Winging It · Implausible Deniability

Every company keeps a quiet list of the people who are allowed to ignore the security rules. It's called the exceptions register, it lives in SharePoint or a spreadsheet that was created the week before the last ISO 27001 audit, and it is one of the most sensitive documents available, though nobody treats it that way, because it's boring.

Nobody applies for a place on the list. Instead an assistant sends a polite email explaining that her exec travels constantly and finds the MFA codes "a bit fiddly." The security team replies with a form, because that is what they always do. The form has been refined over years to include business justification, residual risk and compensating controls. An expiry field carefully built as a dropdown so the word "ongoing" cannot be typed in.

The completed form returns the same afternoon, faster than any other document in office history, and the expiry field reads "ongoing." Someone, somewhere in the approval chain, has beaten the dropdown. Nobody knows how.

This is followed by a meeting, where a person from security presents some perfectly reasonable slides explaining why the most privileged account in the company should keep its protections, to a room that decided otherwise before the email was sent. Delivering the slides is ceremony and everyone in the room knows it, including the presenter, who made them anyway.

The exemption is granted with conditions: enhanced monitoring, which looks very similar to ordinary monitoring, and a ninety-day check-in that is booked into a calendar that will, ninety days later, clash with something more important and never get rebooked.

The conditions are gentle by design: a condition the executive might refuse gets refused, a refused condition gets escalated, and an escalated exemption comes back approved a level up with no conditions attached at all. The people drafting them know this, so they draft the version that can be signed.

Follow the chain and it's hard to find the step where anyone did anything wrong. Security exists to protect the most valuable accounts. The most valuable accounts belong to the most senior people. The most senior people are the ones who can excuse themselves. So protection drains away in exact proportion to how much it was needed, and everyone signs the paperwork with a straight face, every year.

The executive is rarely alone in the register. A few entries down is the sales director, whose laptop cannot run the security agent because it slows down demos, and who takes that laptop to conferences and connects it to whatever network is nearest. Below him, the development team, who hold permanent admin rights to everything after requesting access twice a week was ruled to be harming velocity. And somewhere near the bottom, on no risk assessment anywhere in the building, the chairman's assistant, who over fifteen years has been granted access to every system that ever mattered and removed from none of them, and who now holds more standing privilege than the head of engineering.

Anyone who attacks companies for a living keeps a short mental list of the people worth targeting. It is always the same list: executives, assistants, administrators, finance staff who can move money. The sales director qualifies on access alone. Building it normally takes weeks of research. The exceptions register already contains those names, ranked, with reference numbers, and the numbers have been signed, often by the person the exemption is meant to protect. The risk was requested, assessed and accepted by the same individual, and this arrangement passed audit.

Meanwhile the new intern has multi-factor authentication, a locked-down laptop, mandatory training about tailgating, and a phishing simulation every fortnight. The intern can only open the shared drive containing the lunch menus. The man whose inbox holds the merger correspondence uses a password from 2019 and has a signed form declaring it acceptable.

He should be furious, though at the wrong target. What the register produces is a change of category, because an executive who ignores a control is a problem, and problems appear in audit reports. An executive with an approved exception is governance, and governance receives a green tick.

The auditors agree every year that it is fine, because by the standard they apply it is. Every entry has a signature and an expiry date, in the sense that "ongoing" is an expiry date.

When the breach finally arrives, it arrives through the list. Of course it does; the list is where the access is. And the post-incident review will note, correctly, that the account in question held an approved exception, that the risk had been formally accepted, and that the paperwork was in order at the time of the incident.

Which means that by every standard the organisation measures itself against, nothing went wrong.

— Chris