712-50 exam dumps

712-50 practice question 111 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 111

Single answerBridging Stakeholders and Stockholders

A newly appointed CISO at a publicly traded manufacturing company is preparing for the annual board strategy meeting. The company recently experienced a ransomware incident that caused two days of production disruption but no confirmed data exfiltration. Several business unit leaders want the CISO to request a major increase in cybersecurity spending focused on new technical tools. Meanwhile, the CFO has warned that investors are pressuring the company to protect margins and justify any new spending with measurable business value. The CEO asks the CISO to present a recommendation that will bridge operational stakeholder concerns and stockholder expectations. Which approach should the CISO take FIRST?

  1. A

    Recommend immediate purchase of multiple advanced security platforms to demonstrate decisive action and reassure business unit leaders that security is being strengthened

  2. B

    Frame the incident and proposed security investments in terms of business risk, resilience, financial impact, and prioritized treatment options tied to enterprise objectives and board risk appetite

  3. C

    Avoid discussing the recent incident in detail and focus the presentation on technical threat trends so the board does not overreact to a single event

  4. D

    Request that each business unit independently fund the security controls it wants so that cybersecurity costs are distributed and easier to approve

Show answer and explanation

Correct answer: B

Explanation

In CCISO practice, bridging stakeholders and stockholders means translating security from a technical function into an enterprise risk and value conversation. Internal stakeholders such as operations leaders, IT, and business unit heads are concerned with uptime, delivery, safety, and operational continuity. Stockholders and the board are focused on strategy execution, financial performance, regulatory exposure, and resilience. The CISO must therefore present cybersecurity in a way that connects both perspectives.

The best first approach is to frame the ransomware incident and any proposed investments in terms of business impact and risk treatment: what operational disruption occurred, what financial and strategic consequences could result from recurrence, what control gaps were identified, what options exist, what each option costs, and how each aligns to risk appetite and business objectives. This is consistent with widely accepted governance and risk management practices found in sources such as NIST CSF 2.0's emphasis on Govern and business-context alignment, NIST SP 800-39's enterprise risk management concepts, ISO/IEC 27001 and 27005 risk-based treatment principles, and board-focused cyber governance guidance from organizations such as NACD. The board does not need a tool-centric pitch first; it needs a prioritized, decision-oriented recommendation showing how security investment supports resilience, protects enterprise value, and enables informed oversight.

  • A. Incorrect.

    This is incorrect because leading with tool purchases focuses on solutions before business justification. While decisive action may appear responsive, boards and stockholders generally expect management to show how investments reduce enterprise risk, improve resilience, and support strategy. Buying multiple platforms without a prioritized, risk-based case can also worsen control overlap, increase operating cost, and fail to address the root causes identified in the incident.

  • B. Correct.

    This is correct because the CISO's role in bridging stakeholders and stockholders is to translate cybersecurity issues into business terms the board can govern against: operational disruption, financial exposure, resilience, strategic impact, and treatment choices. A strong first step is to connect the ransomware event to quantified or at least well-articulated business consequences, compare response options, and recommend prioritized investments aligned to enterprise objectives and board-approved risk appetite. This enables informed governance rather than reactive spending.

  • C. Incorrect.

    This is incorrect because withholding relevant incident context undermines transparent risk communication. The board needs concise, decision-useful information about what happened, the business impact, what was learned, and what management proposes to do next. Focusing mainly on threat trends shifts attention away from the company's actual risk posture and can appear evasive, which is particularly problematic when balancing stakeholder concerns and stockholder confidence.

  • D. Incorrect.

    This is incorrect because decentralizing funding in this manner often fragments the security program and weakens enterprise governance. Individual business units may optimize for local needs rather than enterprise risk reduction, resulting in inconsistent controls, duplicated spending, and uneven resilience. The misconception is that spreading cost automatically improves approval, when in reality the board typically expects a coherent enterprise-level security strategy tied to business priorities.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam