Interview question
The incident is contained. You have 10 minutes with the board next week. The technical picture is still incomplete and attribution is unresolved. What do you present?
A communication scenario at the strategic altitude, with the added constraint that you have to be useful while significant things are still unknown.
What a strong answer covers
- Leads with the business impact and the decision the board needs to make, not the technical narrative.
- States plainly what is known, what is not known, and when the gaps will close.
- Does not fill the attribution gap with speculation.
- Translates technical findings into business terms without dumbing them down to the point of inaccuracy.
- Addresses the questions a board actually asks: are we still exposed, could it happen again, what did it cost, are we obliged to disclose, how do we compare to peers.
- Makes specific recommendations with owners and costs, within the board's authority to decide.
- Distinguishes what has been fixed from what is still open.
- Avoids jargon, actor names and ATT&CK IDs entirely, or translates them immediately.
- Is honest about what went wrong without either minimising or catastrophising.
Expert answer
Ten minutes with a board means roughly three things, said clearly, with the decision at the front.
I would open with impact and status: what happened in one sentence, what it affected, that it is contained, and what the residual risk is right now. A board's first question is always "are we still exposed", and answering it before they ask buys the rest of the ten minutes.
Then the decision I need from them. If the answer is more investment in a specific control, or accepting a residual risk, or approving a disclosure position, that goes second, not last. Boards are a decision-making body and a briefing without a decision in it is a status update they did not need to attend.
Then the honest uncertainty. I would say plainly that attribution is unresolved and that I am not going to speculate, and — this is the part that matters — explain why it does not change the decision in front of them. Whether this was a criminal group or something else, the control gaps are the same and the remediation is the same. If it did change the decision, for example because of sanctions exposure on a payment, I would say that too and set out what we are doing to resolve it and by when.
For the technical picture I would give the shape rather than the detail: how they got in, roughly how long they were present, what they reached and what they did not. No actor names, no ATT&CK IDs, no tool names unless a board member asks. Not because boards cannot follow it, but because ten minutes spent on the technical narrative is ten minutes not spent on the decision.
I would make sure I cover the questions they will ask anyway, because being ahead of them signals control: could this happen again and what has changed, what did it cost including response and downtime, do we have a disclosure or notification obligation and what is legal's view, and how does this compare with what is happening to peers in our sector — that last one is genuinely useful context and is where intelligence adds something the incident report cannot.
On what went wrong, I would be straight about it. Boards handle bad news far better than they handle discovering later that they were managed. Neither minimising nor catastrophising — the failure, what it cost, what is being done.
I would close with what is still open, who owns each item, and when I will come back. And I would leave a one-page written version behind, because half of them will want to reread it and none of them will remember the verbal detail.
Mistakes that cost candidates points
- Leading with the technical narrative or a timeline of the investigation.
- Speculating on attribution to fill the gap.
- Using jargon, actor names or framework references without translation.
- Presenting findings with no decision or recommendation attached.
- Minimising what went wrong, or catastrophising it.
- Not addressing disclosure or regulatory obligations.
- No written leave-behind.
You have read the answer, which is the easy part. Answer it in your own words and get graded against this same rubric, with the follow-up probe an interviewer would ask next.
Go deeper
Related questions
- A board member asks you what your team does and why it is worth the budget. You have two minutes. What do you say?
- You have been producing reports for six months and you suspect nobody is reading them. How do you find out, and what do you change?
- The SOC escalates: a finance team member's account authenticated successfully from an IP in a country the company has no presence in, at 03:00 local time. MFA was satisfied. No alerts have fired since. What do you do, and what do you tell the SOC lead?
- A vendor publishes a report claiming an intrusion set is actively targeting your sector, with 200 indicators appended. Your CISO forwards it and asks "are we affected?" Walk me through your response.
- You receive TLP:RED intelligence in a trust group indicating a specific vulnerability is being exploited against your sector. Your organisation is exposed. What do you do?