Interview question
A senior analyst has written an assessment you think is wrong. It is going out to the CISO tomorrow. What do you do?
A question about analytic culture. The interviewer is checking whether you raise disagreement well — and whether you would let something wrong go out to avoid friction.
What a strong answer covers
- Does not stay silent — an assessment believed to be wrong must be raised.
- Goes to the author first and directly, rather than escalating over their head or raising it in front of an audience.
- Separates the disagreement from the person: challenges the reasoning or the evidence, not the analyst.
- Is specific about what is wrong — which judgement, which evidence, which alternative explanation was not considered.
- Comes with the alternative and its supporting reasoning rather than only an objection.
- Accepts that they may be persuaded; goes in genuinely open to being wrong.
- Knows when to escalate: if the author disagrees and the stakes are material, an alternative view should be recorded.
- Recognises that a healthy team treats dissent as a normal analytic input, not as a challenge to authority.
Expert answer
Silence is not an option — if it goes to the CISO and it is wrong, the cost lands on the organisation and eventually on the team's credibility.
I would go to the author directly and privately, and quickly, given the deadline. Not to their manager, and not in a group channel, because raising it in front of an audience turns a technical disagreement into a status contest and makes it much harder for anyone to change their mind.
I would be specific. Not "I think this is wrong" but "the judgement in the second key finding rests on the infrastructure overlap in section three, and I think that overlap is explained by shared hosting — here is the passive DNS showing eighty other unrelated domains on that address". Naming the specific evidence and the specific inference makes it a technical conversation rather than an opinion.
I would bring the alternative rather than only an objection. If I think the assessment is wrong, I should be able to say what I think is more likely and why, and what evidence would distinguish the two.
And I would genuinely go in open to being persuaded. The senior analyst may have context I do not — other reporting, a stakeholder constraint, or a reason the caveat is worded that way. Often the outcome is not that one of us was wrong but that the confidence level or the hedging needs to change, which is a smaller and easier fix than either of us reversing.
If they disagree and I still think it is materially wrong, I would say so plainly and ask that the alternative view be recorded — a dissent footnote or a line noting an alternative hypothesis is normal practice in intelligence writing and costs almost nothing. If it were serious enough, I would tell them I was going to raise it with the team lead, and then do that openly rather than behind them.
A team where this is uncomfortable has a problem. Dissent is an analytic input, and the whole point of techniques like devil's advocacy is that somebody is supposed to argue the other side.
Mistakes that cost candidates points
- Saying nothing to avoid conflict.
- Escalating to a manager before speaking to the author.
- Raising it publicly in a way that forces the author to defend rather than reconsider.
- Objecting without offering an alternative or the evidence for it.
- Framing it as being right rather than as getting the assessment right.
- No path for recording a dissenting view if the disagreement stands.
You have read the answer, which is the easy part. Answer it in your own words and get graded against this same rubric, with the follow-up probe an interviewer would ask next.
Go deeper
Related questions
- What is cyber threat intelligence, and how is it different from a threat feed?
- Why do you want to work in threat intelligence rather than another security discipline?
- Tell me about a time your analysis turned out to be wrong. What happened, and what did you change?
- You have been producing reports for six months and you suspect nobody is reading them. How do you find out, and what do you change?
- It is 2am during a live incident and the incident commander asks you "is this ransomware?" You genuinely do not know yet. What do you say?