Enhance your strategic thinking. This simulation trains you to evaluate business impact, understand governance decisions, and select the best executive path.
You are the Chief Information Security Officer (CISO) for a major regional healthcare network. Ransomware attacks in the sector have surged by 400%, and peer hospitals have suffered catastrophic operational downtimes, forcing them to divert emergency patients. The Board of Directors is demanding an absolute assurance that patient care systems can survive a targeted ransomware event.
The organization's risk tolerance for data loss or extended system downtime is zero, as human lives are directly dependent on system availability. Furthermore, cyber insurance underwriters have mandated stringent proof of resilience before renewing the hospital's policy. The business objective is to guarantee operational continuity and completely neutralize the extortion leverage of any potential attacker.
You have the budget for one major strategic resilience initiative this quarter. The IT operations team wants to layer on additional preventative endpoint agents, but as the CISO, you recognize the "assume breach" paradigm: preventative controls eventually fail. You must prioritize the ultimate failsafe technology that ensures the business can recover its critical data without paying a ransom, even if the primary network is fully compromised.
1. What is the real problem?
Ransomware is an existential threat to business continuity. The core problem is not just malware infection, but the extortion leverage an attacker gains when they encrypt both primary data and standard backups. If backups are compromised, the business has no leverage and is often forced to pay.
2. Business vs. Security Perspective
Security teams often focus heavily on prevention (stopping the infection). The Board and the executive suite focus on survival and continuity (how fast can we resume operations if we get hit?). A mature governance strategy must address both, but prioritize assured recovery.
3. Risk and Impact Analysis
If an attacker gains administrative privileges, they will actively seek out and delete standard backup repositories before deploying the ransomware payload. The impact of losing both primary data and backups is catastrophic operational failure, regulatory fines, and potential loss of life in a healthcare setting.
4. Why the correct answer (A) is BEST
Immutable data storage (Option A) enforces a Write-Once-Read-Many (WORM) architecture. Once data is written to immutable storage, it cannot be altered, encrypted, or deleted for a defined period—even by a compromised administrative account. This guarantees a clean recovery point, neutralizing the attacker's leverage and ensuring the business can survive the attack.
5. Why other options are weaker:
6. Mini Lesson: Cost vs. Risk Trade-off
In risk management, we operate under the "Assume Breach" mentality. Investing solely in preventative controls has diminishing returns. Investing in immutable, verifiable recovery controls provides the ultimate ROI by guaranteeing the organization's existence post-breach. It shifts the strategic posture from brittle defense to assured resilience.
Explore more CCISO simulations to sharpen your executive decision-making.
Visit Practice Tests →