Part of the CISO Interview Template Pack · cisoprep.com
About this example
Northwind Commerce is a fictional company, invented for this document. Every fact below was constructed for illustration. Do not cite any of it as real.
The profile: a mid-market e-commerce platform, roughly $800M revenue, full PCI-DSS scope, a SOC 2 Type II completed six months ago with findings, a team of 14 inherited after the previous security leader left for a larger company, cyber insurance renewing in 5 months, a quarterly audit committee.
Every entry below traces back to one of those facts. That internal consistency is the whole game: a panel can smell generic best practices, but cannot argue with a plan where every line answers something specific about their business.
Why this works: Northwind has visible, datable pressure (renewal in 5 months, findings aging, quarterly committee). Deadlines you inherit are more persuasive than priorities you invent. For a real company, hunt for the inherited clocks first.
Company snapshot
| Field | Entry |
|---|---|
| Company, stage, revenue model | Northwind Commerce. Mid-market e-commerce platform, ~$800M revenue. Merchants sell through the platform; Northwind takes a cut of every processed payment plus subscription fees. Revenue stops when checkout stops. |
| The 2–3 things security must protect | (1) The payment flow: revenue engine and PCI scope. (2) Checkout uptime: an hour down is measurable lost revenue, worst in Q4. (3) The customer and merchant data platform: 40M records; a breach here is a churn event, not just a fine. |
| Regulatory and contractual drivers | PCI-DSS Level 1 (annual ROC). SOC 2 Type II with 3 open findings. Insurance renewal in 5 months; the carrier will ask about the same controls the SOC 2 flagged. State privacy laws. Security addenda with the top 20 enterprise merchants. |
| Known history | No public breach. SOC 2 findings: incomplete production access reviews, no tested disaster recovery for the order database, logging gaps in the payment stack. Previous security leader left after 3 years; team of 14 inherited intact but unled for 4 months. |
| My operating assumptions from the outside | (1) The SOC 2 findings are unremediated or partial, and the clock is running. (2) The renewal will be harder than last year and the CFO doesn't know that yet. (3) The team is competent but demoralized; at least one strong person is a flight risk. (4) Engineering ships fast and sees security as a gate. (5) The crown jewel is the payment flow, but the biggest unmanaged risk is the data platform: everyone watches what makes money, nobody watches what stores it. |
Why this works: Every assumption is falsifiable. "Security is probably underfunded" is filler. "The renewal will be harder and the CFO doesn't know yet" is a claim you can be wrong about, which is exactly what makes it credible.
Phase 1 (Days 1–30): Listen and assess
Goal: understand the business, the risk, and the politics before changing anything. Anti-goal: announcing a strategy, reorganizing the team, buying anything.
The 11 conversations, with what each one produced
| # | Who | Question asked | What was learned |
|---|---|---|---|
| 1 | CEO | "What would make you consider security a failure two years from now?" | Two answers, unprompted: a breach that makes enterprise merchants leave, and "security becoming the reason we ship slower than competitors." He cited a rival's breach and the defections that followed. Uptime never came up; he assumes it. |
| 2 | CFO | "How has security spend been planned historically, and what was the last ask you declined?" | Security is a line inside the IT budget, flat for 3 years. She declined a $400K "platform consolidation" ask because it had no definition of done. She raised the renewal herself: premiums up 30 to 40 percent, carrier wants evidence on MFA, backups, and logging. |
| 3 | General Counsel | "Where are we exposed today that keeps you up at night, and how do we handle privilege in incidents?" | The top-20 merchant addenda promise 48-hour breach notification and annual pen tests; he can't prove either is operationally true. No privilege protocol for incidents; the last tabletop was 2 years ago, without legal. |
| 4 | Audit committee chair | "What do you want from my reporting that you weren't getting?" | Trend, not snapshot: "Every quarter I got a new dashboard with new metrics and no way to tell if we were getting better." She personally committed to the full board that the SOC 2 findings would close within the year. |
| 5 | Head of Engineering | "Where does security help or hurt your velocity today?" | A manual review adds 5 to 8 days to any release touching the payment stack, through a ticket queue with one reviewer. Engineers route around it by batching changes, which makes each review bigger and riskier. |
| 6 | Head of Product | "What's on the roadmap that should scare me?" | A Q4 launch of stored payment credentials for one-click checkout (a significant PCI scope expansion), and an AI merchant-analytics feature training on transaction data with no governance review. Both committed externally. |
| 7 | Head of People | "What does the exit-interview data say about my team?" | Two departures during the leaderless gap, both citing "no growth path." Comp is below the 50th percentile. The interim manager (the GRC lead) is respected but exhausted and didn't want the role. |
| 8 | Chief Revenue Officer | "What do customers and prospects actually ask about security?" | Enterprise deals stall on security questionnaires, which sales answers ad hoc, sometimes optimistically. Two pipeline deals are blocked pending SOC 2 evidence. Prospects already ask about the AI feature's data handling. |
| 9 | Inherited team leads (1:1s) | "What did the last leader protect you from, and what could they never get funded?" | He absorbed exec escalations personally, which is why nothing is written down. The unfunded ask: payment-stack log aggregation (the same SOC 2 gap) and a second reviewer. The detection engineer is interviewing elsewhere. |
| 10 | IT leader | "What do you own that I'm accountable for?" | More than expected: backups, identity, and endpoints all sit in IT. Backups run nightly but a restore of the order database has never been tested. MFA covers corporate SSO but not three legacy admin paths into production. |
| 11 | Previous CISO (reachable) | "What would you have done differently, and what could you never get funded?" | "I'd have fixed access reviews in year one; it poisoned every audit." Never funded: payment-stack logging, asked twice, framed as compliance both times, declined both times. Parting advice: "The CFO funds things with definitions of done." |
Why this works: The answers disagree with each other, which is what real organizations do. A plan that discovers tension is believable; one where every stakeholder endorses the CISO's agenda is fiction. Conversation 11's "declined twice, framed as compliance" is the most useful sentence in the phase: it tells you how NOT to ask.
Phase 1 outputs (the gate to Phase 2)
Stakeholder worry map (verbatim worries)
| Stakeholder | Stated worry, their words |
|---|---|
| CEO | "A breach that makes enterprise merchants leave" / "security becoming why we ship slower" |
| CFO | "The insurance renewal, and asks with no definition of done" |
| GC | "We've promised 48-hour notification and annual pen tests, and I can't prove either" |
| Audit chair | "No trend. And I told the board the findings would close this year" |
| Eng | "The 5-to-8-day payment review queue" |
| Product | "Nothing scares me" (which is itself the finding) |
| CRO | "Deals stalling on security questionnaires" |
| Team | "No growth path, and nobody ever funded the logging" |
Crown-jewel inventory (what actually matters)
- Payment processing flow (revenue engine, PCI scope, expanding in Q4)
- Order database and customer data platform (40M records; restore never tested)
- Checkout availability (direct revenue linkage, Q4 concentration)
- Merchant financial data (contractual addenda, churn risk on breach)
- Production identity paths (three legacy admin routes without MFA: connective tissue for everything above)
Inherited-commitments list
- 3 SOC 2 findings with remediation dates committed to the audit committee, all inside two quarters
- 48-hour breach notification and annual pen tests promised in top-20 merchant addenda
- Insurance renewal in 5 months; carrier evidence expected on MFA, backups, logging
- Q4 stored-credential launch, already announced to merchants
- PCI ROC cycle, assessor fieldwork in roughly 7 months
Team assessment
14 people: 5 security engineering, 3 detection and response, 3 GRC, 2 application security, 1 vendor risk. Capability is real; the GRC lead held the function together unled. Gaps: single-threaded appsec review, no leadership layer, comp below market, detection engineer interviewing. No reorg needed; the problem is leadership and funding, not design.
Draft risk list (unranked; ranking is Phase 2 work)
- Untested restore of the order database
- Three legacy admin paths into production without MFA
- Payment-stack logging gaps (SOC 2 finding, insurance question, detection blind spot)
- Incomplete production access reviews (SOC 2 finding)
- 48-hour notification promise with no rehearsed incident process
- Q4 stored-credential launch expanding PCI scope without security design input
- AI analytics feature training on transaction data, no governance review
- Single-threaded payment review queue driving batching in engineering
- Detection engineer flight risk in a 3-person detection team
- Ad hoc, occasionally optimistic questionnaire answers going to enterprise prospects
Why this works: The draft list includes a people risk (#9) and a truth-telling risk (#10), which most inherited registers omit because they are politically awkward. Listing them before anything goes upward keeps Phase 2 honest.
Phase 2 (Days 31–60): Prioritize and align
Goal: turn findings into a risk-ranked view the executive team agrees with. Anti-goal: a 40-page assessment nobody reads.
The ranked risk list, in business-impact language
| Rank | Risk | Business impact statement |
|---|---|---|
| 1 | Untested restore of the order database | If the order database is corrupted or ransomed, we don't know whether we can restore it or how long it takes. In Q4, each day of checkout downtime is roughly $3M. Also the carrier's first question. |
| 2 | Legacy admin paths without MFA | Three unguarded doors into production. One phished credential ends in risk #1's worst case. A "no" on this carrier item moves the premium. |
| 3 | Payment-stack logging gaps | If the payment flow is compromised today, we may not detect it and could not reconstruct it for the 48-hour notification. One gap, three exposures: detection, contract, SOC 2 finding. |
| 4 | Unrehearsed incident process vs. the 48-hour promise | We contractually promised a notification speed we've never rehearsed. A mishandled first incident becomes a churn event on top of a breach. |
| 5 | Stored-credential launch without security design input | Fine if designed in now; expensive and public if retrofitted after PCI fieldwork. The deadline is external and immovable. |
| 6 | Incomplete production access reviews | The audit chair personally committed closure to the board. Aging findings compound: next year's report, the carrier, and enterprise questionnaires all read the same finding. |
| 7 | AI feature with no data governance review | Prospects are already asking. Sold wrong, a questionnaire liability; designed right, a sales answer. |
| 8 | Payment review queue driving batching | Slower shipping AND riskier changes: the CEO's second failure mode arriving through a process we control. |
| 9 | Detection team key-person risk | Losing the interviewing engineer takes detection from 3 to 2 during the highest-risk quarter. |
| 10 | Ad hoc questionnaire answers | Optimistic answers to enterprise prospects are contractual claims we may be failing quietly. |
Why this works: Every impact statement names a number, a contract, a date, or a person; never a CVSS score. Ranks 1 through 3 are all carrier questions arriving within 5 months: the ranking quietly converts the renewal deadline into leverage.
Socialization notes
Walked the ranked list past the CFO and GC individually, before any group setting.
- CFO (day 38): Agreed with 1 through 3 immediately; "these are the carrier's first three questions" landed. Pushed back on #8 as an engineering problem; kept it, re-anchored to the CEO's stated failure mode. She flagged that any budget ask should land before her mid-cycle reforecast in 3 weeks.
- GC (day 41): Wanted #4 above #3. Resolved by making the dependency explicit: you cannot notify in 48 hours about an incident you cannot reconstruct. He accepted the ordering and asked to co-own the tabletop. A co-owner on the legal risk is a gift.
- CEO (day 44, brief): Previewed the top 3 and the quick wins. His question: "What does the restore test cost me?" Answer: two engineers, one weekend, a maintenance window. His response, verbatim: "Why hasn't that already happened?" That sentence is the sponsorship for quick win #1.
Why this works: Socialization produced changes (the #3 vs #4 ordering, the reframing of #8) and intelligence (the reforecast window). If your socialization round changes nothing, you didn't socialize, you rehearsed.
The first budget ask
The ask (day 47, to the CFO): $185K one-time to deploy log aggregation across the payment stack, covering the 12 production services in PCI scope, plus $60K/year run-rate.
Tied to: Risk #3, SOC 2 finding #3, and the carrier questionnaire, by name.
Definition of done: By day 90, all 12 payment services shipping logs with 90-day retention; the SOC 2 finding evidenced as remediated; the carrier questionnaire items answerable "yes" with proof. Verified by the GRC lead, reported in the day-90 readout.
Outcome: Approved in the same meeting, inside the reforecast window. The CFO: "This is the first security ask I've seen with an end state."
Why this works: Compare the two failed asks in the history: the logging request framed as compliance (declined twice) and the $400K consolidation with no definition of done. This ask is deliberately smaller than the program will need, because its real product is not logs, it is credibility for the year-one budget conversation. It also quietly funds the team's oldest unfunded wish, which the team notices.
Quick wins (two, both passing the four-part filter)
Quick win 1: Tested restore of the order database.
- Visible outside security: the CEO asked "why hasn't that already happened?" out loud; the result goes to him and the CFO directly.
- Ties to named worries: CEO (merchant-losing breach), CFO (carrier evidence), audit chair (the DR finding).
- Low political cost: executed with IT, who was relieved someone asked; one maintenance window.
- Done inside 30 days, provably: restore executed day 55, database recovered in 6 hours 40 minutes, timing report shared. Also closes SOC 2 finding #2.
Quick win 2: Kill the ticket-queue payment review; replace it with an embedded review lane.
- Visible outside security: the Head of Engineering reports the cycle-time change in his own ops review, which beats security reporting it.
- Ties to named worries: engineering's queue, and the CEO's "security as the reason we ship slower."
- Low political cost: negative, engineering asked for it. The second reviewer is a temporary rotation.
- Done inside 30 days, provably: review SLA moved from 5–8 days to 2 for standard changes, with a pre-approved pattern list removing review for the most common change types. Measured from engineering's own ticket data.
Why this works: The second win is the higher-value one precisely because it REMOVES friction. A new CISO who kills a hated process in the first 60 days buys more goodwill than any deployed tool. And the pattern list makes explicitly a risk decision that was previously being made by queue-evasion.
Phase 2 outputs
- Risk register: ranked, business language, socialized individually. Done.
- Quick wins: restore test day 55; review-lane change day 60. Done.
- First budget ask: made day 47, approved, delivery on track for day 90. Done.
- Year-one program skeleton, four initiatives mapped to named risks: (1) Detect and respond: payment logging plus incident rehearsal (risks 3, 4). (2) Production access hardening: MFA on legacy paths, access review automation (risks 2, 6). (3) Secure the Q4 launch: stored-credential design plus AI data governance (risks 5, 7). (4) Team durability: comp correction, second appsec reviewer, detection retention (risks 8, 9).
Phase 3 (Days 61–90): Deliver and report
Goal: the first board-ready readout and a repeatable operating rhythm. Anti-goal: a reassuring readout. Everything wrong right now is inherited; in a year it's yours. Spend the bluntness while it's free.
The day-90 readout (delivered to the audit committee, day 88)
1. What I found. Northwind's posture is better than the audit paper trail suggests and worse than the contracts require. The team is capable; the gaps are funding and process, not competence. Three specifics: we had never tested a restore of the order database (we now have, in under 7 hours); we cannot yet reconstruct activity in the payment stack (logging completes this week); and we have promised merchants a 48-hour breach notification we have never rehearsed. One SOC 2 finding is closed, one closes this week, one is scoped for next quarter. Stated plainly: some of our questionnaire answers today are more optimistic than our controls.
2. What could hurt us. First, compromise of production through the legacy admin paths still lacking MFA: one phished credential reaches the order database, and in Q4 each day of checkout downtime is roughly $3M. Remediation in flight, done next quarter. Second, an incident we detect late and reconstruct slowly, breaching the 48-hour promise and turning a security event into a churn event; the logging work and a Q3 tabletop with legal address this. Third, the stored-credential launch expanding PCI scope: designed with us now (started), routine; retrofitted after assessor fieldwork, expensive and public.
3. What I'm doing, in what order. Four initiatives, each tied to a risk you just heard. Detect and respond first: it collapses the largest gap between what we promise and what we can do. Production access hardening second: carrier-visible and finding-closing. Securing the Q4 launch third: the deadline is external. Team durability fourth but concurrent: we are below market on comp in a 14-person team carrying an $800M platform, and I nearly lost one of three detection engineers.
4. What it costs. The year-one program is $1.4M incremental: $700K run-rate (one appsec engineer, one detection engineer, tooling) and $700K one-time (access automation, launch security work, comp correction). Declining the run-rate keeps the 2-day review SLA on a rotation that fails within two quarters, and leaves detection one resignation from half-staffed through Q4. Declining the comp correction re-runs this year's two departures. The formal ask comes through the budget cycle; today I am asking the committee to agree the risk ranking, so it lands pre-agreed.
Why this works: Section 1 confesses the questionnaire problem before anyone discovers it, converting a future scandal into a present credential. Section 4 doesn't ask for money in the meeting; it asks for agreement on the ranking, which is what a committee can genuinely give, and it prices the "no" in risk terms rather than pleading. The whole readout runs under ten minutes.
The operating rhythm installed
| Cadence | Forum | Content |
|---|---|---|
| Weekly | Security leadership (5 leads, 45 min) | Delivery against the four initiatives, incidents, blockers |
| Monthly | CFO 1:1 (exec sponsor, 30 min) | Risk movement against the ranked ten, budget status, decisions needed; same format every month so trend is visible |
| Quarterly | Audit committee | The four-section readout, updated; SOC 2 finding tracker until closed; same metrics every quarter, per the chair's request |
| Annually | Full board | Posture trend, results against the day-90 commitments, year-two ask |
Plus one rhythm this company needs: a monthly launch-security checkpoint with Product until the stored-credential launch ships.
Phase 3 outputs
- Day-90 readout delivered day 88. The chair's response: "This is the first one I can compare to next quarter's."
- Operating rhythm booked as recurring calendar items with named owners.
- Year-one roadmap: ranking agreed; the $1.4M ask enters the budget cycle pre-socialized. The comp correction was pulled forward and approved early (the detection engineer stayed). The remaining gap, the second appsec hire, is explicitly accepted by the CFO until the cycle closes, in writing, in the 1:1 notes.
Why this works: "The gap explicitly accepted by name" is the most-skipped output in the template. In practice it is not a confrontation, just a sentence in shared meeting notes saying who accepted which risk until when. It costs nothing on the day and is worth everything when the accepted risk materializes.
The interview one-pager, written for Northwind
Built ONLY from outside information (public filings-equivalent reading, the security job postings they left up, a prospect's public complaint that surfaced the SOC 2 status). One page. Presented only when asked or when the conversation opens the door.
My first 90 days at Northwind Commerce: working plan, built from the outside
What I believe from the outside (assumptions, stated as such):
- Your revenue is transaction-based, so your crown jewels are the payment flow, checkout uptime, and the customer data platform, roughly in that order of visibility and the reverse order of current risk.
- You carry full PCI scope and a recent SOC 2 with findings, which means your next insurance renewal and your enterprise sales questionnaires are pulling on the same controls at the same time.
- The team has been unled for a stretch, so the first risk I'd check is not technical: it's retention.
Days 1–30: Listen. Eleven structured conversations (CEO through the previous CISO if reachable), a crown-jewel inventory, and an inherited-commitments list: audit remediations, merchant contract promises, insurance conditions. No reorg, no purchases, no strategy announcements.
Days 31–60: Prioritize. A risk list ranked in revenue and contract terms, walked past the CFO and GC individually before any group sees it. One scoped budget ask with a definition of done. One or two quick wins visible outside security, ideally removing friction rather than adding control.
Days 61–90: Deliver. A four-section readout to the audit committee: what I found, what could hurt us, what I'm doing in what order, what it costs. Install a reporting rhythm the committee can compare quarter over quarter.
What I won't do in the first 90 days: reorganize the team, replace the stack, or promise a full risk assessment by day 30.
The caveat, said out loud: "This is my plan given what I can see from the outside. The first 30 days exist to find out where it's wrong, and I'd expect the version I show you at day 45 to be different in at least one important way."
Why this works: The one-pager makes three specific, checkable claims about THEIR business, then explicitly bounds its own confidence. Specificity plus stated uncertainty is what panels read as seniority: certainty from the outside reads junior, vagueness reads unprepared. Notice it never cites the inside facts the full example relies on. Never claim inside knowledge you cannot have.
Northwind Commerce is fictional; all names, figures, findings, and events in this document were invented for illustration.
© CISO Prep · cisoprep.com · Part of the CISO Interview Template Pack.