712-50 Question 154
Single answerLead with empathyA newly appointed CISO inherits a security program after a phishing incident that led to public blame of several employees by senior leadership. Since then, business unit managers have become reluctant to report mistakes, and participation in security awareness sessions has dropped sharply. The CEO asks the CISO to rebuild trust quickly while still improving accountability and reducing repeat incidents. Which action should the CISO take FIRST to demonstrate empathetic leadership while advancing security outcomes?
- A
Implement a stricter disciplinary policy for policy violations so employees understand the seriousness of security failures
- B
Launch a listening campaign with affected teams, acknowledge the impact of the blame culture, and revise incident review practices to focus on learning and process improvement rather than individual fault
- C
Outsource security awareness training to a third party and make completion mandatory with quarterly testing
- D
Require all phishing-related incidents to be escalated directly to the CEO to reinforce executive oversight
Show answer and explanation
Correct answer: B
Explanation
The best first step is to rebuild trust through empathetic engagement and a shift from blame to learning. In executive security leadership, leading with empathy does not mean lowering standards; it means understanding stakeholder experience, creating psychological safety for reporting, and designing accountability mechanisms that improve resilience rather than conceal failure. This aligns with established security culture and human risk management practices, which emphasize that incident reporting improves when staff believe they will be treated fairly and that reviews will examine systemic factors, not just individual mistakes. A just-culture approach, common in high-reliability environments, is especially relevant: it distinguishes between human error, risky behavior, and reckless behavior, enabling proportionate accountability while preserving openness. From a governance perspective, the CISO should first address culture and communication because the scenario indicates these are the leading causes of reduced reporting and falling training participation. Once trust is reestablished, controls such as improved training, metrics, and disciplinary pathways can be applied more effectively.
- A. Incorrect.
This is incorrect because increasing punishment first is likely to deepen fear and underreporting. In environments where employees already feel blamed, a stricter disciplinary posture usually suppresses transparency, which weakens detection and response. While accountability matters, empathetic leadership in this scenario starts by restoring psychological safety and trust so the organization can learn from incidents.
- B. Correct.
This is correct because it directly addresses the root problem: a blame culture that is reducing reporting and engagement. An empathetic CISO should seek to understand stakeholder concerns, validate the impact of prior actions, and shift post-incident reviews toward a just, learning-oriented approach. This supports both human factors and security performance by encouraging earlier reporting, stronger collaboration, and sustainable behavioral change.
- C. Incorrect.
This is incorrect because training alone does not fix the trust breakdown described in the scenario. Mandatory training and testing may improve baseline awareness, but if employees fear blame, they may still hide mistakes or disengage. A third-party provider also does not solve the leadership and culture issue the CISO has been asked to address first.
- D. Incorrect.
This is incorrect because direct CEO escalation for all phishing incidents is disproportionate and can further intimidate staff and managers. Executive oversight is important, but routing operational incidents to the CEO as a default does not demonstrate empathy and may worsen reporting hesitation. It also risks creating bottlenecks and distracting leadership from governance-level responsibilities.