CCISO (712-50) Executive Decision Simulation
This module simulates a real-world governance decision. Review the business context and apply strategic risk management principles to select the optimal path forward.
Executive Briefing
You are the CISO of FinTech Global, an organization rapidly developing a new B2B mobile payment platform intended to capture significant emerging market share.
Recently, critical product launches have faced severe delays. Pre-deployment vulnerability assessments are discovering deep architectural flaws, forcing last-minute code rewrites and network restructuring.
Business Context
- Business Objective: Launch the payment platform by Q3 to meet aggressive revenue projections promised to the Board.
- Risk Appetite: Moderate tolerance for operational risk, but strictly zero tolerance for regulatory non-compliance (PCI-DSS) or data breaches.
- Financial Constraints: The development budget is fixed. Unplanned security retrofitting is consuming strategic reserve funds.
Decision Scenario
The Board of Directors is frustrated. They perceive the cybersecurity department as an expensive "Department of No" that acts as an excessive, after-the-fact tax on innovation.
The CFO demands a governance strategy that controls these unpredictable, late-stage security remediation costs without allowing the company to incur unacceptable residual risk.
Question
What can be done to ensure that security is addressed cost effectively?
Strategic Analysis
In governance frameworks like SDLC, the cost to fix a vulnerability increases exponentially as the project progresses. A security requirement addressed during the Requirements/Design phase costs $1. Finding and fixing that same flaw during Testing costs $15. Fixing it in Production costs $100+. Business alignment requires moving security to the far left of the timeline.
Explore more CCISO executive simulations
View Practice Tests