skip to content

An executive says insider risk is covered because 'we trust our staff'. How do you answer?

level: principalimportance: nice to knowfreq 34%

answer

  1. do not dispute the trust claim
  2. trust answers one problem of three
  3. carelessness involves no dishonesty
  4. bring a priced, owner-attached decision
  5. refused means written acceptance, not silence

basics

~20 s

Answer without arguing about honesty. Trust addresses at most one of three insider problems and none of the loss from carelessness or a taken session, so move the decision from who holds a role to what that role may reach, and price the smallest scope cut you can defend.

solid answer

~50 s

Do not contest the trust claim; it is probably true and disputing it makes the conversation about people. Reframe instead: insider risk is three problems sharing a name, and trust speaks only to the deliberate one. Two of the three — the analyst who exports a customer table to finish a report, and the engineer whose session someone else is holding — involve no dishonesty at all, so trust cannot bound them. Then make it a decision the executive can actually take: name the two or three capabilities whose loss you would not accept, say what bounding each costs in daily friction to the people who keep production running, and propose the smallest change that removes the worst case. If it is still refused, get the accepted risk written down with the executive's name and a trigger to revisit, and move on rather than relitigating it monthly.

go deeper

for a junior

You will not run this conversation yet, but know the one line that carries it: two of the three insider problems involve nobody being dishonest, so trust cannot be the bound on them.

for a middle

Be able to explain to a manager what screening does and does not buy, without either dismissing it or overstating it, and to point at the careless and hijacked cases as the ones trust never reaches.

for a senior

Bring a short, priced list of capabilities rather than a principle. Know the friction your proposal imposes on the people who keep production running and say it out loud before they do.

for a principal

Own the outcome either way: the smallest scope change that removes the worst case, or a written acceptance with a named owner and a revisit trigger. Be the person who sometimes recommends accepting a risk, so your refusals are believed.

## Why this is a judgment question, not a technical one The technical content here is settled: scope is the only knob. What makes it a lead's question is that the person who can approve a scope change also owns the budget, the delivery schedule and the goodwill of the team whose daily work gets slower. You are not looking for the right control; you are looking for the largest reduction in worst case that this person will actually agree to. ## Do not fight the trust claim The instinct is to argue that staff cannot be trusted. It is a losing move for three reasons: it is usually false, it insults the team, and it concedes the executive's framing that the subject is honesty. The move that works is to accept the claim and show that it answers a smaller question than they think. > "I agree, and I am not proposing anything that assumes otherwise. Two of the three ways this hurts us do not involve anyone being dishonest." From there the argument writes itself: the careless export of a customer table into a personal spreadsheet service to hit a deadline; the platform engineer whose session is held by somebody else. Trust is true and irrelevant in both. ## Say what screening actually buys If background checks are cited, be precise rather than dismissive. They are a point-in-time filter aimed at the deliberate subtype, and people's circumstances change after they are hired. That makes screening a reasonable hiring practice and a poor bound on loss. Being fair about what it does buy is what keeps you credible for the rest of the conversation. ## Convert the argument into a decision An executive can refuse an argument indefinitely; they have to do something with a decision. Bring three things. 1. **A short list of capabilities whose loss you would not accept.** Not every permission — two or three. Typically: bulk read of the customer store, and the ability of a role to grant roles. Long lists get deferred wholesale. 2. **The price in friction, stated honestly.** Bounding a platform role means someone waits for an approval during an outage, or a report takes an extra day. If you do not name that cost, the people who feel it will name it for you, later, and your proposal will die on the floor. 3. **A named owner per decision.** "Who decides whether the analytics role can export whole tables" is answerable; "should we do least privilege" is not. ## Concede properly Sometimes the honest answer is that bounding a capability costs more than the loss it prevents. Say so yourself, before someone else does — a security lead who has never recommended accepting a risk is not believed on the ones they refuse to accept. Where a scope cut is genuinely uneconomic, the correct outcome is documented risk acceptance: what is unbounded, whose signature is on it, and the trigger that reopens it — a new data store entering that role's reach, an acquisition, a customer contract that demands otherwise. Then stop raising it. Relitigating a settled acceptance every quarter costs you the credibility you will need when the trigger actually fires. ## What a strong answer sounds like in the room A lead who handles this well does four things in about two minutes: agrees about the staff, splits the category into three, points at the two subtypes trust does not reach, and puts one small, priced, owner-attached change on the table. A weak answer either lectures about human nature or produces a programme-sized proposal that nobody can approve. ## The failure modes to avoid - **Moralising.** Any sentence that implies the team might be dishonest loses the room and the argument. - **Overreach.** Proposing to remove all standing scope everywhere guarantees refusal and burns the one meeting you had. - **Silence after refusal.** If you walk away without a written acceptance, the risk is still there and now nobody owns it — including, when it lands, you.

  • The executive refuses anyway. What do you do?
    Turn it into documented risk acceptance: state precisely what is unbounded, whose decision it was, and the trigger that reopens it — a new data store entering that role's reach, an acquisition, a customer contract demanding otherwise. Then stop raising it. An unowned risk you keep mentioning is worse than an owned one you agreed to accept.
  • Which of the three subtypes usually moves an executive fastest?
    The compromised one, because it costs them nothing morally — it says nothing about their staff, and it is the version they have already read about. Lead with it when the room is defensive, then bring in the careless case, which is the one that actually happens most and is hardest to argue is anybody's fault.
  • How do you keep the platform team on side while proposing this?
    Bring them in before the executive conversation and let them choose where the bound goes. They know which capabilities they genuinely need at three in the morning and which they hold only because the role came bundled. A scope proposal the people affected helped shape survives contact with the first outage; one imposed on them does not.

saying these in an interview costs you the question

  • Argues that staff cannot be trusted
  • Offers background checks as the bound on insider loss
  • Brings a programme-sized proposal with no cost attached
  • Treats a refusal as closed without written risk acceptance
  • Never recommends accepting a risk, so is not believed when refusing one

context