The Template Pack · free

CISO Tabletop Walkthroughs: Breach, Budget Cut, M&A

Three fully worked scenario responses, from the first 60 seconds to the last curveball, so you walk into the live round having already run it.

Free, no paywall · part of the CISO Interview Template Pack


How to Use This Document

These are practice walkthroughs built for rehearsal, not transcripts of real interviews or incidents. Work each scenario three times: read it, say the opening out loud with a timer, then have someone throw the curveballs at you mid-answer. Internalize the openings almost verbatim; improvise inside the frame after that. One rule governs all three: the panel is not grading your answer, it is grading what it would feel like to sit next to you when the thing actually happens.


Scenario A: Ransomware, the First 24 Hours

1. The prompt as panels phrase it

  • "It's 2am. Your on-call lead calls: ransomware has encrypted roughly 30% of endpoints and it's still spreading. Walk us through your first 24 hours."
  • "You wake up to a ransom note on the SOC channel and half of manufacturing is down. What do you do, in order?"
  • "Our detection team just confirmed active ransomware in production. The CEO is asking you what happens next. Go."

The third variant puts the CEO in the first sentence; take the hint about what they want to hear first.

2. The first 60 seconds, word for word

"Before I touch containment, three things happen in the first fifteen minutes. First, I name an incident commander, and it is not me. My IR lead runs the technical bridge; my job tonight is decisions and communication, and if I'm on keyboard, nobody is doing that job. Second, general counsel gets on the phone now, so the investigation runs under privilege from minute zero, and I notify our cyber insurance carrier tonight, because their panel constrains which forensics firm we can even engage. Third, I start the clocks: a decision log from this moment, because everything will be reconstructed later, and a look at notification obligations, since some of those windows may already be running. Then the cadence: CEO briefed within the hour, executive updates every two hours, nobody outside the comms plan speaks externally. With that structure standing, here's what my IC is executing on containment."

Why this works. Four signals in one minute. Incident command before tooling says you know which chair you're interviewing for. Privilege before forensics tells the lawyer on the panel you've run a legal-driven response, and the insurance detail says you've lived a claim. The disclosure clock says you know a breach is a regulatory event from minute one. And a stated cadence says you know silence upward is what gets CISOs fired.

3. The full response arc

Hour 0-1: command and privilege. The opening above, then exactly two or three clarifying questions:

  • "Are we a public company?" Yes means a materiality assessment starts today and disclosure involves the CFO and disclosure counsel. No shifts the pressure to contractual notification and state statutes.
  • "Is the attacker still active?" Active means containment beats forensics; dormant buys evidence-preservation time.
  • "Is revenue flowing through the affected systems?" This sets what availability is worth: taking payment systems offline at a retailer is a CEO conversation; at an internal tools company it's your call.

If the panel declines to answer: "I'll assume public SaaS, attacker still active. Flag me if that's wrong."

Hour 1-4: containment at altitude. Narrate what the IC executes, in one breath: isolate segments, kill the spread vector, preserve evidence before wiping anything, verify backups offline before trusting them, establish blast radius including identity, because owned domain controllers change the whole recovery plan. Decision you own: "I take systems offline proactively ahead of the spread and inform the CEO. I don't ask permission, because waiting costs more than the outage."

Hour 4-12: the business track. Where most candidates go quiet and lose the round. CFO on financial exposure and insurance mechanics, GC on notification analysis and law enforcement, comms on a holding statement drafted before anyone asks. State the boundary: "Technical containment is mine. Money, disclosure, and external words go to the CEO and GC, with my recommendation attached."

Hour 12-24: recovery posture and the first honest status. Restore order comes from the business, not IT convenience: crown-jewel tiering, or a triage of one tonight. End of day one: a written status with what we know, what we don't, and the next three decisions coming at the executive team. That last phrase is the most senior sentence you can say.

4. The whiteboard move

Draw three swim lanes, Technical, Legal/Regulatory, Communication, with a time axis marked 1h, 4h, 12h, 24h. The IC's name goes on the technical lane, yours spans all three. Draw a vertical line at each decision point that crosses lanes (ransom demand, disclosure call, proactive shutdown). The picture argues without words: the CISO's job is the vertical lines, not the top lane.

5. Curveballs and answer shapes

"The backups are encrypted too." Do not improvise a miracle. Shape: this changes the recovery math, so it changes who's in the room. Rebuild-from-scratch goes on the table next to the ransom option, the CFO prices the outage per day, and the ransom conversation is now live. You updated the plan out loud instead of defending it, which is the actual test.

"The CEO wants to pay the ransom." Never give a personal verdict. Shape: payment is a business decision the CEO can make; your job is to make it informed. Bring recovery time with and without the key, the sanctions screen from GC (paying a sanctioned entity is a federal problem that outranks the outage), the carrier's position, and the note that a decryptor does nothing about exfiltrated data. "My job was the briefing, not the veto."

"A journalist emailed asking about an outage." Shape: handled at hour four, which is why the holding statement exists. Comms sends it, nobody confirms specifics, and GC hears within the hour that public attention may accelerate the disclosure decision.

6. Failure modes, bluntly

  • You opened with EDR isolation steps. The panel hired a Director in their heads and stopped listening. Tooling first is the number one killer here.
  • You recited "activate the IR plan" four ways and made zero decisions. Process talk without ownership reads as never having been in the seat.
  • You never mentioned the CEO until forced. First upward communication at hour twelve means you were already fired in the panel's imagination.
  • You froze or got defensive on the backups curveball. Panels score the injection more heavily than the opening; losing structure there erases everything before it.

7. Self-scoring rubric

Dimension What a 1 sounds like What a 5 sounds like
Structure Technical tasks in whatever order they arrived Named tracks, a time axis, decision points flagged before the panel injects them
Business framing Encryption percentages and tool names Revenue exposure, disclosure obligations, recovery cost per day
Decision ownership "It depends," "we'd follow the process" "That call is mine, made" versus "that goes to the CEO with my recommendation"
Communication discipline CEO mentioned once, reactively Cadence set in minute one: CEO in the hour, execs every two hours, one external voice
Composure A pause, or a defense of the old plan "That changes X, so the plan is now Y," at the same tempo as everything else

Scenario B: The 20% Budget Cut

1. The prompt as panels phrase it

  • "The company missed its number. Every function is taking a cut and security's is 20%. What goes?"
  • "The CFO needs 20% out of your budget by Friday. Walk us through how you'd decide."
  • "New reality: your budget is 80% of what it was. Rebuild the program on that number."

All three are the same test: do you cut by risk or by politics, and are you an executive peer or a department defending turf. Expect a finance leader in the room, and assume they are the real audience.

2. The first 60 seconds, word for word

"First, I'm not going to argue with the number. The company needs the money, and my job is to find the 20% that buys back the least risk, not to relitigate the cut. Second, here's how I'll decide, because the method matters more than the line items. Tool consolidation and vendor renegotiation come first because they're reversible. Program deferrals come second, each with a named risk that moves into next year. Headcount comes last, and if it comes, I'll tell you exactly what stops being done rather than pretending the same coverage continues with fewer people. Third, every option comes with a consequence in business terms and a residual risk I'll ask this executive team to formally accept. Two questions, then actual cuts."

Why this works. The first sentence disarms the trap: defending the budget. The finance person has heard "we're already underfunded" from every security leader they've met; not saying it is itself a signal. The cut hierarchy (reversible first, headcount last, consequences attached) is a method they can imagine surviving next year's cut too. And "formally accept the residual risk" separates executives from managers: you price risk, you don't absorb it silently.

3. The full response arc

Minute 1-3: clarifying questions.

  • "Is this a one-year cut or the new baseline?" A one-year cut makes deferrals honest; a new baseline makes them lies with a delay, and the answer has to restructure, not postpone.
  • "Are we cutting dollars or headcount specifically?" Dollars means vendor money can save people; heads means your third tier moves up, and you say so plainly.
  • "Is the company in survive mode or growth mode?" Survive mode justifies cutting things that slow the business; growth mode means customer-facing security work is last to touch, because it carries revenue.

Minute 3-10: the cut, in tiers. Proportions, not real figures: "Tier one, roughly half the target: consolidate overlapping tools, renegotiate the two biggest renewals, cut shelfware. Tier two, another third: defer program work that's important but not time-bound, naming the risk each deferral creates. Tier three, if the math forces it: headcount, and here is the specific work that stops." The percentages don't need to be exact; the ranked structure with consequences does.

Minute 10-15: the protect list and the ask. Name one or two asymmetric line items you'll fight for: "The IR retainer stays. It's small money and its absence is catastrophic on the worst day. I'll cut awareness tooling before detection engineering, because one is a checkbox and the other finds the breach." Then the close: "Here's my recommendation. It creates two named residual risks, and I want the executive team to accept those explicitly, on the record, because that acceptance is the company's decision." The CFO is in this continuously; the CEO comes in only for formal risk acceptance and any cut touching a board-level commitment. Say that decide-versus-escalate line out loud.

4. The whiteboard move

Draw a two-by-two: cost saved against risk created. Place your cut candidates in the quadrants live, talking while you place them. High savings, low new risk is tier one; low savings, high risk is your protect list, and you circle it. The picture shows the finance leader you think about their money the way they do, and gives the room a shared object to argue with.

5. Curveballs and answer shapes

"Actually, the CFO wants 30%." Shape: the method holds, the tiers cut deeper, the conversation changes character. "At 20% I can protect the core. At 30% we're choosing between capabilities, so I'd bring the executive team two program-shaped options: which risk category does the company want to own next year?" Escalate the frame, not the fight.

"Your best engineer will quit if you cut their favorite tool." Shape: name the real issue, retention risk, and price it like everything else. Talk to the engineer first; don't pre-surrender the budget to a threat. A critical person is a data point in the risk column, not a veto.

"The board asks whether the company is less safe after this cut." Shape: yes, and here is exactly how much. "We accepted two named risks. Here's the compensating control for each and the trigger that would make me ask to reverse the cut." Never say the cut is free. A CISO who says a 20% cut changed nothing just told the board the budget was 20% padding.

6. Failure modes, bluntly

  • You defended the budget. "A cut would be irresponsible" is the fastest fail here. Every panel already has a security team telling them this; they are interviewing for someone who doesn't.
  • You listed tool names at a finance leader. Wrong vocabulary even when the cuts are right. Risk and dollars, or you lose the one panelist this scenario was built for.
  • You volunteered cuts instantly with no consequences attached. The eager amputator reads as someone whose budget was padded all along.
  • You cut people without naming what work stops. Either dishonest or naive; the panel can't tell which, and both are disqualifying.

7. Self-scoring rubric

Dimension What a 1 sounds like What a 5 sounds like
Structure A grab bag of cuts in random order Tiers ranked by reversibility, consequences attached to every line
Business framing Tool names and headcount numbers Dollars saved against risk created, sales cycle impact, cost of the gaps opened
Decision ownership "Whatever the CFO prefers" "My recommendation is this; the residual risk needs your explicit acceptance"
Communication discipline A security team meeting register Vocabulary calibrated to the CFO, one protected line item argued in their terms
Composure The 30% curveball produces deflation or bargaining The method scales without a beat: deeper tiers, reframed choice, same tempo

Scenario C: The Acquisition Closing in Six Weeks

1. The prompt as panels phrase it

  • "We're acquiring a 300-person software company. The deal closes in six weeks. What do you do?"
  • "Corp dev just looped you in on an acquisition that's mostly done. Diligence access is limited and the close date is fixed. Where do you spend your time?"
  • "You have four weeks of pre-close access to a target's data room and one hour with their CTO. Go."

The second and third variants hand you the real constraint (limited access, fixed clock) that the first hides. If you get the first, surface those constraints yourself; it scores even better.

2. The first 60 seconds, word for word

"I'll split this at the close date, because pre-close and post-close are different jobs with different customers. Pre-close, my customer is the deal team, not the target's security posture. I have limited access and a fixed clock, so the output is not a remediation plan; it's material risk that affects price or terms, anything that belongs in reps and warranties, and an honest list of what we couldn't assess. Post-close, my customer becomes the integration, and day one is about identity boundaries and visibility, not remediation. Two workstreams. First, three questions, because the answers change the plan materially."

Why this works. The pre-close/post-close split, stated in the first sentence, is the whole exam in miniature: it shows you know diligence access is negotiated and time-boxed, the thing candidates who've never been inside a deal miss. "My customer is the deal team" tells the corp dev person you were invited to inform the transaction, not audit for its own sake. And "what we couldn't assess" signals honesty under constraint, which a deal team rarely gets from a security leader.

3. The full response arc

Minutes 1-3: clarifying questions.

  • "Is this an acqui-hire, a product tuck-in, or are we buying their platform and customers?" This reorders everything. Acqui-hire: the platform may be decommissioned, so deep product review is wasted time. Platform acquisition: their production posture is your breach surface on day one.
  • "What access do we have: data room only, questionnaires, or people?" Data room only means reading documents for what's absent. An hour with their security lead goes to breach history and key-person risk, not architecture.
  • "Will they run on a transition services agreement after close?" If the seller's IT runs the target for six months, you're securing a boundary with the seller, not absorbing an environment. Asking this unprompted is worth more than any other sentence here; most candidates have never heard the acronym.

Weeks 1-4, pre-close. Sequence what you can actually learn: external attack surface scan (no permission needed, start today), breach and disclosure history, their certification package read adversarially, scoping first, because a clean report that excludes the crown jewels you're buying is the red flag generic diligence misses. Key-person risk: if security is one person with no retention agreement, that goes on the deal team's issue list this week. Deliverable: "A short memo: material risks priced or papered, candidates for reps and warranties or escrow, and the couldn't-assess list. An active or undisclosed incident is not a memo, it's a same-day escalation to GC and the deal lead, because it can reopen price or terms." That is your decide-versus-escalate line.

Close to day 30. Day one is identity and access boundaries: you do not flat-connect the networks, you decide what federates and when. Their environment enters your monitoring before anyone remediates anything. Policy scoping is yours: incident reporting and admin access rules apply immediately; tooling standards get a grace period. A line worth using verbatim: "The first thirty days are visibility and containment of unknowns, not remediation. I can't prioritize fixes in an environment I can't see yet."

Day 30-90. Remediation, sequenced by the risk register, with owners and dates, plus a report back on whether pre-close estimates matched reality. Closing that loop is a move almost nobody makes and everyone remembers.

4. The whiteboard move

Draw one timeline with a bold vertical line at Close. Left of it, two rows: "What we can learn" and "What it feeds" (price, terms, reps and warranties, escrow). Right of it, three phases: Day 1 (identity boundaries, visibility), Day 30 (risk register complete), Day 90 (remediation with owners). The bold line does the arguing: two different jobs, and a place to physically point when a curveball tries to blur them.

5. Curveballs and answer shapes

"You find something bad. The acquisition closes anyway." Shape: your job was to inform the decision, not make it. The company can rationally close over a known problem if price or terms reflect it. Post-close, the finding jumps the day-one queue, its remediation cost attaches to the integration budget before close, and it's recorded as an accepted risk with a named owner. The test is whether you can lose an argument and still execute.

"The target had a breach two years ago and didn't tell us." Shape: same-day escalation, and be precise about why: nondisclosure in diligence is a trust and legal fact, not just a security fact. It can trigger renegotiation, escrow, or reps-and-warranties claims, so GC and the deal lead hear it within the hour, from you. Then the security question: what did they fix, and what else did they hide.

"Their security team quits at close." Shape: this was on your pre-close list as key-person exposure, which is why retention agreements came up in week one. If it happens anyway: their environment goes under your team immediately, an external retainer bridges the gap, and the lost knowledge becomes a named risk with a rediscovery plan.

"The CEO wants the products integrated in 30 days, not your 90." Shape: price the speed, don't resist it. "We can do 30. Here's what it skips, here's the exposure, and here's the minimum I won't compress: identity separation until their admin access is verified. If the business accepts that explicitly, we run the 30-day plan with compensating controls."

6. Failure modes, bluntly

  • You proposed a full pen test, architecture review, and complete vendor inventory pre-close. That's a quarter of work in a four-week window. The audit fantasy says you've never been inside a real deal, and nothing recovers from it.
  • You skipped pre-close and went straight to integration. Your highest-leverage work happens before close, when findings can still move price and terms. After close, you're just cleaning up.
  • You treated the deal as yours to block. "I'd recommend we don't close until..." is a security leader who doesn't know their altitude. You inform, price, and escalate. The deal team decides.
  • You flat-connected the networks on day one, or never mentioned identity. That one technical detail actually matters here, and skipping it undoes the executive polish everywhere else.

7. Self-scoring rubric

Dimension What a 1 sounds like What a 5 sounds like
Structure One undifferentiated list of security tasks A hard split at close, different customers and outputs on each side
Business framing Vulnerabilities and audit findings Price, terms, reps and warranties, escrow, and what the deal team does with each finding
Decision ownership Waits to be told what the deal team wants "Day-one boundaries are mine; an undisclosed incident is a same-day escalation to GC"
Communication discipline Same technical register for every audience Deal-team vocabulary pre-close, integration vocabulary post-close, TSA raised unprompted
Composure "It closes anyway" produces frustration or a lecture The finding moves to the day-one queue, gets an owner, the plan updates at full tempo

After the Run-Through

Score yourself against the fifteen rubric rows the day after you practice, not the same evening. Anything at 3 or below, rewrite in one sentence and say it out loud until it stops sounding rehearsed. Know the openings word for word; trust the structure enough to improvise everything else. That, not coincidentally, is also the job.

Want the whole pack?

All seven pieces are free to read here, or grab them as one download.

See all seven →Download all (HTML)

More from the pack

Free template

Steal the 90-Day CISO Plan

The exact 90-day plan structure hiring panels expect: the single asset every CISO candidate gets asked for. Free, editable, yours in one click.

Instant access, no confirmation hoops. Occasional emails on landing the seat; unsubscribe anytime.