712-50 Question 127
Select 2Leading People, Building Teams, and Mentoring Future Leaders (6 questions)A newly hired CISO inherits a security organization formed through multiple acquisitions. The team includes strong technical specialists, but morale is low, turnover among high-potential managers is increasing, and there is no clear succession plan for critical leadership roles. The board has asked the CISO to strengthen leadership depth without disrupting ongoing security operations. Which TWO actions should the CISO take FIRST to build future leaders while improving team cohesion?
- A
Identify high-potential staff using transparent criteria, then create individualized development plans that include stretch assignments, mentoring, and measurable leadership objectives
- B
Replace most existing managers with external hires who already have leadership experience in mature security programs
- C
Establish a leadership pipeline by mapping critical roles, identifying successors for key positions, and cross-training team members to reduce single points of dependency
- D
Delay leadership development efforts until the security program reaches a stable operational state and incident volume declines
- E
Announce a competitive ranking system in which only the top 10% of staff receive leadership opportunities, to accelerate performance differentiation
Show answer and explanation
Correct answers: A, C
Explanation
The best answer combines structured leadership development with formal succession planning. In a fragmented, low-morale security organization, the CISO should first create clarity around talent identification and future leadership paths, while reducing operational dependency on a few individuals. This aligns with common executive leadership and workforce management practices: assess talent objectively, develop internal successors, use mentoring and stretch assignments to build capability, and cross-train to improve resilience. These actions also support retention, which is often as important as recruitment in building strong security leadership. Broadly accepted best practices from leadership development and governance frameworks emphasize succession planning, role clarity, accountability, and capability development as core management responsibilities. For a CCISO-level leader, the focus is not merely on technical excellence, but on building a sustainable leadership bench and a cohesive culture that can support long-term program maturity.
- A. Correct.
Correct. This is a practical first step because it addresses both talent retention and leadership development in a structured, defensible way. Transparent criteria reduce perceptions of favoritism, while individualized development plans help align employee aspirations with organizational needs. Stretch assignments, mentoring, and measurable objectives are widely used leadership development practices because they build capability through experience rather than relying only on classroom training.
- B. Incorrect.
Incorrect. External hiring can be useful for filling specific capability gaps, but replacing most existing managers early would likely damage morale, increase resistance, and undermine trust in the new CISO. It also fails to develop internal bench strength, which is a core requirement in the scenario. A common misconception is that leadership problems are solved primarily through replacement, when in practice sustainable succession usually requires a mix of development, retention, and selective hiring.
- C. Correct.
Correct. Mapping critical roles and identifying successors is fundamental to succession planning and organizational resilience. Cross-training reduces operational risk from key-person dependency while also broadening staff capability. This action supports continuity of leadership and operations at the same time, which is important because the board wants stronger leadership depth without disrupting current security activities.
- D. Incorrect.
Incorrect. Waiting for a perfectly stable environment is poor leadership in this context because operational pressure is common in cybersecurity. Delaying development increases the risk of further turnover and leaves critical leadership gaps unaddressed. A frequent error is treating leadership development as optional or secondary to operations, when effective CISOs integrate talent development into ongoing work.
- E. Incorrect.
Incorrect. Forced ranking systems can create internal competition, reduce collaboration, and discourage knowledge sharing, which is especially harmful in a post-acquisition environment where cohesion is already weak. While performance differentiation matters, restricting leadership opportunities to a small elite group too early can alienate capable staff and undermine a culture of mentoring and growth.