Skip to content

FRM Part II · FRM Exam Part II

Case Study: Cyberthreats and Information Security Risks: formula sheet

Full chapter guide

Key formulas

CIA triad
Confidentiality + Integrity + Availability
Map each attack to the property it breaks. Ransomware: availability (and confidentiality if data is stolen). Data theft: confidentiality. Tampering with records: integrity. DDoS: availability.
Actor to motive
Criminals → profit; Nation-states → espionage/disruption; Hacktivists → ideology; Insiders → grievance, gain or error
This is a general pattern, not a strict rule. Actors can overlap, and attribution is often uncertain.
Phishing vs malware
Phishing = deception of a person; Malware = malicious code
Phishing often delivers malware, but the two are different things.
Basel operational risk link
Cyber event → external fraud / internal fraud / business disruption and system failures
Which category fits depends on who acts and what is affected. An attack by an outsider is usually external fraud; a malicious employee is internal fraud.
Confidentiality
Confidentiality = only authorised access to information
Breach examples: data theft, leaked customer records, phishing credential capture.
Integrity
Integrity = accuracy and completeness, no unauthorised change
Breach examples: altered payment instructions, tampered ledgers, corrupted data.
Availability
Availability = authorised access when needed
Breach examples: ransomware lockout, DDoS, system outage, failed recovery.
Basel operational risk definition
Operational risk = loss from inadequate or failed processes, people and systems, or from external events
Includes legal risk. Excludes strategic and reputational risk.
Expected operational loss (frequency-severity)
Expected annual loss = expected number of events × average loss per event
Use it to compare cyber scenarios. Assumes frequency and severity are independent.
Kill chain order
Reconnaissance → Initial access → Privilege escalation → Lateral movement → Data theft or disruption → Cover tracks or extort
Use it to place each case fact at the right stage and pick a control for that stage.
CIA triad
Confidentiality, Integrity, Availability
Data theft hits confidentiality, fraudulent payments hit integrity, ransomware hits availability.
Control types
Preventive, Detective, Corrective (response and recovery)
Match the failed control to its type. Many cases show detection failing even when prevention is partly in place.
Shared responsibility rule
Provider secures the cloud; customer secures what it configures and deploys in the cloud
Customer misconfiguration is not the provider's failure.
Total incident loss
Total loss = direct loss + response and remediation cost + legal and regulatory cost + reputational and business loss
A conceptual breakdown. Reputational loss is hard to measure.
NIST Cybersecurity Framework functions
Identify → Protect → Detect → Respond → Recover
Core functions. Newer versions add Govern. The functions run continuously, not as a strict one-time sequence.
CIA triad
Confidentiality, Integrity, Availability
The three properties of information security that controls aim to protect.
Three lines of defense
1st line: owns and manages risk | 2nd line: oversees and challenges | 3rd line: independent assurance
Internal audit is the third line. Risk management is the second line, not the first.
Control types
Preventive (Protect) | Detective (Detect) | Corrective (Respond, Recover)
A useful mapping to NIST functions, not a strict rule.
Residual risk
Residual risk = Inherent risk − Effect of controls
Conceptual relationship used in risk assessment; controls reduce but rarely eliminate risk.
Incident response lifecycle
Prepare → Detect and analyse → Contain → Eradicate → Recover → Learn
Order matters. Containment comes before eradication, and recovery only after the threat is removed.
RTO
RTO = maximum tolerable time to restore a service after disruption
A time-to-restore target. It drives choices such as hot, warm or cold standby.
RPO
RPO = maximum tolerable data loss, measured as time back to the last good copy
Backup or replication interval must be no longer than the RPO.
Impact tolerance
Impact tolerance = maximum disruption to a critical service the firm will accept
A resilience concept. Recovery targets should sit inside it.
Relationship check
Backup interval ≤ RPO; actual restore time ≤ RTO ≤ impact tolerance
Use to test whether a design meets its targets.
Annualised loss expectancy
Expected annual loss = Loss event frequency × Loss magnitude per event
Use expected values per year. Frequency is events per year, magnitude is the average cost per event.
FAIR loss event frequency
Loss event frequency = Threat event frequency × Vulnerability
Vulnerability is the probability that a threat event becomes a loss event, given the strength of controls.
FAIR loss magnitude
Loss magnitude = Primary loss + Secondary loss
Secondary loss includes fines, legal costs and stakeholder reactions.
Net loss after insurance
Net loss = Gross loss − Insurance recovery, where recovery = min(max(Gross loss − Retention, 0), Policy limit)
Apply the retention first, then cap at the limit. Check for exclusions and sub-limits.
Residual risk
Residual risk = Inherent risk − Effect of controls and risk transfer
A conceptual relationship, not an exact arithmetic subtraction in every framework.

Quick revision

  • Cyber risk is a type of operational risk: loss from people, processes, systems or external events.
  • CIA triad: confidentiality (no unauthorised disclosure), integrity (no unauthorised change), availability (access when needed).
  • Ransomware mainly attacks availability; data theft mainly attacks confidentiality; tampering mainly attacks integrity.
  • Threat actors differ in motive: criminals seek money, state actors seek strategic goals, insiders may act from grievance or error.
  • Preventive controls stop events, detective controls spot them, corrective controls limit damage and restore.
  • Defence in depth uses several layers so one failure does not cause a breach.
  • Weak access management and slow patching are repeated causes of control failure in cases.
  • Third-party and supply chain links extend your risk beyond your own systems.
  • Incident response runs from preparation and detection through containment, recovery and lessons learned.
  • Recovery time objective is how fast service must return; recovery point objective is how much data loss is tolerable.
  • Cyber loss estimates combine event frequency and severity, but limited data makes them uncertain.
  • Good governance means board oversight and clear ownership of cyber risk, not only IT ownership.

Common mistakes

  • Treating phishing as a type of malware. Fix: Phishing is social engineering aimed at a person. Malware is code. Phishing is a delivery route.
  • Saying ransomware only affects availability. Fix: Remember double extortion: stolen data also breaches confidentiality.
  • Treating cyber risk as a separate Basel risk category. Fix: Remember it is a cause of operational risk loss. Losses fall in event types such as external fraud or business disruption and system failures.
  • Calling ransomware only a confidentiality breach. Fix: Locked systems are an availability failure. Add confidentiality only if data was also exfiltrated.
  • Blaming the cloud provider for a customer misconfiguration. Fix: Apply shared responsibility: the customer owns its configuration, identity and access settings.
  • Treating the breach as one event instead of a chain. Fix: Walk the kill chain and note which control would have broken each link.
  • Placing internal audit in the second line or giving it control ownership. Fix: Audit is the third line and gives independent assurance. It must not own or run controls.
  • Treating NIST functions as a strict one-time sequence. Fix: The functions run concurrently and continuously. Lessons from Recover feed back into Identify and Protect.
  • Mixing up RTO and RPO. Fix: RTO is how long you can be down. RPO is how far back your data can go. Ask: restore time or lost data?
  • Restoring systems before containing the threat. Fix: Contain and eradicate first. Restoring into a compromised environment lets the attacker return.

Exam tips

  • Practise telling method from actor. Many wrong options swap the two.
  • Link each scenario to a CIA property. It quickly removes options.
  • Be wary of absolutes such as always, only or never about actors and motives.
  • Expect cases that mention cloud, third parties or AI. Treat these as new routes for the same threat types.
  • Connect threats to Basel operational risk event types when the question asks for classification.
  • Name the CIA property first. Most options differ only by which property they pick.
  • Watch for scenarios that breach two properties, such as ransomware with data theft.
  • Remember that Basel operational risk includes legal risk but excludes reputational and strategic risk.