nerdexam
EC-Council

712-50 · Question #432

XYZ is a publicly-traded software development company. Who is ultimately accountable to the shareholders in the event of a cybersecurity breach?

The correct answer is C. CISO. Wait - there's a likely error in this answer key. Option D (CEO) is the correct answer, not C. Here's why: Why D (CEO) is correct: In a publicly-traded company, the CEO is the highest executive officer and bears ultimate accountability to shareholders for all organizational…

Governance (Policy, Legal & Compliance)

Question

XYZ is a publicly-traded software development company. Who is ultimately accountable to the shareholders in the event of a cybersecurity breach?

Options

  • AChief Financial Officer (CFO)
  • BChief Software Architect (CIO)
  • CCISO
  • DChief Executive Officer (CEO)

How the community answered

(34 responses)
  • A
    3% (1)
  • B
    9% (3)
  • C
    85% (29)
  • D
    3% (1)

Explanation

Wait - there's a likely error in this answer key. Option D (CEO) is the correct answer, not C.

Here's why:

Why D (CEO) is correct: In a publicly-traded company, the CEO is the highest executive officer and bears ultimate accountability to shareholders for all organizational outcomes - including cybersecurity breaches. The CEO reports to the Board of Directors, who represent shareholders. Post-breach, the CEO answers to investors, regulators (e.g., SEC disclosure requirements), and the board.

Why C (CISO) is wrong: The CISO owns the cybersecurity program and is operationally responsible for breach prevention and response - but "responsible" and "ultimately accountable" are different things. The CISO answers to the CEO, not directly to shareholders.

Why A (CFO) is wrong: The CFO manages financial risk and reporting, including breach-related financial losses, but has no direct accountability to shareholders for security posture.

Why B (CIO/Chief Software Architect) is wrong: This role governs technology strategy and architecture, not security accountability. Note the question also mislabels this role - CIO typically stands for Chief Information Officer.

Memory tip: Think of accountability as a chain - CISO → CEO → Board → Shareholders. "Ultimate" accountability always travels to the top of that chain: the CEO.

If this came from a study guide or course, it's worth flagging the answer key - this is a meaningful distinction in security governance.

Topics

#CISO accountability#organizational governance#cybersecurity breach#executive responsibility

Community Discussion

No community discussion yet for this question.

Full 712-50 Practice