712-50 Question 21
Single answerRisk Management (6 questions)A newly appointed CISO is preparing the annual cybersecurity investment plan for a global manufacturing company. The board has asked for a recommendation on whether to fund a proposed security program to reduce ransomware risk in plants running legacy operational technology (OT). The company has experienced two ransomware-related shutdowns in the last three years, each causing approximately $4 million in production losses. A proposed control package costing $2.5 million is expected to reduce the likelihood of a major OT ransomware shutdown from 20% annually to 8% annually, but it will not materially reduce the financial impact if such an event occurs. The company has a formally approved risk appetite statement requiring risks above defined financial thresholds to be either treated or explicitly accepted by executive management. What should the CISO do FIRST to provide the most defensible recommendation to the board?
- A
Recommend immediate approval because any reduction in ransomware likelihood is justified in critical infrastructure environments
- B
Calculate the expected annual loss reduction, compare it to the control cost, and determine whether the residual risk remains within the approved risk appetite
- C
Defer the decision until the OT environment can be fully modernized, because legacy systems make ransomware risk calculations unreliable
- D
Transfer the risk through cyber insurance, since insurance is typically more cost-effective than investing in preventive controls
- E
Escalate the issue directly to the audit committee because ransomware affecting manufacturing operations is automatically a board-level exception
Show answer and explanation
Correct answer: B
Explanation
At the CCISO level, risk management decisions should be framed in business terms and aligned with governance requirements. The most defensible first step is to quantify the proposed treatment's effect on risk exposure and then evaluate whether the resulting residual risk is within the organization's formally approved risk appetite. In this scenario, the control lowers annualized expected loss from $800,000 to $320,000, an annual reduction of $480,000. That does not automatically mean the investment should be rejected or approved, because the board may also consider non-financial factors such as operational resilience, concentration risk, safety implications in OT environments, regulatory expectations, recovery limitations, and the strategic importance of manufacturing continuity. However, the CISO must first present a clear analysis showing expected risk reduction and residual risk status. This approach aligns with broadly accepted practices from enterprise risk management and information security governance frameworks, including NIST guidance on risk assessment and response, ISO 27005 principles for information security risk management, and FAIR-style quantitative reasoning where appropriate. The key CCISO concept is that security investment recommendations should be supported by measurable risk reduction and governance alignment, not by intuition alone.
- A. Incorrect.
This is incorrect because it relies on a generalized assumption rather than a risk-based business case. In CCISO-level decision making, recommendations to the board should be grounded in quantified or otherwise defensible analysis, aligned to business impact, and measured against risk appetite. Even in critical environments, not every control investment is automatically justified without showing expected risk reduction and residual risk implications.
- B. Correct.
This is correct because the CISO should first quantify the change in expected loss and assess residual risk against the organization's approved risk appetite. Here, annualized loss expectancy before treatment is 20% × $4 million = $800,000. After treatment, it is 8% × $4 million = $320,000. The expected annual loss reduction is therefore $480,000. This analysis gives the board a defensible basis to evaluate whether a $2.5 million investment is economically justified and whether the remaining risk still requires treatment or formal acceptance. This is consistent with enterprise risk management principles and with a CISO's role in translating security risk into business terms for executive decision makers.
- C. Incorrect.
This is incorrect because uncertainty in legacy OT environments does not eliminate the need for risk analysis or investment decisions. Risk calculations often involve estimation and ranges, especially in operational settings. Waiting for full modernization may actually prolong unacceptable exposure. A CISO should use the best available data and assumptions, document limitations, and support decision making now rather than postponing action indefinitely.
- D. Incorrect.
This is incorrect because insurance is only one risk treatment option and does not inherently replace preventive or detective controls. Insurance also may not cover all operational losses, reputational damage, safety impacts, or regulatory consequences. The scenario asks what the CISO should do first to make a defensible recommendation. That requires evaluating risk reduction, economics, and residual risk before selecting among treatment options such as mitigation, transfer, avoidance, or acceptance.
- E. Incorrect.
This is incorrect because not every significant cyber risk automatically bypasses normal governance processes. Escalation may ultimately be appropriate if residual risk exceeds risk appetite or requires executive acceptance, but the first step is to provide decision-quality analysis. The board or audit committee should receive a recommendation supported by quantified impact, likelihood reduction, cost comparison, and alignment to the approved risk appetite.