When it’s on fire, the order of your moves matters more than any single move — contain first, then learn, then speak.
“Walk me through your next thirty minutes” isn’t asking for the root cause. It’s testing whether you can stay calm and sequence. The reliable loop: stop the bleed, split facts from unknowns, set a communication , and make the reversible calls now while parking the irreversible ones until the facts are in.
Two things move underneath every incident: the damage that accrues while the problem is uncontained, and the trust of everyone watching how you handle it. Speaking before you know, or promising an update and going quiet, spikes one and drains the other.
Sequence your first 30 minutes
Drag to reorder, or use the arrows. Each action takes a few minutes — you can only do one at a time.
A calm 30-minute schedule tends to look like this:
min 0 ── contain: roll back the bad deploy (stop the bleed)
min 5 ── learn: assign fact-finding (facts vs unknowns)
min 9 ── comms: internal note + "update in 15"(set the cadence)
min 12 ── align: brief the exec on facts so far
min 15 ── comms: public statement, once facts are in
── parked: refunds / data purge (irreversible -> later)
External statements wait for facts; internal acknowledgement does not. That single distinction protects trust more than eloquence ever will.
| Fits | The trade-off |
|---|---|
| Outages, security incidents, a bad deploy, a data mix-up, a PR flare-up — any “it just broke, what now” prompt. | This is a bias-to-action loop for the first hour, not a root-cause investigation. The post-mortem comes later — say so, don’t skip it. |
“A deploy at 2:00 starts double-charging customers on payment retries. Walk me through your next thirty minutes.” A strong answer sequences it: 2:00 — roll the deploy back immediately; the bleeding stops even before I know the exact cause. 2:05 — I put someone on fact-finding: how many customers, over what window, which charges. 2:09 — internal note to support and leadership: “retries double-charged between 1:50 and 2:04, rolled back, refund plan by 2:20, next update in 15.” 2:15 — once we’ve scoped it, a public status update and proactive refunds to the affected list. What I don’t do at 2:01 is email every customer an apology or purge the charge records — those wait for the facts.
A deploy is actively corrupting orders. What’s your first move?
You promised an update in 15 minutes. It’s minute 15 and you still don’t know the root cause. What do you do?
Prep Room · the interviewer is listening for order and composure, not a miracle fix.