CCISO Financial Management 3 — Questions and Answers
Question 1: A CISO identifies that a critical vendor managing customer PII has no cyber insurance. Under a shared risk model, what financial control should the CISO recommend?
- Terminate the vendor contract immediately
- Require the vendor to obtain adequate cyber liability insurance as a contractual obligation (Correct answer)
- Purchase additional cyber insurance to cover the vendor's risk
- Classify the vendor as a low-risk third party
Correct answer: Require the vendor to obtain adequate cyber liability insurance as a contractual obligation
Requiring vendors to maintain cyber liability insurance transfers financial risk back to the vendor and is a standard third-party risk management contractual control.
Question 2: A CISO must present a business case for a $2M security platform. The expected annual loss (ALE) for the risk it mitigates is $800,000. What does this indicate about the investment?
- The investment is financially justified because it addresses a real risk
- The investment cost exceeds the annual expected loss, suggesting it may not be cost-effective (Correct answer)
- The ALE should be multiplied by 5 years before comparing to cost
- The platform should be approved based on regulatory compliance needs alone
Correct answer: The investment cost exceeds the annual expected loss, suggesting it may not be cost-effective
When control cost ($2M) exceeds the annual expected loss ($800K), a cost-benefit analysis suggests the investment is not economically justified on risk grounds alone without other factors.
Question 3: Which of the following best describes the relationship between Annual Rate of Occurrence (ARO) and Annual Loss Expectancy (ALE)?
- ALE = ARO + Single Loss Expectancy (SLE)
- ALE = SLE × ARO (Correct answer)
- ALE = SLE / ARO
- ALE = ARO × Total Asset Value
Correct answer: ALE = SLE × ARO
ALE is calculated by multiplying Single Loss Expectancy (the cost of one incident) by the Annual Rate of Occurrence (how often it is expected to occur per year).
Question 4: A CISO is asked to reduce the security budget by 20% mid-year. What is the most appropriate first step?
- Immediately cut headcount to achieve the target reduction
- Perform a risk impact assessment to identify which cuts introduce the least additional risk (Correct answer)
- Defer all vendor renewals regardless of criticality
- Notify regulators of the budget reduction
Correct answer: Perform a risk impact assessment to identify which cuts introduce the least additional risk
Before making cuts, a risk impact assessment identifies which expenditures are critical to risk posture versus optional, enabling informed decisions that minimize exposure.
Question 5: A publicly traded company's CISO must ensure that material cybersecurity incidents are disclosed per SEC rules. What is the primary financial risk of late or inaccurate disclosure?
- Increased cyber insurance deductibles
- SEC enforcement actions, fines, and shareholder litigation (Correct answer)
- Loss of PCI DSS certification
- Mandatory security audit by the Federal Reserve
Correct answer: SEC enforcement actions, fines, and shareholder litigation
Under SEC cybersecurity disclosure rules, late or inaccurate material incident reporting exposes the company to SEC enforcement, civil penalties, and securities fraud litigation.
Question 6: A CISO is negotiating a cloud security contract and encounters a limitation of liability clause capping vendor damages at one month's fees. What financial risk management strategy should the CISO recommend?
- Accept the clause as standard industry practice
- Supplement with cyber insurance to cover losses exceeding the contractual cap (Correct answer)
- Renegotiate to a cap of six months' fees as an industry standard
- Require an escrow account equal to projected maximum losses
Correct answer: Supplement with cyber insurance to cover losses exceeding the contractual cap
When contractual liability caps fall short of potential loss exposure, cyber insurance fills the financial gap between what the vendor will pay and actual breach costs.
Question 7: Which financial document provides the CISO with the best view of committed but not yet spent security funds across the fiscal year?
- Income statement
- Balance sheet
- Budget vs. actuals report with encumbrances (Correct answer)
- Cash flow statement
Correct answer: Budget vs. actuals report with encumbrances
A budget vs. actuals report that includes encumbrances (committed but unspent funds) shows true available budget by accounting for purchase orders and contracts already in progress.
A CISO identifies that a critical vendor managing customer PII has no cyber insurance.
Under a shared risk model, what financial control should the CISO recommend?