Role-play

Pretend you are the CISO

Pretend you are the CISO so soft residual-risk language and heroic control stories fail before a board, insurer, or enterprise buyer absorbs them.

Optimistic security packages optimize for "we have a program." The CISO seat does the opposite. It asks which residual risk was accepted without a named owner, which control is described but not sampled, which vendor concentrates access without a tested exit, and which incident path would blind logging for hours. A fluent risk memo is not evidence that the program can survive a careful read under pressure.

This is a core move in a vendor, architecture, or go-to-market war game: after you describe the upside, seat a careful CISO perspective and make it try to decline. The output you want is a short list of material objections, the exhibits each needs, and the edits that would survive them.

Mandate and constraints

Name a real mandate: protect customer data, keep production recoverable, underwrite a change without silent gaps, or defend a board claim without inventing maturity. Give constraints: the threat model frame you will honor, the evidence standard for controls, and the residual risk you will not invent away. Without constraints the seat becomes cartoonish. With constraints it produces questions you might actually hear in an audit, insurance renewal, or enterprise security review.

Write the seat into the prompt as a named role with a mandate. Example: "CISO: list the top reasons to delay this change, the claim with the weakest control evidence, the blast radius that worries you most, and the ten diligence questions you would send after review. Stay inside a realistic mandate and avoid illegal tactics."

Outputs that count

  • Top reasons to challenge, delay, or reject this package.
  • The claim that looks strongest and is least evidenced.
  • The incident, abuse, or concentration path that would worry you most.
  • What would make you accept residual risk in writing.
  • The ten hardest diligence questions you would send after the meeting.

Run that brief in Pingpong against the real architecture notes, control inventory, vendor exhibits, and board language. Follow with a home-team response pass so you leave with edits and source packs, not only fear. When the decision is a customer-facing security claim, run this seat after product and legal attacks so it can use earlier objections as ammunition.

When the plan leans on a single identity provider, a single region, or a single on-call owner, force the seat to price concentration risk in writing. Ask what happens if that owner is unavailable, if the provider has an outage, or if sampling finds gaps. Concentration that only appears in an appendix still counts. Pair with war-game a security questionnaire, pretend you are the security lead, stress-test a security incident response, pretend you are the regulator, and the war-game decisions hub. See how to run a Pingpong.