Interview question
On the same morning: a new critical vulnerability is being exploited in the wild, the CISO wants a board paper by Friday, and IR needs support on a live case. You cannot do all three. How do you decide?
A prioritisation question. The interviewer wants a decision rule, not a heroic claim that you would somehow do everything.
What a strong answer covers
- Establishes a decision rule rather than reacting to whoever asked loudest.
- Prioritises by decision impact and time sensitivity — what happens if each is delayed.
- Recognises the live incident usually wins on immediacy, but checks rather than assumes.
- Assesses the vulnerability against actual organisational exposure before treating it as urgent.
- Separates the fast triage of each item from the full work — an hour of triage changes the ranking.
- Communicates the trade-off explicitly to all three stakeholders rather than silently dropping one.
- Renegotiates deadlines and scope rather than delivering three things badly.
- Escalates for a decision if the conflict is genuinely between competing priorities of the same weight.
- Considers what can be delegated or partially delivered.
Expert answer
I would not answer this by claiming I could do all three. The point of the question is the decision rule.
My rule is decision impact against time sensitivity: for each item, what decision does it support, when is the decision point, and what happens if it slips.
But before ranking I would spend maybe an hour triaging all three, because that hour usually changes the ranking. On the vulnerability: is it actually exploitable in our environment, is it internet-facing, do we have compensating controls? A critical CVSS score in software we do not run is not urgent, and this is exactly where intelligence adds value — filtering the noise rather than amplifying it. On the incident: what does IR actually need, and is it something only I can provide? Sometimes it is thirty minutes of context rather than a day of support. On the board paper: when is the meeting, and what decision does the paper serve?
After that triage the ranking is usually obvious. Live incident support tends to win because the cost of delay is immediate and irreversible, but I would check rather than assume — if IR is fine for a few hours and the vulnerability is being actively exploited against our sector on an appliance we have exposed, that flips.
The board paper is usually the one that moves, and there is often room to renegotiate it: a shorter paper, a verbal briefing, or Monday instead of Friday. Deadlines set on the assumption of a quiet week are frequently movable when you ask.
The part that matters most is the communication. I would tell all three stakeholders what I am doing and why, rather than silently dropping one and hoping. "I am on the incident today, I have triaged the vulnerability and we are not exposed on the affected component so it can wait until tomorrow, and I need either an extra day or a shorter scope on the board paper" is a professional answer. Three people delivered to badly is worse than two delivered well and one honestly renegotiated.
If two genuinely tie in weight, that is a decision for the person who owns the priorities, and I would escalate it as a decision rather than absorbing it and burning out.
Mistakes that cost candidates points
- Claiming to do all three by working late.
- Prioritising by who asked most forcefully or most senior.
- Not triaging before ranking, so the vulnerability is treated as urgent without checking exposure.
- Silently dropping one stakeholder without telling them.
- Not renegotiating scope or deadline as an option.
You have read the answer, which is the easy part. Answer it in your own words and get graded against this same rubric, with the follow-up probe an interviewer would ask next.
Go deeper
Related questions
- Explain the difference between tactical, operational and strategic threat intelligence, with an example of each.
- You are the first intelligence hire at a company with a working SOC but no CTI function. What do you do in your first 90 days?
- Your CISO says "I want to know about ransomware." Turn that into something you can actually collect against.
- What is F3EAD, and why do some CTI teams prefer it to the traditional intelligence cycle?
- Tell me about a time your analysis turned out to be wrong. What happened, and what did you change?