712-50 Question 161
Single answerExecutive PresenceA newly appointed CISO is presenting to the board after a ransomware incident that disrupted operations for two days. Several directors are skeptical of cybersecurity spending because the company had previously passed compliance audits. The CEO asks the CISO to use the board meeting to rebuild confidence and secure support for a multi-year resilience program. Which approach best demonstrates strong executive presence in this situation?
- A
Lead with highly technical details of the malware strain and endpoint telemetry to demonstrate depth of expertise, then ask for immediate approval of additional security tools
- B
Frame the incident in terms of business impact, resilience gaps, risk treatment options, and decision points for leadership, while communicating calmly and concisely in non-technical language
- C
Emphasize that the incident occurred because business units did not follow security policy, and recommend stricter enforcement before discussing investment needs
- D
Focus on the fact that the organization met audit requirements, explain that no program can stop every attack, and defer strategic recommendations until the investigation is fully complete
Show answer and explanation
Correct answer: B
Explanation
In CCISO practice, executive presence means more than confidence or presentation skill; it reflects the ability to influence senior stakeholders through clear judgment, business alignment, emotional control, and credible decision support. In board communications, the CISO should avoid diving into excessive technical detail unless specifically requested and should instead translate cyber events into enterprise risk language: business interruption, recovery priorities, financial implications, regulatory considerations, customer trust, and strategic trade-offs. Best practices from board-focused cybersecurity governance guidance, including principles promoted by organizations such as NIST and ISACA, emphasize risk-based communication, role-appropriate reporting, and resilience over mere compliance. The strongest response therefore centers on concise business communication, visible command of the incident, and actionable options for leadership.
- A. Incorrect.
This is incorrect because executive presence at the board level is not primarily about displaying technical mastery. While technical understanding is essential for a CISO, board members typically need a clear articulation of business impact, organizational exposure, and decision-ready recommendations. Leading with malware specifics and telemetry often reduces clarity, weakens influence, and can make the CISO appear disconnected from board priorities. The request for immediate tool approval also suggests a tactical, solution-first mindset rather than strategic leadership.
- B. Correct.
This is correct because strong executive presence requires composure, clarity, credibility, and alignment with business priorities. In a board setting, the CISO should translate the incident into operational, financial, legal, reputational, and strategic implications. Presenting resilience gaps, practical response options, and leadership decisions needed shows command of the situation and supports informed governance. Calm, concise, non-technical communication is especially important when trust must be rebuilt after an incident.
- C. Incorrect.
This is incorrect because blaming business units in a board meeting undermines leadership credibility and usually weakens executive influence. Although policy adherence may be relevant, executive presence requires ownership, balanced judgment, and cross-functional leadership. Directors expect the CISO to present enterprise-level solutions, not focus on fault allocation. This option reflects a common misconception that strong leadership means being forceful or punitive rather than collaborative and strategic.
- D. Incorrect.
This is incorrect because it overemphasizes audit success and underplays the board's need for forward-looking risk decisions. Passing compliance audits does not equate to operational resilience, and directors generally understand that compliance is only one component of a security program. Deferring strategic recommendations entirely until the investigation is complete may appear hesitant and unprepared. A CISO with executive presence can acknowledge uncertainty while still presenting provisional risk-informed next steps.