712-50 Question 128
Single answerHiring Future Leaders and TalentA newly appointed CISO is building a succession pipeline for the security function after losing two senior managers in the same year. The board has asked for a plan to identify and develop future security leaders who can eventually take over critical roles, not just fill current technical vacancies. Budget is limited, and the organization has struggled with promoting highly skilled individual contributors who later fail in management roles. Which action should the CISO take FIRST to improve hiring and development of future leaders?
- A
Create a leadership competency framework for security roles, map successors against it, and use it to guide hiring, assessment, and development plans
- B
Prioritize hiring the most technically advanced candidates from leading security teams, assuming leadership capability can be developed later
- C
Promote the highest-performing security engineers into management positions to retain top talent and reduce attrition risk
- D
Outsource leadership development to an external training provider and require all managers to complete the same program
Show answer and explanation
Correct answer: A
Explanation
The best answer is to first define the leadership profile required for future security leaders and build hiring and development around it. In CCISO-level practice, hiring future leaders is not simply about filling vacancies with strong technical candidates; it is about workforce planning, succession management, and aligning talent decisions to business strategy. A competency-based approach helps the CISO identify leadership potential objectively, reduce promotion mistakes, and create targeted development plans under budget constraints. This aligns with broadly accepted talent-management and succession-planning practices in leadership development, including role-based competency modeling, assessment against defined criteria, and structured development planning. It also reflects common governance and human capital best practices seen in frameworks and guidance from ISACA, NIST workforce development concepts, and general executive talent-management principles: define role requirements first, assess candidates against them, and then invest in development based on identified gaps.
- A. Correct.
Correct. A leadership competency framework is the best first step because it defines what success looks like in future leadership roles before hiring or promotion decisions are made. In a succession-planning context, the CISO needs to distinguish technical excellence from leadership readiness by identifying competencies such as strategic thinking, business alignment, stakeholder management, risk-based decision-making, communication, talent development, and crisis leadership. Once these competencies are defined, the organization can assess internal candidates, identify gaps, make better hiring decisions, and target development investments efficiently. This directly addresses the organization's past failure of promoting strong individual contributors who lacked managerial capability.
- B. Incorrect.
Incorrect. This reflects a common misconception that technical expertise is the primary predictor of leadership success in cybersecurity. While technical credibility is important, future security leaders must also influence executives, manage budgets, align security with business objectives, develop teams, and make risk-based decisions. Hiring solely for advanced technical depth can recreate the same problem the organization already experienced: strong specialists who are not prepared to lead.
- C. Incorrect.
Incorrect. Promoting top engineers into management without validating leadership competencies is a frequent talent-management error. High performance in an individual contributor role does not necessarily translate into success in people leadership, strategic planning, or executive communication. This option may seem attractive because it rewards top talent and may help retention in the short term, but it does not solve the core issue of identifying who can lead effectively.
- D. Incorrect.
Incorrect. External leadership training can be useful, but making it the first action is premature. Without first defining the specific leadership capabilities needed for the security organization, the training may be too generic and poorly aligned to succession requirements. A uniform program also ignores role-specific needs, organizational culture, and the differences between first-line managers, senior leaders, and executive successors.