skip to content

An industry site your engineers read weekly is poisoned by a publicity-seeking crew and you do not own it - what do you decide?

level: principalimportance: nice to knowfreq 20%

answer

  1. you cannot patch someone else's site
  2. each option has a different owner
  3. your peers share the readership
  4. publicity is the payoff you may be funding
  5. blocking is a holding action, not a fix

basics

~20 s

You cannot fix a site you do not own, so the choices are telling its operator, telling the sector, or removing your people's need to visit it. Each has a different owner and a different cost.

solid answer

~50 s

Frame it as three levers you actually hold and one you do not. You do not hold the site. You can tell its operator privately and give them a window; you can tell the sector, which protects peers who share the readership but hands a publicity-motivated crew exactly the attention they are optimising for and may name your organisation as a visitor; and you can remove the dependency by hosting or replacing the resource internally, which is the only durable answer and the one that costs a budget line and a named owner. Doing nothing is a legitimate fourth option but it must be signed by someone, not defaulted into. The organisational bite is that the second lever is usually not yours: publishing anything about another organisation's site is a call your legal and communications owners can refuse.

go deeper

for a junior

Understand that the poisoned page belongs to someone else, so nobody in your organisation can simply fix it - the options are all about telling people or changing what your own people depend on.

for a middle

Be able to lay out the options - report privately, tell the sector, remove the dependency, accept - and explain why blocking the site is only a holding action while one of the others is arranged.

for a senior

Show you can weigh peer exposure against a disclosure you may not be authorised to make, and that you would put a review date and an owner on whatever is chosen.

for a principal

Own the disclosure call with your legal and communications counterparts, fund and staff the dependency removal, and be able to say why the crew's motive moves the disclosure decision but not the funding one.

## Why this is a decision rather than a fix The asset is somebody else's. You cannot patch it, you cannot instrument it, and you have no contract with its operator. Every option you have is either about *other people's behaviour* or about *your own dependency*, and each one has a different owner inside your organisation. That is what makes it a leadership question rather than a technical one. ## The four options, with their owners and their costs **1. Tell the site's operator, privately.** Cheapest, most likely to actually end it, and the one you can start within the hour. Costs: you may be talking to a two-person association with no engineering capacity, in which case a private report buys nothing but delay. You also start a clock you do not control - if they do nothing for a month, you have to decide again, with the added awkwardness of having known. **2. Tell the sector.** This is the contested one. In favour: your peers share that readership, they are exposed by the same page, and they have no way of knowing. Against: it is rarely your decision alone. Publishing something that says another organisation's site is serving an attacker's file is a statement about a third party, and your communications and legal owners can and sometimes should refuse it. It may also implicitly disclose that your own people were visiting, and possibly that one of them ran something. And with a crew optimising for attention within that sector, sector-wide noise is part of what they came for. **3. Remove the dependency.** Mirror the specification updates internally, subscribe to a feed, negotiate a direct data exchange with the association, or replace the resource. This is the only option that removes your organisation from the readership the technique relies on, and it is the only one that still works next quarter when the same page is poisoned again by somebody else. It is also the one that costs real money and needs a named owner to keep it current - an out-of-date internal mirror is worse than useless because people quietly go back to the real site. **4. Accept.** Sometimes right - a low-value resource, a small readership, a crew already losing interest. What is not right is arriving here by default. Acceptance is a decision with an owner and a review date, or it is negligence wearing a decision's clothes. ## How the crew's motive changes the arithmetic This is where the answer stops being generic. If the crew is optimising for publicity within a sector rather than for money or for a specific estate, then: - **Their payoff is the sector noticing.** Quiet remediation denies them part of it. That is a genuine argument for the private route first - and it is also, uncomfortably, an argument that overlaps with the self-interested reason to stay quiet, which is precisely why the decision should not be made by the person who benefits from silence. - **They will probably not stop at one site.** A crew choosing targets for sector visibility has a list, and your peers' resources are on it. That pushes the balance towards telling the sector sooner than pure self-interest would. - **Attribution claims are worth less than they look.** A publicity-motivated crew *wants* to be named and may claim work that is not theirs. An executive asking who did this is asking a question whose answer will not change any of the four options above, and it is worth saying so plainly rather than spending a week on it. Compare that with a crew paying per click for search placement: they are indifferent to your sector, they stop when the return drops, and there is nobody to deny a payoff to. Same technique family, completely different decision. ## The trap to name out loud The reflex answer is `block the site`. It is available, it is fast, and it is usually wrong on its own: engineers need that resource to do their jobs, a block pushes them towards worse copies of the same content, and it will still be in place long after the page is clean because nobody owns removing it. Blocking is a holding action while option 3 is funded, not a substitute for funding it. ## What a strong answer sounds like Name the four options, attach an owner to each, say which you would start today and which needs a decision you cannot make alone, and be explicit that the crew's motive changes the disclosure call but not the dependency call. Then state the review date. An answer that picks one option and defends it as obviously correct has missed that the disagreement is the point.

  • How would your decision differ if the crew were paying per click for search placement instead?
    Substantially. There is no publicity payoff to deny, so the disclosure calculus loses its sharpest edge; the operator is indifferent to your sector and stops when returns fall; and there is no third-party site owner to negotiate with, because the route was bought rather than broken into. The dependency question - where your engineers get tools from - stays exactly the same.
  • An executive wants to know who is behind it before deciding anything. How do you handle that?
    Say plainly that the answer does not change any option on the table, and that a publicity-motivated crew has an incentive to be named and may claim work that is not theirs. Offer the decision-relevant version instead: what this class of crew targets next, and whether our peers are on that list. Then ask for the decision on disclosure and on funding the alternative.
  • Why is an internal mirror of the resource risky as an answer?
    Because it decays. A mirror nobody owns goes stale, people notice it is behind and quietly return to the original, and you have then paid for the control and lost the benefit. If you propose it, propose the owner, the refresh cadence and the budget line with it, or propose something else.

saying these in an interview costs you the question

  • Proposes blocking the site as the complete answer
  • Publishes about a third party without the owning function
  • Treats attribution as a prerequisite for deciding
  • Drifts into acceptance without naming an owner
  • Assumes the site's operator can and will fix it

context