Study material Exam simulator CISO briefing Log in Create account Back to csisc.co.uk

CSISC Training — CCISO exam preparation

Prepare for CCISO the way a board expects a CISO to think.

Study guides, original scenario-based practice exams and a timed online simulator covering all five CCISO domains. Every question comes with a full explanation of why the right answer is right, and why the others fall short.

Original questions, not braindumps · Instant access after payment · Prices include UK VAT

Built for security leaders, not crammers

Learn the domains, rehearse the sitting, and know when you’re ready.

The CCISO exam tests judgement at executive level: risk ownership, budgets, audit and governance. Our material is written in that register, with scenarios a working CISO will recognise.

Learn each domain

A study guide organised by the five CCISO domains, with worked examples of the risk and finance calculations the exam expects.

Rehearse the real sitting

Timed mock exams at the official pace of one minute per question, with flag-for-review and a domain-by-domain score.

Know you’re ready

Your library tracks every attempt and shows your weakest domain, so revision goes where it counts.

Covers all five CCISO domains
D1Governance & RiskD2Controls & AuditD3Programme & OperationsD4Core CompetenciesD5Strategy & Finance

Study material

Everything you need for the exam, nothing you don’t

Every practice question is original and scenario-based, written to the CCISO body of knowledge, with a full explanation for each answer. Your PDFs and simulator access appear in your library as soon as payment completes.

BundleBest value

CCISO Complete Pass Bundle

Every product below in one purchase, with 12 months of simulator access.

  • Study guide, practice pack and flashcards (PDF)
  • The Boardroom CISO eBook
  • 600-question online simulator, 12 months
£149£235
PDF

CCISO Study Guide

A domain-by-domain guide written for working executives, with worked examples of risk and finance calculations.

  • All five domains
  • End-of-chapter review questions
  • Formula sheet for ALE, ROSI, EVM
£49
PDF

Practice Exam Pack

Four full-length 150-question practice exams with answer keys and a full explanation for every question.

  • 600 original scenario questions
  • Explanations for right and wrong options
  • Domain tags for targeted revision
£59
Online

Exam Simulator, 90 days

The timed online simulator with the full question bank, randomised exams and progress tracking.

  • Exam and practice modes
  • Domain score reports
  • Unlimited attempts
£79
PDF

Domain Flashcards

Printable cards covering key terms, frameworks and formulas for last-week revision.

  • 320 cards across five domains
£19
eBook

The Boardroom CISO

A practical handbook on security strategy, budgets and board communication, for the job after the exam.

  • Board report templates
  • Budget and business case examples
£29

The CCISO exam at a glance

150
Multiple-choice questions in a single sitting
2.5h
Exam duration, so roughly one minute per question
5
Domains assessed, from governance to finance
60–73%
Cut score, which varies by exam form

Exam format as published by EC-Council. Check eccouncil.org for current eligibility and exam requirements before you book.

Online exam simulator

Rehearse the real sitting

Exam mode mirrors the live test: one question at a time, a countdown, flag-for-review and a score report by domain. Practice mode shows the explanation as soon as you answer. This free demo holds 25 questions. Full access unlocks the complete bank.

Loading the simulator…

CISO briefing

What the role asks of you, domain by domain

Short, practical notes for working security leaders. Each maps to a CCISO domain, so reading for the job is also revising for the exam.

D1 · Governance

Reporting cyber risk to the board

Lead with business impact, not control counts. Frame each top risk as likelihood, impact in pounds, current treatment and the decision you need from directors.

  • Keep the board-level register to 8–12 risks
  • Show trend, not just status
  • State the residual risk the board is accepting
D5 · Finance

Building a budget the CFO will sign

Tie each line to a risk it reduces and quantify the reduction. Separate run costs from change projects and show three-year total cost of ownership.

ROSI(ALE reduction − cost) ÷ cost
ALESLE × ARO
SLEAsset value × EF
D3 · Operations

Ransomware: the first hour

Confirm, contain, communicate. Isolate affected segments before you investigate root cause, preserve evidence, and activate the communications plan agreed in advance with legal.

  • Know who can authorise taking systems offline
  • Test restore times against your RTO
D2 · Audit

Turning audit findings into a programme

Accept findings on the facts, then agree the remediation plan: owner, target date, interim compensating control. Track closure as a measure the audit committee sees.

D4 · Core competencies

Zero trust without the slogans

Start with identity: strong authentication everywhere, least privilege, and per-request authorisation using device and context signals. Segment the crown jewels first.

D5 · Vendors

Third-party risk that scales

Tier suppliers by data access and business criticality. Put right-to-audit, breach notification and exit terms into the contract before signature, while you still have leverage.

Tier 1 reviewAnnual + on change
Tier 2 reviewEvery 2 years
Tier 3 reviewAt onboarding
Illustration of a checklist representing exam readiness

From CSISC

Need security leadership now, not after the exam?

The certification proves the knowledge. The board still needs someone accountable for security today.

CSISC places Executive Cyber Leaders inside UK organisations: setting strategy, managing risk and reporting to the board, without the cost of a full-time hire.

Start with 25 free questions.

No account needed. See how the simulator works and where you stand across the five domains.