Practise as: Incident drill · Interview
Live alertMarch 2022, you are Okta's security lead. Lapsus$ posts screenshots of your internal admin tools, taken in January from a laptop of a support engineer at your outsourced vendor, Sitel.
Interview questionHow do you respond, both technically and in communications?
- 01 What happened?
- 02 What is the impact?
- 03 What do you do?
What a strong answer covers
Try it out loud first. Then check yourself:
- Establish facts: Sitel engineer's machine accessed via RDP for about 5 days in January; what could that role do?
- Scope by role permissions and audit logs: support could reset passwords/MFA but not download customer databases
- Notify affected customers fast; Okta was criticised for a 2-month delay and initially cited up to 366 tenants
- Final finding: 2 customer tenants actually accessed; forensics depended on getting Sitel's report quickly
- Lessons: third-party access in scope for IR, contractual forensic rights, least-privilege support tooling
If the interviewer pushes back
- Lapsus$ used MFA fatigue, SIM swaps and bribing insiders. Which controls address each?
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.