CCISO Financial Management 2 — Questions and Answers
Question 1: A CISO needs to justify a $500,000 security investment to the board. Which financial metric best demonstrates the investment's value by comparing potential loss reduction to cost?
- Net Present Value (NPV)
- Return on Security Investment (ROSI) (Correct answer)
- Internal Rate of Return (IRR)
- Payback Period
Correct answer: Return on Security Investment (ROSI)
ROSI specifically quantifies security investment value by calculating how much risk (potential loss) is reduced relative to the cost of the control.
Question 2: During budget planning, a CISO discovers that the organization's cyber insurance premium is increasing 40% due to poor security posture. How should this be classified in the security budget?
- Capital expenditure (CapEx)
- Operational expenditure (OpEx) (Correct answer)
- Sunk cost
- Discretionary spending
Correct answer: Operational expenditure (OpEx)
Insurance premiums are recurring operational costs classified as OpEx, not one-time capital investments.
Question 3: A CISO is building a Total Cost of Ownership (TCO) model for a new SIEM platform. Which component is most commonly underestimated in TCO calculations?
- Licensing fees
- Hardware procurement costs
- Integration, training, and ongoing maintenance costs (Correct answer)
- Initial implementation fees
Correct answer: Integration, training, and ongoing maintenance costs
TCO models often underestimate indirect costs like staff training, system integration labor, and ongoing maintenance, which frequently exceed initial procurement costs.
Question 4: A company allocates its security budget using a percentage of IT budget model. What is the primary weakness of this approach compared to risk-based budgeting?
- It always results in overspending on security
- It fails to account for the organization's specific threat landscape and risk profile (Correct answer)
- It is difficult to calculate and present to executives
- It cannot accommodate emergency security spending
Correct answer: It fails to account for the organization's specific threat landscape and risk profile
Percentage-of-IT budgeting is a benchmarking shortcut that ignores the organization's unique risks, industry threats, and regulatory requirements.
Question 5: When presenting a security budget variance to the CFO, the CISO notes spending exceeded the incident response line item by 200% due to a ransomware event. How should this be categorized?
- Planned variance
- Favorable variance
- Unfavorable variance requiring reforecast (Correct answer)
- Capital overrun requiring board approval
Correct answer: Unfavorable variance requiring reforecast
Unplanned cost overruns driven by security incidents represent unfavorable variances that require budget reforecast and updated financial planning.
Question 6: A CISO is evaluating whether to build an internal SOC or outsource to an MSSP. Which financial analysis technique is most appropriate for comparing these two multi-year options?
- Break-even analysis
- Net Present Value (NPV) analysis (Correct answer)
- Payback period calculation
- Gross margin comparison
Correct answer: Net Present Value (NPV) analysis
NPV analysis accounts for the time value of money across multi-year cost streams, making it ideal for comparing build-vs-buy decisions with different upfront and recurring costs.
Question 7: Under a zero-based budgeting (ZBB) model, what must a CISO do differently compared to incremental budgeting?
- Request 10-15% more than the prior year to account for inflation
- Justify every security expenditure from scratch each budget cycle (Correct answer)
- Base requests solely on industry benchmarks
- Delegate budget preparation to department managers
Correct answer: Justify every security expenditure from scratch each budget cycle
Zero-based budgeting requires justifying all spending from a zero baseline each cycle, rather than simply adjusting the prior year's approved budget.
A CISO needs to justify a $500,000 security investment to the board.
Which financial metric best demonstrates the investment's value by comparing potential loss reduction to cost?