712-50 Question 147
Single answerLeading During Crisis and DisastersA global manufacturing company is hit by a ransomware attack during a regional hurricane that has already disrupted power and telecommunications for one of its primary data centers. The CEO is demanding hourly updates, plant managers want systems restored immediately to avoid production losses, and the legal team is concerned about regulatory notification obligations because employee data may have been accessed. As the CISO, you discover that the incident response team is working in parallel with the disaster recovery team, but they are using different priorities and conflicting communications to executives. What should you do FIRST to lead effectively through this combined cyber and physical crisis?
- A
Establish a unified crisis command structure that integrates incident response, disaster recovery, legal, communications, and business leadership under a single decision-making framework with agreed priorities
- B
Authorize the disaster recovery team to restore affected systems immediately from backups so production can resume while the incident response team continues investigating separately
- C
Instruct the legal team to handle all executive and external communications until the full forensic scope is confirmed
- D
Focus the security team on determining attribution for the ransomware attack before making broader business continuity decisions
Show answer and explanation
Correct answer: A
Explanation
This question tests executive-level crisis leadership rather than pure incident handling. In CCISO contexts, the CISO must lead through ambiguity by aligning cyber incident response, disaster recovery, crisis communications, legal obligations, and business continuity under a single governance structure. Best practices from NIST Computer Security Incident Handling Guide (SP 800-61), NIST Cybersecurity Framework guidance on responding and recovering, and business continuity/disaster recovery standards such as ISO 22301 emphasize coordinated command, defined roles, communication pathways, and business-prioritized decision-making. In a compound event such as ransomware during a hurricane, separate technical teams operating independently can create contradictory messages, improper recovery sequencing, and increased legal and operational risk. The strongest first action is therefore to establish unified crisis leadership and a common operating picture before major recovery or disclosure decisions proceed.
- A. Correct.
Correct. In a combined cyber and physical disruption, the CISO's first leadership priority is to create a unified command structure so decisions, priorities, and communications are coordinated across security, IT operations, disaster recovery, legal, communications, and business leadership. This reduces conflicting actions, supports executive decision-making, and aligns incident response with business continuity objectives. It reflects crisis leadership best practices found in incident management and business continuity frameworks, including coordinated command, clear roles, and a common operating picture.
- B. Incorrect.
Incorrect. Restoring systems immediately may be tempting because of production pressure, but doing so before establishing coordinated governance can destroy forensic evidence, reintroduce malware, or restore into an unstable environment. The issue in the scenario is not simply technical recovery; it is conflicting priorities across teams. Recovery actions should occur within a unified crisis management structure, not as an isolated operational decision.
- C. Incorrect.
Incorrect. Legal counsel is essential for regulatory obligations, privilege considerations, and notification requirements, but assigning all executive and external communications solely to legal is too narrow and does not solve the core leadership problem of fragmented crisis management. Crisis communication should be coordinated across leadership, legal, communications, and operational teams to ensure messages are accurate, timely, and aligned with business decisions.
- D. Incorrect.
Incorrect. Attribution is rarely the first priority during an active business-disrupting crisis. While threat intelligence and forensic investigation matter, immediate leadership focus should be on life safety, business continuity, containment, evidence preservation, regulatory coordination, and coherent executive communication. Overemphasizing attribution early is a common mistake that delays effective response.