After a ransomware incident is contained, the CISO asks the analyst to brief executives on whether to fund better backups and segmentation. Which metric set should the analyst present?
Select an answer to reveal the explanation.
Short Explanation
Think of an executive brief like a budget pitch: they care what the incident cost and what fix saves money. You don't win them over with tactic counts or packet stats; you show downtime cost, customer impact, and closed control gaps. That's how you turn SOC work into funding.
Full Explanation
Executive incident reporting exists to translate technical containment into business decisions. The useful metric set connects measurable operational loss, customer-facing consequences, and concrete control improvements because those three elements answer what happened, how much it hurt, and what investment prevents recurrence. Downtime cost and customer impact quantify risk realized, while control gaps closed demonstrate that remediation reduced future likelihood or impact. Tactic counts, alert volume, and mean time to detect remain valuable for detection tuning and analyst workload, but they do not show financial or mission consequences. Ticket counts, headcount, and scanner license utilization measure team productivity and tool consumption, not whether controls improved resilience. Raw SIEM event counts, blocked IP addresses, and average packet size are low-level telemetry indicators; they can be noisy and do not map to business outcomes. Exam caveat: when a question asks for executive or strategic reporting, prioritize business impact, cost, and control improvement over SOC activity metrics. Operational check: convert outage hours, affected records or services, and remediation spend into a one-page table with owner and follow-up control.