Enhance your strategic thinking. This simulation trains you to evaluate business impact, understand governance decisions, and select the best executive path.
You are the Chief Information Security Officer (CISO) for a publicly traded enterprise. Recent threat intelligence indicates a massive spike in targeted social engineering attacks, specifically aimed at C-suite executives and financial controllers (Whaling/Business Email Compromise). You need to validate that your investment in the "people" pillar of your security program is actually reducing this strategic risk.
The Board of Directors has recently approved a substantial budget increase for cybersecurity awareness training. However, the Audit Committee is now demanding concrete metrics to prove ROI. They want assurance that senior leaders—who hold the keys to sensitive financial data and strategic IP—are highly resilient against advanced, targeted threats. Merely reporting that "100% of staff completed the annual training video" is no longer acceptable to the board.
You must choose an evaluation method that accurately measures human behavior and the true risk reduction provided by your awareness program. The method must yield empirical data without disrupting business operations, while explicitly demonstrating whether your most privileged users can identify and report sophisticated threats.
1. What is the real problem?
Training completion does not equal threat resilience. The organization needs to move beyond vanity metrics (e.g., hours of training logged) and measure actual human behavior when confronted with realistic, targeted threats.
2. Business vs. Security Perspective
From a security perspective, we need to know if our people will click a malicious link. From a business perspective, the board needs empirical data to justify the security awareness budget and demonstrate regulatory due diligence in mitigating social engineering risks.
3. Risk and Impact Analysis
Senior executives are high-value targets. A compromised executive account can lead to maximum business impact, such as wire fraud, IP theft, or a massive data breach. If we do not explicitly test their resilience against targeted attacks, the organization carries a massive, unquantified risk.
4. Why the correct answer (C) is BEST
Option C (Controlled spear phishing campaigns) directly tests the human element. It provides actionable, quantifiable metrics on how well executives apply their security awareness training when faced with a realistic, tailored threat. It shifts the measurement from "effort expended" to "actual control effectiveness."
5. Why other options are weaker:
6. Mini Lesson: Metrics & KPIs
Good governance requires distinguishing between operational metrics (e.g., number of endpoints scanned) and risk metrics (e.g., human susceptibility to phishing). Board-level reporting must focus on risk reduction and control effectiveness. To evaluate human awareness, you must simulate the human attack vector.
Explore more CCISO simulations to sharpen your executive decision-making.
Visit Practice Tests →