712-50 Question 151
Single answerMotivating Teams for Common GoalsA newly appointed CISO inherits a security organization made up of incident response, security engineering, GRC, and identity teams spread across three regions. Employee engagement scores are falling, and business unit leaders complain that the security teams optimize for their own metrics rather than enterprise outcomes. For example, engineering delays projects to reduce technical debt, GRC focuses on policy exceptions, and incident response prioritizes mean time to contain without sharing lessons learned. The CEO has asked the CISO to unify the function around business objectives without increasing headcount. Which action should the CISO take FIRST to motivate teams toward common goals while improving cross-functional alignment?
- A
Introduce a common set of outcome-based objectives tied to enterprise risk reduction and business enablement, and cascade them into shared team goals and recognition mechanisms
- B
Replace existing team managers with external hires who have stronger technical backgrounds and can impose more discipline across the function
- C
Increase individual performance pressure by ranking teams against one another on quarterly security metrics and linking the lowest-ranked team to budget reductions
- D
Standardize all teams on a single operational metric, such as ticket closure volume, so each group is measured consistently across regions
Show answer and explanation
Correct answer: A
Explanation
The key issue in this scenario is not simply performance management; it is motivational alignment across specialized security teams. A CISO must create unity of purpose by translating enterprise strategy into shared security objectives that teams can see themselves contributing toward. This is consistent with common executive leadership and governance practices: align goals to business outcomes, define measurable results, reinforce collaboration through incentives and recognition, and avoid metrics that drive siloed or adversarial behavior. In practice, this may include enterprise OKRs or similar cascaded objectives, shared KPIs such as risk reduction, resilience improvement, secure business enablement, and post-incident learning outcomes, along with cross-functional reviews and recognition for collaborative achievements. This reflects established management principles from governance and performance frameworks such as balanced scorecard approaches, risk-based security leadership, and change leadership practices that emphasize vision, communication, and reinforcement over fear or purely structural interventions.
- A. Correct.
This is the best first action because it aligns motivation with a shared mission instead of reinforcing silos. In a CCISO context, senior security leaders are expected to connect team performance to business objectives, risk management outcomes, and stakeholder value. Establishing common, outcome-based objectives helps each team understand how its work contributes to enterprise priorities, while shared goals and recognition encourage collaboration rather than local optimization. This approach is practical, scalable without adding headcount, and consistent with leadership best practices such as goal alignment, balanced performance measurement, and incentive structures that support desired behaviors.
- B. Incorrect.
This is incorrect because changing managers is a disruptive structural response before the leadership problem has been properly diagnosed. The scenario indicates misaligned goals and incentives more than lack of technical depth. External replacements may damage morale further, slow delivery, and signal that the answer to low engagement is punishment rather than clarity, purpose, and coordination. A CISO should first align objectives, expectations, and collaboration mechanisms before making personnel changes.
- C. Incorrect.
This is incorrect because forced internal competition typically worsens silo behavior. If teams are already optimizing for local metrics, ranking them against one another will likely deepen mistrust, reduce information sharing, and encourage gaming of metrics. While accountability matters, motivation toward common goals is better achieved through shared outcomes, cross-functional KPIs, and recognition for enterprise impact. Linking poor ranking to budget cuts would also create fear-based behavior rather than sustainable engagement.
- D. Incorrect.
This is incorrect because a single activity metric such as ticket closure volume is too narrow and would distort behavior across diverse security functions. Incident response, engineering, GRC, and identity perform different work with different value drivers. Using one operational metric for all teams creates false consistency and may reward speed over effectiveness, quality, or risk reduction. Good leadership practice requires balanced metrics that reflect both team responsibilities and enterprise objectives.