. name the tie-breaker before the incident
  3. HR is not an observer here
  4. look for the reversible middle
  5. time-box it and write down why

basics

~20 s

Neither function outranks the other, so the tie goes to the accountable executive the plan names, with HR present because cutting an employee's access is an employment act. Take the reversible option, time-box it, record the rationale.

solid answer

~50 s

Counsel owns legal exposure and the evidential picture; the CISO owns the security risk of continued access; HR owns the employment consequence of touching a live employee's account. None of them outranks the others by default, which is why a mature plan names one accountable executive who breaks ties and says so before an incident, not during one. State the real trade: leaving the account live shows what else the subject does and avoids tipping them off, while every retained hour is more data out and more difficulty explaining why you waited. Then look for the reversible middle: revoke the active sessions and the bulk-export entitlement rather than the whole account, set an explicit review time, and define the trigger that ends the observation immediately. Whatever is chosen, write down who decided, on what basis and when, because that record will be examined.

go deeper

for a junior

Understand that this call is not the analyst's to make. Your job is to state clearly what continued access can still reach and what you have already preserved, and to escalate rather than act on the account yourself.

for a middle

Be able to lay out both positions fairly, the evidential value of observing versus the exposure of continued access, and to name the middle options such as revoking sessions and entitlements without disabling the account.

for a senior

Show you can drive the decision: package the trade in business terms, recommend one option with your confidence, secure a time-box and a trigger that ends observation, and ensure preservation happens regardless of which way it goes.

for a principal

Own the structure. Name the tie-break executive in advance, write standing criteria for when continued access stops being arguable, agree the employment mechanics with HR, and make sure the reasoning is recorded well enough to defend later.

## Two functions, two legitimate positions, no default winner This is the disagreement that a plan built only of technical roles cannot resolve. Counsel argues for keeping the departing employee's account enabled: the case is thin, the evidential picture would be much stronger with another few days of activity, and disabling the account announces the investigation to its subject, who may then destroy a personal device, delete a cloud copy or leave with a story straight. The CISO argues for cutting now: every retained hour is more of the organisation's data leaving, the risk is asymmetric, and an organisation that knew and did nothing has a far worse position afterwards than one that acted early. Both are right within their remit, and neither remit contains the other. Security cannot judge the litigation posture. Counsel cannot accept the operational risk of continued exfiltration on the security team's behalf. Nor is HR an observer here: disabling a current employee's access is an employment act with process implications, may amount to a de facto suspension, and in some jurisdictions has to follow defined steps. ### The answer to *who decides* The honest answer at this level is that the decision belongs to a single accountable executive, named in advance. Which chair that is varies legitimately: at some organisations the General Counsel, at others the CEO or a designated deputy, at a regulated firm sometimes a risk committee chair with authority to act between meetings. What is not acceptable is the two common failure modes: an argument settled by whoever is loudest or most senior in the room, or an escalation into a committee with no named decider that produces delay dressed as consensus. An interviewer is testing whether you know that the resolution is structural rather than rhetorical. The good answer says: we agreed this in the plan; here is who the decision-maker is; here is what I put in front of them. ### What you put in front of them Executives cannot arbitrate a technical argument, so do not hand them one. Hand them the trade in their terms: - **What continued access can still reach.** Named systems and data classes, not a vague *sensitive data*. - **The rate.** What has already left, over what period, so *another 48 hours* has a magnitude attached. - **What observation would actually buy.** Be honest: often the answer is *confirmation of intent*, which matters for an employment case and rarely changes the security picture. - **The tipping-off risk if you act.** What the subject can still destroy that you have not preserved. - **The reversibility of each option.** Cutting access is easy to reverse; data already gone is not. ### The reversible middle The framing *who wins* is usually a false binary, and the strongest answers refuse it. Between *leave everything live* and *disable the account* sits a range: revoke active sessions and refresh tokens while leaving the account enabled; remove the bulk-export entitlement or the group that grants it; restrict access to a device or network the subject is not on; move the subject's most sensitive dataset out of their reach on a routine-looking change. And do the preservation work regardless, so that if the decision later flips to immediate cutoff, you are not left with the only account of what happened having aged out of retention. Bind whatever you choose to a **time-box and a trigger**: observation continues until a stated hour, and ends immediately if a defined event occurs, for example any further bulk export or any access to a named regulated dataset. Open-ended observation is how a considered decision becomes a drift nobody owns. ### The record This decision will be re-examined, possibly in an employment tribunal, possibly by a regulator, possibly by a board asking why nothing was done on the Tuesday. Write a dated note: what was known at the time, what options were considered, who decided, on what basis, and what the review trigger was. A decision that looks indefensible in hindsight but was reasoned and recorded at the time is survivable; a good decision nobody wrote down is not. ### Doing the work before the incident The principal-level move is to make this argument boring in advance. Name the tie-break executive in the response plan. Write standing criteria while nobody is emotional, for instance that continued access to regulated data ends the observation debate immediately. Pre-agree with HR what constraining an employee's access means procedurally. Have the counsel-directed forensic engagement ready to activate rather than negotiated mid-crisis. The organisations that handle this well are not the ones with better arguments at 03:00; they are the ones that had the argument in daylight, months earlier.

  • What do you actually put in front of the executive who has to break the tie?
    The trade in business terms: which named systems and data classes continued access can still reach, how much has already left and over what period, what further observation would genuinely buy, what the subject could destroy if you tip them off, and the reversibility of each option. Recommend one, state your confidence, and give a deadline for the decision.
  • Is there an option between leaving the account live and disabling it?
    Usually yes, and finding it is the stronger answer. Revoke active sessions and refresh tokens while the account stays enabled, remove the bulk-export entitlement, restrict access to a device or network the subject is not using, or move the most sensitive dataset out of reach as a routine-looking change. Each cuts exposure without announcing the investigation.
  • How do you keep an observation decision from drifting?
    Bind it to a time-box and a trigger. Observation runs until a stated hour with a scheduled review, and ends immediately if a defined event occurs, such as any further bulk export or any touch of a named regulated dataset. Assign one person to watch for the trigger. Open-ended observation is how a considered decision becomes nobody's decision.
  • How much of this should be settled before an incident happens?
    Almost all of the structure. Name the tie-break executive in the plan, write standing criteria for when continued access is no longer arguable, agree with HR what constraining an employee's access means procedurally, and have the counsel-directed forensic engagement ready to activate. Live cases should be executions of prior agreements, not first negotiations.

saying these in an interview costs you the question

  • Says the CISO always wins because it is a security incident
  • Treats counsel's preference as binding on operational risk
  • Escalates to a committee with no named decision-maker
  • Cuts a live employee's access without HR involvement
  • Presents the executive with a technical argument to arbitrate
  • Leaves the observation open-ended with no trigger or review
  • Makes the call and records nothing about the reasoning

context