Assess whether backups are clean enough to restore from insider exfil
August 31, 2026
SITUATION Insider exfil of a customer export arrived with packet captures showing SMB to a previously quiet subnet for incident commander. That is a Cybersecurity Incident Response decision on backups are clean enough in a hospital after a weekend EHR outage.
DECISION Incident commander in a hospital after a weekend EHR outage must choose Contain now / Monitor / Escalate / Hold using insider exfil of a customer export after packet captures showing SMB to a previously quiet subnet.
HYPOTHESES TO TEST 1. Incident commander can defend Contain now from insider exfil of a customer export after packet captures showing SMB to a previously quiet subnet in a Cybersecurity challenge. 2. Incident commander cannot defend Contain now from insider exfil of a customer export; Monitor is what the extract actually supports after packet captures showing SMB to a previously quiet subnet. 3. Packet captures showing SMB to a previously quiet subnet never reached the population in insider exfil of a customer export — reopen intake, do not close backups are clean enough. 4. Two facts in insider exfil of a customer export after packet captures showing SMB to a previously quiet subnet conflict for incident commander; hold this Incident Response file.
ANALYSIS REQUIRED 1. Separate a scoped exception from an unbounded exposure a hospital after a weekend EHR outage has not measured. 2. Map identities, standing privileges, and last-use timestamps in insider exfil of a customer export to the blast radius of packet captures showing SMB to a previously quiet subnet. 3. Name the compensating control that would let incident commander release a reversible hold. 4. For this Cybersecurity Incident Response file, read insider exfil of a customer export against packet captures showing SMB to a previously quiet subnet and write the one fact that would move backups are clean enough for incident commander.
RECOMMENDATION Choose Contain now / Monitor / Escalate / Hold on this Cybersecurity / Incident Response packet (insider exfil of a customer export after packet captures showing SMB to a previously quiet subnet). If insider exfil of a customer export cannot force a Cybersecurity label under Incident Response, stop. Do not invent missing evidence a hospital after a weekend EHR outage does not have.
COMMAND RETURNS - Bottom-line Cybersecurity option on backups are clean enough, then the evidence in insider exfil of a customer export, then the action for incident commander - Hypothesis scorecard against insider exfil of a customer export: supported / rejected / untestable - Owner and next date for incident commander in a hospital after a weekend EHR outage - What changes backups are clean enough if packet captures showing SMB to a previously quiet subnet is later withdrawn
Explore more
More Cybersecurity prompts
- Identity-and-access reviewer must resolve whether the incident is contained
- Assess whether attribution is good enough to name an actor from EDR
- Threat-intel lead must resolve whether attribution is good enough to name
- Assess whether a vendor finding is theoretical or exploitable here after CISA
- Whether attribution is good enough to name an actor from AI-model API key
Explore related decision areas
See governed multi-model AI on your own prompt
Compare GPT-5, Claude, and Gemini side by side, with human review and a decision record built in.

