← All CCISO Flashcard Decks

Financial Management Flashcards

7 cards from real CCISO practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Financial Management flashcards as text
  1. A CISO is implementing a chargeback model where security costs are allocated back to business units. What is the primary governance benefit of this approach?

    Answer: It creates business unit accountability for security spending and incentivizes risk-reducing behavior

    Chargeback models make business units financially accountable for security costs, creating incentives to reduce risky behaviors that drive security spending.

  2. During a merger, a CISO is asked to value the cybersecurity risks of the acquisition target. Which financial due diligence activity is most critical?

    Answer: Assessing undisclosed breach history, regulatory violations, and known vulnerability exposure

    M&A security due diligence must prioritize undisclosed incidents, regulatory violations, and known vulnerabilities because these create inherited financial liabilities post-acquisition.

  3. A CISO is reviewing the organization's cyber insurance policy and finds that the policy excludes nation-state attacks. What type of exclusion is this?

    Answer: War and hostile act exclusion

    Nation-state attack exclusions fall under war and hostile act clauses, which insurers invoke to limit exposure to large-scale geopolitical cyber conflicts.

  4. A CISO wants to implement continuous security spending optimization. Which practice best supports real-time financial management of the security program?

    Answer: Monthly budget vs. actuals reviews with rolling 90-day forecasts

    Monthly actuals reviews with rolling forecasts enable CISOs to detect overspending or underspending early and reallocate funds before fiscal year-end constraints become binding.

  5. An organization experiences a ransomware attack with a demanded payment of $3M. The CISO must advise the CFO on the financial decision framework. Which factor most directly affects the pay-or-don't-pay decision?

    Answer: The cost of alternative recovery options compared to ransom payment and regulatory risk of paying

    The rational financial framework compares total cost of paying (ransom + regulatory sanctions risk + reputation) versus total cost of recovery (restoration time, data recreation, downtime losses).

  6. A CISO is evaluating a security control that costs $200,000 annually and reduces a risk with an ALE of $150,000. Using cost-benefit analysis, what should the CISO recommend?

    Answer: Do not implement the control as the cost exceeds the expected annual loss it prevents

    When safeguard cost ($200K) exceeds the ALE it prevents ($150K), a pure cost-benefit analysis indicates the control is not economically justified — spending more than you save is not rational unless compliance or other factors apply.

  7. A CISO is presenting the security program's financial performance to the audit committee. Which metric demonstrates that security spending is generating measurable risk reduction over time?

    Answer: Trend of declining ALE combined with stable or decreasing security spend per protected asset

    Declining ALE alongside stable or reduced per-asset spending demonstrates efficiency — the program is reducing financial risk exposure without proportional cost increases.