Interview question
An executive wants a named attacker for a board slide tomorrow. Your evidence supports clustering the activity but not naming a group. What do you do?
A behavioural question testing analytic integrity under stakeholder pressure — and whether you can push back without being obstructive.
What a strong answer covers
- Does not provide a name the evidence does not support.
- Separates the three distinct claims: clustering activity, mapping to a public group name, and asserting sponsorship.
- Establishes what decision the name is actually for, because often the name is not what the executive needs.
- Offers what the evidence does support, framed usefully for a board audience.
- Explains the downside of naming wrongly in terms the executive cares about — public correction, legal exposure, misdirected response.
- Stays collaborative rather than obstructive; finds a way to give them something usable by the deadline.
- Documents the judgement and the pressure, and states what would let a name be added later.
Expert answer
I would not give them a name the evidence does not support, but refusing flatly is the wrong move too. The productive step is to find out what the name is for.
Usually when an executive asks for a name they are trying to answer something else: are we being targeted specifically or were we unlucky, is this likely to happen again, and does this change what we should be spending on. A group name is a proxy for those questions, and often a bad one. If I can answer the real questions, the name usually stops mattering.
I would also separate the three claims that get collapsed into "attribution". Clustering — these intrusions share enough tradecraft and infrastructure to be the same operator — is something I can often support well. Mapping that cluster to a public vendor name is much shakier, because different vendors cluster on different criteria and two names rarely cover exactly the same activity. Asserting sponsorship usually depends on collection I do not have. I would tell the executive which of those three I can stand behind.
So what I would offer for the slide: that the activity is consistent, tracked internally under our own designation, that its targeting profile and tradecraft are consistent with a particular motivation, and what that implies for what we do next. If there is a public group overlap, I would present it as an observation with the specific evidence and a moderate confidence level, explicitly not as an identification.
On the downside, I would put it in their terms rather than mine: if we name a group on a board slide and it is wrong, we will have to correct it in front of the same audience, it can create legal and insurance complications, and it can point the response in the wrong direction. The cost of being vague is low; the cost of being confidently wrong is not.
I would document the assessment and the constraint, and say plainly what additional evidence would let us attach a name later — so it reads as a live analytic question rather than an analyst being difficult.
Mistakes that cost candidates points
- Giving the name to keep the stakeholder happy.
- Refusing without offering anything usable by the deadline.
- Not distinguishing clustering from naming from sponsorship.
- Explaining the problem in analyst terms rather than in terms of the executive's risk.
- Not documenting the judgement or what would change it.
You have read the answer, which is the easy part. Answer it in your own words and get graded against this same rubric, with the follow-up probe an interviewer would ask next.
Go deeper
Related questions
- Ransomware has been deployed across part of your estate. A known family was used, a ransom note was left, but no data exfiltration has been observed despite C2 being active for six days beforehand. What are your hypotheses, and how would you test them?
- Which classes of attribution evidence are hardest for an adversary to fake, and which are easiest? How does that change how you weight them?
- Tell me about a time your analysis turned out to be wrong. What happened, and what did you change?
- A senior analyst has written an assessment you think is wrong. It is going out to the CISO tomorrow. What do you do?
- You have been producing reports for six months and you suspect nobody is reading them. How do you find out, and what do you change?