712-50 Question 122
Single answerPredicting Future through Data AnalysisA global manufacturing company wants the CISO to justify next year's cybersecurity budget using predictive analysis rather than historical spending trends. The security team has three years of incident data, including phishing rates, vulnerability remediation times, third-party assessment findings, and security operations center (SOC) alert volumes. The board wants to know which business units are most likely to experience a material cyber incident in the next 12 months so that limited funds can be prioritized. Which approach should the CISO recommend FIRST to produce the most defensible forecast for executive decision-making?
- A
Build a risk model that combines historical incident frequency with leading indicators such as control maturity, asset criticality, exposure trends, and business-unit-specific threat intelligence, then validate the model against known outcomes
- B
Use the total number of SOC alerts by business unit as the primary predictor because high alert counts directly indicate future material incidents
- C
Rank business units by the largest cybersecurity spend increase requested by their managers, since local leadership best understands where future incidents will occur
- D
Project next year's incident likelihood by extending the three-year average number of incidents per business unit without adjusting for environmental or control changes
Show answer and explanation
Correct answer: A
Explanation
In a CCISO context, predicting future outcomes through data analysis should support business-aligned risk decisions, not just technical reporting. The strongest first step is to build and validate a predictive risk model using multiple relevant variables, including historical loss data and leading indicators. This is consistent with established risk management principles reflected in frameworks such as NIST Cybersecurity Framework 2.0 and NIST SP 800-30, which emphasize analyzing likelihood and impact using threat, vulnerability, exposure, and control information. It also aligns with FAIR-style thinking, where forecast quality improves when organizations evaluate probable event frequency and loss exposure using measurable factors rather than single operational metrics. For executive decision-making, the model should be transparent, calibrated, and tested against prior outcomes so the CISO can explain not only which business units appear riskier, but why.
- A. Correct.
Correct. A defensible predictive approach should use both lagging data (past incidents) and leading indicators that are causally relevant to future risk, such as control maturity, asset criticality, external exposure, and threat activity. Validation against known outcomes is critical to demonstrate that the model has predictive value rather than merely describing the past. This aligns with mature cyber risk management practices, where forecasting should be tied to business context and measurable drivers of loss exposure.
- B. Incorrect.
Incorrect. SOC alert volume is a noisy operational metric and often reflects logging coverage, tuning quality, and detection engineering maturity rather than actual likelihood of a material incident. A business unit with more telemetry can generate more alerts without being at higher risk. Using alert counts alone is a common mistake because it confuses activity data with risk outcomes.
- C. Incorrect.
Incorrect. Business-unit leaders may provide useful context, but budget requests are subjective and can be influenced by politics, local priorities, or varying levels of security awareness. They are not an objective predictive indicator of future cyber incidents. Relying primarily on requested spend would weaken the credibility of the forecast with the board.
- D. Incorrect.
Incorrect. Straight-line extrapolation from historical averages is easier to present, but it is not the most defensible method when control environments, threat conditions, digital exposure, and business operations change over time. This approach may be acceptable for basic trend reporting, but not for prioritizing scarce funds based on forward-looking cyber risk.