712-50 Question 178
Single answerResilience During Uncertain EnvironmentA global manufacturing company is facing simultaneous uncertainty: a regional conflict has disrupted a major supplier, inflation is driving emergency cost-cutting, and the board is concerned about ransomware affecting production plants. The CISO is asked to recommend a resilience strategy that preserves critical operations even if preventive controls fail and business conditions continue to change over the next 12 months. Which action should the CISO prioritize FIRST to improve organizational resilience in this environment?
- A
Conduct an enterprise-wide business impact analysis to identify critical processes, map technology and third-party dependencies, and align recovery priorities and tolerances with executive risk appetite
- B
Increase spending on perimeter security tools for all plants to reduce the likelihood of cyberattacks during the period of instability
- C
Suspend nonessential security governance activities and focus the security team exclusively on ransomware response playbooks
- D
Transfer as much cyber risk as possible through insurance and accept temporary gaps in recovery capability until market conditions stabilize
Show answer and explanation
Correct answer: A
Explanation
The best answer is the enterprise-wide BIA and dependency mapping because organizational resilience in uncertain environments depends on maintaining and recovering critical business services despite shifting threats, supply-chain disruption, and resource constraints. For a CCISO-level leader, the priority is to establish a decision framework that links business criticality, recovery time objectives, recovery point objectives where relevant, third-party reliance, manual workarounds, and executive risk appetite. This enables rational allocation of scarce resources and supports board-level decisions on continuity, cyber recovery, and operational tradeoffs. This approach aligns with recognized practices in business continuity and operational resilience, including guidance from ISO 22301 on business continuity management systems, NIST Special Publication 800-34 on contingency planning, and NIST Cybersecurity Framework concepts related to governance, business environment, and recovery. Preventive controls, incident playbooks, and insurance remain important, but they should be informed by a clear understanding of what the organization must protect and restore first.
- A. Correct.
Correct. In a volatile environment, resilience begins with understanding what must continue, how quickly it must be restored, and what dependencies could cause cascading failure. An enterprise-wide business impact analysis (BIA), combined with dependency mapping and executive-approved recovery tolerances, gives the CISO the foundation to prioritize investments, validate recovery strategies, and coordinate with business, IT, operations, and third parties. This is the best first step because it supports resilience even when prevention fails and conditions change.
- B. Incorrect.
Incorrect. Strengthening perimeter security may reduce some attack likelihood, but it does not address broader operational resilience across supplier disruption, financial constraints, and recovery from a successful attack. A resilience strategy must account for continuity of critical business services, not just preventive technology controls. Choosing this option reflects the common misconception that more preventive tooling alone creates resilience.
- C. Incorrect.
Incorrect. Ransomware preparedness is important, but narrowing the program too aggressively creates blind spots in governance, third-party oversight, risk prioritization, and continuity planning. During uncertainty, governance and cross-functional decision-making become more important, not less. This option is attractive because ransomware is a visible threat, but it is too tactical and too narrow for the scenario.
- D. Incorrect.
Incorrect. Cyber insurance can be part of risk treatment, but it does not restore operations, replace tested recovery capabilities, or solve supply-chain and dependency issues. Accepting temporary recovery gaps during instability weakens resilience precisely when the organization should be validating its ability to operate through disruption. This option reflects a misunderstanding of the difference between financial risk transfer and operational resilience.