712-50 Question 110
Single answerBridging Stakeholders and StockholdersA newly appointed CISO is preparing for the board's quarterly review after a ransomware incident that disrupted one business unit for 18 hours but did not lead to confirmed data exfiltration. Several operational stakeholders want a highly technical briefing on malware behavior and endpoint tooling gaps. Meanwhile, major investors have begun asking whether the company can still meet revenue guidance and whether cyber risk is being governed effectively. The CEO asks the CISO to present a single update that addresses both internal stakeholders and stockholders. Which approach is MOST appropriate for the CISO to take?
- A
Deliver a deeply technical presentation to the board, focusing on indicators of compromise, exploit chains, and endpoint forensic findings so directors can fully understand the incident details before discussing financial implications.
- B
Frame the update around business impact, governance actions, risk treatment decisions, regulatory and disclosure considerations, recovery status, and measurable plans to reduce recurrence, while providing technical details separately to operational stakeholders.
- C
Avoid discussing potential financial or control weaknesses until the investigation is fully complete, because preliminary information could create unnecessary concern among directors and investors.
- D
Center the presentation on the security team's rapid tactical response and tool performance, emphasizing operational successes rather than broader business risk, since investor confidence is best preserved by limiting strategic discussion.
Show answer and explanation
Correct answer: B
Explanation
In CCISO practice, bridging stakeholders and stockholders requires translating cybersecurity from a technical function into an enterprise governance and value-protection issue. The board and investors need information that supports oversight and confidence: business interruption, likely financial implications, effect on strategic objectives, legal or regulatory exposure, management's response, residual risk, and remediation priorities. Operational stakeholders, by contrast, need technical details to contain and recover from the event. A mature CISO uses audience-appropriate communication rather than a one-size-fits-all briefing. This aligns with broadly accepted governance principles reflected in board-focused guidance from sources such as NIST Cybersecurity Framework governance concepts, NIST incident handling guidance, and enterprise governance practices that emphasize reporting cyber risk in business terms, decision points, and measurable outcomes.
- A. Incorrect.
This is not the best approach. Board members and stockholders generally need concise, decision-oriented information tied to enterprise risk, resilience, legal exposure, financial impact, and management actions rather than low-level technical artifacts. Technical detail is important, but it should usually be tailored for operational stakeholders such as IT, SOC, incident response, and engineering teams. A common mistake is assuming that more technical depth creates better governance; in practice, it can obscure the business significance and hinder effective board oversight.
- B. Correct.
This is the best answer. A CCISO must translate cyber events into business language that bridges stakeholder needs and stockholder interests. For directors and investors, the key issues are operational disruption, financial impact, governance effectiveness, recovery progress, disclosure obligations, and whether management has a credible remediation plan. Providing a business-focused summary with clear metrics, decisions needed, and accountability demonstrates mature security leadership, while separate technical briefings can satisfy operational stakeholders who need implementation detail.
- C. Incorrect.
This is incorrect because boards have oversight responsibilities during active incidents and need timely, decision-useful updates even when all facts are not yet confirmed. While the CISO should avoid speculation and clearly label preliminary information, withholding discussion of business impact or control concerns can undermine governance, delay risk treatment decisions, and create larger problems for disclosure, audit, and stakeholder trust. The misconception here is that uncertainty justifies silence; effective executives communicate what is known, unknown, and being done.
- D. Incorrect.
This is not the most appropriate approach. Highlighting tactical response performance may be part of the update, but making it the centerpiece misses the broader purpose of bridging stakeholders and stockholders. Investors and directors are less concerned with tool-level performance than with resilience, impact on strategic objectives, management accountability, and future risk reduction. This option reflects a common operational bias: equating incident response activity with adequate executive communication.