CCISO Financial Management 5 — Questions and Answers
Question 1: A CISO is implementing a chargeback model where security costs are allocated back to business units. What is the primary governance benefit of this approach?
- It reduces the overall security budget requirement
- It creates business unit accountability for security spending and incentivizes risk-reducing behavior (Correct answer)
- It eliminates the need for a centralized security budget
- It transfers legal liability to individual business units
Correct answer: It creates business unit accountability for security spending and incentivizes risk-reducing behavior
Chargeback models make business units financially accountable for security costs, creating incentives to reduce risky behaviors that drive security spending.
Question 2: During a merger, a CISO is asked to value the cybersecurity risks of the acquisition target. Which financial due diligence activity is most critical?
- Reviewing the target's security awareness training completion rates
- Assessing undisclosed breach history, regulatory violations, and known vulnerability exposure (Correct answer)
- Evaluating the target's firewall rule sets
- Auditing the target's software development lifecycle
Correct answer: Assessing undisclosed breach history, regulatory violations, and known vulnerability exposure
M&A security due diligence must prioritize undisclosed incidents, regulatory violations, and known vulnerabilities because these create inherited financial liabilities post-acquisition.
Question 3: A CISO is reviewing the organization's cyber insurance policy and finds that the policy excludes nation-state attacks. What type of exclusion is this?
- Sublimit exclusion
- War and hostile act exclusion (Correct answer)
- Systemic risk exclusion
- First-party coverage gap
Correct answer: War and hostile act exclusion
Nation-state attack exclusions fall under war and hostile act clauses, which insurers invoke to limit exposure to large-scale geopolitical cyber conflicts.
Question 4: A CISO wants to implement continuous security spending optimization. Which practice best supports real-time financial management of the security program?
- Annual budget review meetings with the CFO
- Monthly budget vs. actuals reviews with rolling 90-day forecasts (Correct answer)
- Quarterly penetration tests tied to budget cycles
- Annual vendor contract renegotiations
Correct answer: Monthly budget vs. actuals reviews with rolling 90-day forecasts
Monthly actuals reviews with rolling forecasts enable CISOs to detect overspending or underspending early and reallocate funds before fiscal year-end constraints become binding.
Question 5: An organization experiences a ransomware attack with a demanded payment of $3M. The CISO must advise the CFO on the financial decision framework. Which factor most directly affects the pay-or-don't-pay decision?
- Whether cyber insurance covers ransomware payments
- The attacker's reputation for providing working decryption keys after payment
- The cost of alternative recovery options compared to ransom payment and regulatory risk of paying (Correct answer)
- The organization's annual revenue relative to the ransom amount
Correct answer: The cost of alternative recovery options compared to ransom payment and regulatory risk of paying
The rational financial framework compares total cost of paying (ransom + regulatory sanctions risk + reputation) versus total cost of recovery (restoration time, data recreation, downtime losses).
Question 6: A CISO is evaluating a security control that costs $200,000 annually and reduces a risk with an ALE of $150,000. Using cost-benefit analysis, what should the CISO recommend?
- Implement the control because regulatory compliance requires it
- Do not implement the control as the cost exceeds the expected annual loss it prevents (Correct answer)
- Implement the control because all risks must be mitigated
- Defer the decision pending a third-party risk assessment
Correct answer: Do not implement the control as the cost exceeds the expected annual loss it prevents
When safeguard cost ($200K) exceeds the ALE it prevents ($150K), a pure cost-benefit analysis indicates the control is not economically justified — spending more than you save is not rational unless compliance or other factors apply.
Question 7: A CISO is presenting the security program's financial performance to the audit committee. Which metric demonstrates that security spending is generating measurable risk reduction over time?
- Total security headcount growth year-over-year
- Trend of declining ALE combined with stable or decreasing security spend per protected asset (Correct answer)
- Number of security tools deployed across the organization
- Percentage of IT budget allocated to security
Correct answer: Trend of declining ALE combined with stable or decreasing security spend per protected asset
Declining ALE alongside stable or reduced per-asset spending demonstrates efficiency — the program is reducing financial risk exposure without proportional cost increases.
A CISO is implementing a chargeback model where security costs are allocated back to business units.
What is the primary governance benefit of this approach?