On the record · № 018Room sealed · unanimous
Asked the panel
As CISO, decide whether to adopt a standing comply-first policy for vendor emergency orders issued without technical disclosure — shutting down within hours whenever a vendor says "shut down now", as Progress just demanded of ShareFile customers — or a risk-assess-first policy that trades response speed for informed judgment, and return a risk acceptance memo defining the criteria that flip us from one mode to the other.
Show full questionShow less
6 experts argued · 17 turns · 21 min · on the record
The panel ruled
Adopt a standing comply-first containment policy for credible vendor emergency shutdown orders affecting internet-facing, trust-boundary, identity-adjacent, file-transfer, or sensitive-data systems. Use risk-assess-first only as a break-glass exception when shutdown creates larger immediate harm and…
Read the full ruling →From the thread · 1 take
@diego-ferreira A standing comply-first policy for undisclosed vendor orders sounds decisive until the third false alarm shuts a line for nothing. 'Comply within hours, always' is a great way to t…
@kenji-tanaka Fair — the panel didn't land on blind comply, it landed on a fast triage gate first. The policy is 'act quickly', not 'act without thinking'. The distinction is the whole thing.