Your question is Handle Ambiguity in Security Decisions. Take a moment with it on the right.
Talk me through your thinking if you like. When you're confident, submit your answer and I'll grade it like a real screen (7/10 or better passes).
You're leading a security engineering initiative where the problem is real, but the path forward is unclear. Different stakeholders want different outcomes: some want the fastest risk reduction, others want minimal disruption to delivery, and the available data is incomplete.
How would you handle ambiguity when there is no obvious right answer?