712-50 Question 160
Single answerExecutive PresenceA newly appointed CISO is presenting to the board after a recent ransomware incident that caused limited operational disruption but no confirmed data exfiltration. Several directors are frustrated because prior security briefings were highly technical and did not help them understand business exposure or management decisions. The CEO has asked the CISO to demonstrate stronger executive presence in this meeting and regain confidence in the security program. Which approach should the CISO take FIRST during the board presentation?
- A
Begin with a detailed walkthrough of indicators of compromise, malware behavior, and forensic tools used so the board can see the technical depth of the investigation
- B
Frame the discussion around business impact, current risk posture, management's response decisions, and the specific board-level support or approvals needed
- C
Emphasize that the security team followed all technical procedures correctly and defer broader business questions to the CEO and CFO
- D
Provide a comprehensive list of all security projects underway to demonstrate that the security program is active and working hard
Show answer and explanation
Correct answer: B
Explanation
Executive presence for a CISO is demonstrated through concise, confident, business-aligned communication, especially during high-visibility events such as board briefings after an incident. In this scenario, the board has already indicated that prior technical briefings were ineffective. The strongest first step is to reframe the conversation in terms the board uses for oversight: business impact, enterprise risk, management actions, residual exposure, and decisions requiring governance input. This aligns with widely accepted security leadership and governance practices reflected in board-focused guidance such as NIST Cybersecurity Framework governance-oriented communication principles, NIST SP 800-61 incident handling emphasis on management reporting, and common board reporting best practices that stress risk, impact, and decision support over technical detail. A CCISO candidate should recognize that executive presence is not merely presentation style; it is the ability to communicate authority, accountability, and strategic relevance to senior stakeholders.
- A. Incorrect.
This is incorrect because board members typically need governance-relevant information, not technical investigation detail. While technical rigor matters operationally, executive presence requires translating cyber events into business impact, risk implications, decision points, and accountability. Leading with deep forensic content often reinforces the perception that the CISO cannot operate at the executive level.
- B. Correct.
This is correct because effective executive presence at the CISO level means communicating with clarity, confidence, and relevance to the audience. For a board, that means focusing on operational and financial impact, legal or regulatory implications, residual risk, what management has done, what choices remain, and where board guidance or approval is required. This demonstrates strategic thinking, composure, and alignment with governance responsibilities.
- C. Incorrect.
This is incorrect because it weakens leadership credibility. A CISO is expected to own security outcomes, explain them in business terms, and engage confidently with executive stakeholders. Deferring business implications to others suggests a narrow technical role rather than enterprise leadership. Executive presence includes accountability and the ability to bridge technical issues and business decision-making.
- D. Incorrect.
This is incorrect because activity does not equal effectiveness, and a long project list can appear defensive or unfocused during an incident review. Boards generally care more about whether current controls reduced impact, what gaps were exposed, how risk is being managed, and whether investments are aligned to business priorities. Listing projects without connecting them to outcomes does not demonstrate executive presence.