Open cardosec

Case 0C1627 · GRC · L2 Practitioner

The Exception Nobody Renewed

Practise as: Incident drill

Live alertAn external attack surface scan finds an internet-facing Windows Server 2012 R2 host running the billing portal; its risk exception expired 14 months ago.

  1. 01 What happened?
  2. 02 What is the impact?
  3. 03 What do you do?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Assess exposure first: is it exploitable now? Check open ports, known exploited vulns (CISA KEV), and logs for compromise.
  2. Short-term: isolate behind VPN/WAF, add EDR and monitoring. 2012 R2 ESU patches end 13 Oct 2026, so plan to migrate or retire.
  3. Escalate to the business owner: renew the exception with a fresh risk rating and deadline, or fund the migration.
  4. Fix the process: exceptions register with auto-reminders and expiry that escalates rather than silently lapsing.
  5. Report it as a governance failure, not just a vuln: an expired exception means risk ran unaccepted for 14 months.

If the interviewer pushes back

  • The owner says the vendor app only runs on 2012 R2 and migration takes a year. What compensating controls make that tolerable?

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.