Post-incident recovery
You took the job because the previous CISO was fired after a breach.
A 500-employee SaaS firm three months after a public S3 leak. Board confidence is low, the team is exhausted, and Y1 budget is half-spent on remediation. Stabilize first; rebuild trust quarter by quarter.
What is the Post-incident recovery scenario?
A 500-employee SaaS firm three months after a public S3 leak. Board confidence is low, the team is exhausted, and Y1 budget is half-spent on remediation. Stabilize first; rebuild trust quarter by quarter. Incoming CISOs after a public breach typically have 90 days to demonstrate control to a skeptical board. The first-quarter priority is detection visibility and stakeholder communication, not new product purchases — boards want to see the existing environment understood before additional spend is approved.
How does the Post-incident recovery scenario start?
- Difficulty: standard
- Tech profile: Cloud-Native SaaS
- Region: US
- Starting team: 1 ciso, 1 senior, 1 junior, 1 grc
- Year-1 budget: $550k
- Annual budget growth: 18%
- Starting board confidence: 25 (overridden)
- Starting morale: 35 (overridden)
How do you win the Post-incident recovery scenario?
Inherited team, depleted budget, suspicious board. Board ≥ 50 by Q4 or you don't reach Y2.
Which risks matter most in Post-incident recovery?
- R01 RansomwareExternal · severity 10
- R06 Supply Chain CompromiseExternal · severity 9
- R07 Zero-Day ExploitationExternal · severity 9
- R20 Recovery Failure (post-breach)Resilience · severity 9
- R29 Regulatory Fine / DPA ActionGovernance · severity 9
- R44 OSS Maintainer Takeover / Hostile ForkExternal · severity 9
Which investments are recommended for Post-incident recovery?
Strong starting purchases for this scenario, ordered by relevance:
- XDR Platform Suite (enterprise class)Platform
- Productivity Suite — Security TierPlatform
- Commercial SIEM (mid-market)SIEM
- Enterprise SIEM (heavy/full-featured)SIEM
- Cloud-based backupBackup
- Immutable backup + DR runbookBackup
How do you start playing the Post-incident recovery scenario?
Click Play CISO Game free to start a no-signup demo run. On the Setup screen, pick the Post-incident recovery tile and the difficulty, budget, and team will pre-fill. Hit Start Game and you're in.