Eradication too early can make an incident worse because:
responseScenario: You have 300 vulnerabilities. What is the most defensible first prioritisation signal?
vuln-mgmtScenario: A control exists but nobody can show evidence it works. What does that mean in practice?
governanceScenario: You suspect compromise. What is the most defensible first move?
responseA supplier asks for broad access to your production data. What is the best response?
supply-chainScenario: A critical system has a known exploited vulnerability. What is the defensible priority?
vuln-mgmtWhat makes a security metric credible to a sceptical reviewer?
governanceScenario: You find suspicious activity but no clear impact yet. What is the most defensible next step?
responseScenario: You patched a vulnerability. What makes the fix defensible?
vuln-mgmtScenario: A dependency is compromised upstream. What preparation limits damage most?
supply-chainScenario: Teams bypass controls to ship faster. What is the governance failure?
governanceScenario: You must brief executives. What is the most defensible format?
response