An executive is told 'it was a zero-day, so nothing would have stopped it' — what do you fund?
answer
- It is a claim, not a conclusion
- Two facts settle it
- The claim's scope is one control
- Money buys a clock, not immunity
- Residual risk needs a named owner
basics
~20 sFirst test the sentence: was a fix available on the day? Most such claims turn out to be n-day, where money spent shortening the gap between a fix existing and running pays off. If the claim holds, fund that shorter clock anyway and record the remainder as accepted residual risk.
solid answer
~50 sI treat the sentence as a claim, not a conclusion, and it has exactly one testable part: was a vendor fix available when the flaw was used? That is checkable against the release history and the version that was actually running, and most claims collapse — the fix existed and had not taken effect, which is an addressable gap wearing an unavoidable label. If the claim survives, it still only means that *patching* could not have prevented this one event; it never means nothing could have. On funding, the honest answer is that money buys a shorter clock, not immunity: the interval between a fix existing and corrected code actually running is where the great majority of real loss sits, and it is measurable and improvable. What I will not do is buy a promise of preventing unfixed flaws, and I will get the leftover risk written down and explicitly accepted by an owner rather than narrated away.
go deeper
Be ready to say that the claim can be checked: find out whether a vendor fix existed on the day and which version was running.
Explain why the answer usually changes the diagnosis — most events labelled zero-day turn out to involve a fix that existed and had not taken effect, which is a different and addressable problem.
Show you can bound the claim even when it holds: no fix existing rules out one control, not all of them, and the funded improvement is the interval between a fix existing and corrected code running.
Own the decision and its politics — refuse the guarantee, name what money can and cannot buy, get the residual accepted in writing by someone who can refuse, and stop the label being reused as a default explanation.
## Why this sentence needs answering rather than agreeing with 'It was a zero-day, so nothing would have stopped it' does two things at once. It explains an event, and it closes a budget conversation. The second is the reason it needs handling: if the label stands, the organisation has just concluded that the loss was unavoidable, and every improvement that would have actually helped becomes unfundable. The sentence is not automatically wrong. It is simply a claim, and it has a hard, checkable core. ## Step one: test the claim 'Zero-day' asserts one narrow, verifiable thing: **no vendor fix existed at the moment of use**. Two facts settle it — the vendor's release history for the affected component, and the version that was actually running when the event occurred. In practice most claims do not survive this. What is usually found is that a fix existed and had not taken effect on the machine involved. That is a completely different finding: an addressable gap in how quickly corrected code starts running, not an act of god. The label was doing the work of hiding it, and typically nobody applied it dishonestly — 'zero-day' is simply what people say when a compromise feels unexpected. ## Step two: bound what the claim covers even if it holds Suppose the check passes and no fix existed. The sentence still overreaches. 'No fix existed' means one specific control could not have prevented this event. It does not mean the event was invisible, unbounded, or beyond every other kind of intervention. The scope of the claim is one control, and saying so plainly is what stops the conversation ending there. ## Step three: say what money actually buys This is the part an executive can act on, and it needs to be stated as a trade, not a wish. - **A shorter clock is purchasable.** The interval between a fix existing and corrected code actually running in your estate is measurable, improvable, and it is where the overwhelming majority of real compromises land. Shortening it is unglamorous — it is about how quickly updates reach machines and how quickly long-running programs restart — and it is the highest-return item on the list precisely because the unfixed case is rare and the fixed-but-not-running case is not. - **Immunity from unfixed flaws is not purchasable**, and any spend justified as buying it should be challenged. If a control earns its budget, it earns it on what it does generally, not on a promise about a category defined by nobody knowing about it yet. - **The remainder is residual risk, and it needs an owner.** The correct outcome of this conversation is not that the risk is eliminated but that a named executive has looked at the size of it and accepted it in writing. That converts an argument that recurs after every incident into a decision with a date on it. ## Step four: guard the narrative for next time The organisational failure mode is that 'zero-day' becomes the default explanation for anything surprising. Once that happens, the same unfixed-but-fixable gap can produce compromise after compromise, each one narrated as unavoidable and none of them funded. The cheap countermeasure is procedural: require that the phrase be accompanied by the two facts that support it — the fix availability date, and the version that was running — before it enters any report that goes upward. If those two facts are not present, the sentence is a hypothesis. ## What a strong answer sounds like in the room 'Give me a day. If a fix existed when this happened, then the thing to fund is how long our software takes to actually start running fixes, and I can show you that number and where it would land after the spend. If no fix existed, I will tell you that too, and my recommendation will still be the same number, because that is the risk we can actually move — and I will bring you the piece we are choosing to accept so you can decide whether to accept it.' That answer is fundable, honest about what cannot be bought, and it does not let the label end the discussion. ## Common wrong answers - **Agreeing.** 'Zero-days are unstoppable' concedes the budget and the improvement in one sentence. - **Overpromising.** Claiming a purchase will handle unfixed flaws sets up the next conversation to be worse, because the next event will happen anyway. - **Winning the argument and stopping.** Proving it was an n-day and not converting that into a funded change to the clock leaves the organisation exactly where it was, minus some goodwill. - **Leaving the residual unowned.** Risk nobody has explicitly accepted is risk that gets re-litigated from zero after every event.
- The check shows a fix did exist. How do you say that without it becoming a blame exercise?Present it as a measurement, not a fault: the fix was available on this date, corrected code started running on that date, and the interval is the thing we are funding. Nobody chose that interval; it is a property of how updates reach machines and how long programs stay open. Framing it as a number with a target keeps the conversation on the improvement rather than on who missed a ticket.
- What if the executive asks for a guarantee that it will not happen again?Decline the guarantee and offer the trade instead. I can commit to a measurable reduction in the interval between a fix existing and running, with a number and a date. I cannot commit to preventing exploitation of flaws that nobody has fixed yet, and anyone who does commit to that is selling something. Then I bring the remaining exposure back as an explicit acceptance decision rather than an implied one.
- Why insist the accepted residual is written down?Because unwritten acceptance evaporates at the next incident, and the same argument restarts with less credibility each time. A dated, named acceptance turns the question 'why didn't you stop this' into 'this is the risk we agreed to carry, and here is what has changed since'. It also forces the size of the residual to be estimated honestly at a moment when nobody is under pressure.
saying these in an interview costs you the question
- Accepts the zero-day label without checking fix availability
- Agrees that zero-days make prevention hopeless
- Promises a purchase that will stop unfixed flaws
- Wins the classification argument but funds nothing
- Leaves the leftover risk unwritten and unowned