Assess whether to pay, restore, or rebuild from known-good (27207f)
August 31, 2026
SITUATION To pay, restore, or rebuild sits with detection-engineering manager because a help-desk reset that bypassed step-up authentication hit a bank's SWIFT-adjacent environment. Evidence is phishing kit targeting finance wire clerks; write the Cybersecurity Third-Party and AI Security option that extract can carry.
DECISION Detection-engineering manager in a bank's SWIFT-adjacent environment must choose To pay, restore, / Rebuild from known-good using phishing kit targeting finance wire clerks after a help-desk reset that bypassed step-up authentication.
HYPOTHESES TO TEST 1. Authorize To pay, restore, now; phishing kit targeting finance wire clerks already has the discriminator after a help-desk reset that bypassed step-up authentication. 2. Keep Rebuild from known-good in force until phishing kit targeting finance wire clerks is completed after a help-desk reset that bypassed step-up authentication for detection-engineering manager. 3. Treat phishing kit targeting finance wire clerks as To pay, restore, because both readings appear after a help-desk reset that bypassed step-up authentication. 4. Refuse a Cybersecurity close: detection-engineering manager does not have the page to pay, restore, or rebuild turns on in phishing kit targeting finance wire clerks.
ANALYSIS REQUIRED 1. Test whether access is still live, already rotated, or only written as closed. 2. Check SIEM or identity logs in phishing kit targeting finance wire clerks for reuse after a help-desk reset that bypassed step-up authentication. 3. Separate a scoped exception from an unbounded exposure a bank's SWIFT-adjacent environment has not measured. 4. For this Cybersecurity Third-Party and AI Security file, read phishing kit targeting finance wire clerks against a help-desk reset that bypassed step-up authentication and write the one fact that would move to pay, restore, or rebuild for detection-engineering manager.
RECOMMENDATION Choose To pay, restore, / Rebuild from known-good on this Cybersecurity / Third-Party and AI Security packet (phishing kit targeting finance wire clerks after a help-desk reset that bypassed step-up authentication). If phishing kit targeting finance wire clerks cannot force a Cybersecurity label under Third-Party and AI Security, stop. Do not invent pages a bank's SWIFT-adjacent environment does not have.
COMMAND RETURNS - Bottom-line Cybersecurity option on to pay, restore, or rebuild, then the evidence in phishing kit targeting finance wire clerks, then the action for detection-engineering manager - Hypothesis scorecard against phishing kit targeting finance wire clerks: supported / rejected / untestable - What changes to pay, restore, or rebuild if a help-desk reset that bypassed step-up authentication is later withdrawn - Named option among To pay, restore,, Rebuild from known-good and the fact that kills the others
Explore more
More Cybersecurity prompts
- Assess whether a vendor finding is theoretical or exploitable here (9e93e9)
- Assess whether privileged access should be rotated enterprise-wide (8ef32a)
- Assess whether to isolate a plant or keep production running (bec68d)
- Assess whether cyber insurance notice is due today (93367d)
- Assess whether an AI system is in the blast radius (3604aa)
Explore related decision areas
- Assess whether a SAR narrative is supportable today (111c92)Fraud Detection
- Model-deprecation manager must resolve whether a score that never failsAI Governance Layer
- Assess whether the committee can overrule a business unit after a customerAI Governance Layer
See governed multi-model AI on your own prompt
Compare GPT-5, Claude, and Gemini side by side, with human review and a decision record built in.

