712-50 Question 146
Single answerLeading During Crisis and DisastersA multinational financial services company is hit by a ransomware attack that encrypts several internal systems during quarter-end processing. Initial technical analysis suggests customer transaction platforms remain online, but there is uncertainty about possible data exfiltration. The CEO wants to immediately announce that customer data is safe to calm investors, while the CIO wants all affected systems disconnected globally, including some that support critical settlement activities. As the CISO leading the crisis response, what is the BEST next action?
- A
Approve the CEO's statement to reduce panic, since transaction systems are still operating and no confirmed breach has been reported
- B
Direct the CIO to disconnect all potentially affected systems immediately worldwide to prioritize containment over business operations
- C
Activate the cyber crisis management structure, establish a verified common operating picture, and coordinate legal, business, and technical decision-making before approving external statements or broad shutdowns
- D
Wait for the forensic team to complete root-cause analysis before involving executives, to avoid unnecessary escalation and conflicting decisions
Show answer and explanation
Correct answer: C
Explanation
In CCISO practice, leading during crisis and disasters is primarily about governance, prioritization, and coordinated decision-making under uncertainty rather than purely technical action. The best first move is to activate the incident or cyber crisis management framework, confirm roles and escalation paths, and build a reliable common operating picture before making irreversible operational decisions or public statements. This aligns with widely accepted best practices in NIST SP 800-61 incident handling guidance, which emphasizes coordinated response, communication control, evidence-based decision-making, and stakeholder management. It also aligns with business continuity and crisis management principles found in ISO 27035 and ISO 22301, where organizations are expected to balance incident containment with continuity of critical services. In this scenario, the CISO must prevent two common leadership failures: communicating unverified conclusions and taking overly broad containment action without assessing business impact. The strongest response is therefore to activate formal crisis governance and synchronize technical, legal, communications, and business leadership before committing to external messaging or enterprise-wide shutdown decisions.
- A. Incorrect.
This is incorrect because public assurances should not be made before facts are validated, especially when data exfiltration is still uncertain. Premature statements create legal, regulatory, and reputational risk if later evidence contradicts them. A common executive error during crises is prioritizing market reassurance over verified situational awareness.
- B. Incorrect.
This is incorrect because although containment is important, an immediate global shutdown without structured impact analysis can unnecessarily disrupt critical business services such as settlement operations. Effective crisis leadership requires balancing containment, safety, legal obligations, and business continuity. A blanket technical response without executive coordination may worsen organizational harm.
- C. Correct.
This is correct because the CISO's leadership role during a crisis is to ensure disciplined decision-making under uncertainty. Activating the crisis management structure creates governance, clarifies authority, aligns stakeholders, and supports decisions based on a validated common operating picture. This approach allows the organization to evaluate containment options, preserve critical operations, prepare accurate communications, and address legal/regulatory obligations in parallel.
- D. Incorrect.
This is incorrect because delaying executive involvement until forensics are complete is inconsistent with effective crisis leadership. Major incidents require prompt executive coordination, especially when customer impact, regulatory exposure, and critical operations are at stake. Forensic analysis informs decisions, but crisis governance must begin before all facts are known.