ExamRange

CCISO (712-50) Executive Decision Simulation

Welcome to the executive strategy simulator. This scenario trains you to evaluate business impact and make governance-aligned decisions just as a Chief Information Security Officer would in the boardroom.

Executive Briefing

You are the Chief Information Security Officer (CISO) for FinTech Global, a mid-sized payment processing organization. During an annual risk assessment, your team identifies a sophisticated Advanced Persistent Threat (APT) risk targeting your core transaction database.

The engineering team proposes a massive overhaul of the network architecture to completely mitigate the risk. However, the Chief Financial Officer (CFO) has pushed back, noting that capital expenditure (CapEx) is tightly constrained this fiscal year due to pending acquisitions.

Business Context

FinTech Global's Board of Directors has established a moderate risk appetite for operational delays, but an incredibly low risk tolerance for direct financial loss resulting from a breach. The business objectives require maintaining a lean operational budget while ensuring the company's balance sheet is protected against catastrophic cyber events.

The cost to implement the proposed technical controls (Mitigation) is $1.5 million. The potential financial impact of the APT materializing is estimated at $12 million. The probability is low, but the impact is business-ending.

Decision Scenario

You are preparing your risk treatment recommendation for the Executive Risk Committee. Because mitigation is financially unfeasible and the impact exceeds the organization's risk tolerance (meaning you cannot simply "Accept" it), you must recommend an alternative governance strategy that aligns with the CFO's budget constraints while addressing the Board's mandate to protect the company's financial viability.

Question

Which of the following is an example of risk transference?

A. Purchasing Cyber insurance
B. Outsourcing the function to a 3rd party
C. Writing specific language in an agreement that puts the burden back on the other party
D. Implementing changes to current operating procedure
Executive Hint: Think about the core definition of "transference" in risk management. Are you transferring the operational duty, the legal liability, or the actual financial burden? Only one option provides a direct mechanism to shift the financial impact of a realized risk to another entity's balance sheet.