712-50 Question 123
Single answerPredicting Future through Data AnalysisA global enterprise is building a security analytics program to predict which business units are most likely to experience a material cyber incident in the next 12 months. The CISO wants to use the model to prioritize budget, tabletop exercises, and control improvements. Historical incident data exists, but it is uneven across regions, and several recently acquired subsidiaries have limited loss history. Which approach is MOST appropriate for producing decision-useful forecasts at the executive level?
- A
Build a forecasting model using only internal incident counts from the last 12 months, because internal data is the most relevant and avoids external bias.
- B
Combine internal loss/event data with external threat intelligence and business context, then validate the model for data quality, bias, and changing conditions before using it for resource allocation.
- C
Use the business units with the highest number of vulnerabilities as the predicted highest-loss units, since vulnerability volume is the strongest standalone predictor of material incidents.
- D
Avoid predictive modeling entirely and rely on quarterly risk register updates from business unit leaders, because executive forecasting should remain qualitative.
Show answer and explanation
Correct answer: B
Explanation
For predicting future cyber risk at the executive level, the strongest approach is to use a blended model that incorporates internal incident and control data, external threat and industry loss information, and business context. This is especially important when historical internal data is incomplete, uneven, or sparse, such as after mergers and acquisitions. Good practice also requires validating the model for data quality, representativeness, bias, and ongoing relevance as the environment changes. This aligns with established risk management principles found in frameworks and guidance such as NIST SP 800-30 for risk assessment, NIST Cybersecurity Framework guidance on risk-informed decision-making, and FAIR-style quantitative risk thinking that emphasizes frequency, magnitude, and calibrated use of available data. At the CISO level, the goal is not perfect prediction, but sufficiently reliable forecasting to support prioritization of investments, exercises, and control improvements.
- A. Incorrect.
This is not the best approach because relying only on 12 months of internal incident counts is likely to produce weak forecasts, especially when data is sparse, inconsistent across regions, or absent for newly acquired subsidiaries. Short internal histories often underrepresent low-frequency, high-impact events and can embed reporting inconsistency rather than true risk. A common mistake is assuming internal data alone is inherently sufficient for prediction; in practice, executive-level forecasting benefits from multiple data sources and proper model validation.
- B. Correct.
This is the best answer because it reflects sound executive risk analytics practice: combine internal data with external threat intelligence, exposure indicators, and business context such as critical processes, asset value, control maturity, and acquisition status. It also recognizes that predictive models must be validated for data quality issues, bias, and concept drift before they are used to drive budget and strategic prioritization. This approach is aligned with mature cyber risk management practices that emphasize multiple inputs, governance over analytics, and fitness for decision-making rather than simplistic scoring.
- C. Incorrect.
This is incorrect because vulnerability volume alone is not a reliable predictor of material cyber loss. High counts may reflect better scanning coverage, broader asset inventories, or many low-severity findings rather than higher business risk. Material incidents depend on multiple factors, including exploitability, adversary interest, control effectiveness, business criticality, detection capability, and third-party exposure. A common misconception is equating technical weakness counts with enterprise loss likelihood.
- D. Incorrect.
This is incorrect because while qualitative input from business leaders is valuable, avoiding predictive modeling altogether ignores the benefit of structured data analysis in forward-looking risk management. Executive decisions about budget and preparedness are improved when qualitative judgment is supplemented by evidence-based forecasts. The misconception here is that forecasting must be either purely quantitative or purely qualitative; mature programs use both.