Skip to content

FRM Part II · FRM Exam Part II

Cyber-resilience: Range of Practices: formula sheet

Full chapter guide

Key formulas

CIA triad
Confidentiality + Integrity + Availability
The three security objectives. A cyber event breaches at least one of them.
Cyber risk in Basel terms
Cyber risk ⊂ Operational risk
Operational risk is loss from inadequate or failed processes, people, systems or external events. It includes legal risk but excludes strategic and reputational risk in the Basel definition.
Security vs resilience
Resilience = Security (prevent) + Detect + Respond + Recover + Learn
A memory aid, not a regulatory formula. Resilience assumes breaches will happen.
Lifecycle of cyber resilience
Govern → Identify → Protect → Detect → Respond → Recover → Learn
Use as a checklist to place any control or action in the right phase.
Board role
Board = approve strategy and appetite + oversee + challenge
The board does not design or operate technical controls.
Appetite cascade
Risk appetite → risk tolerances → limits and KRIs
Appetite is broad; tolerances and KRIs are measurable and monitored.
Three lines of defense
1st line = own and manage; 2nd line = oversee and challenge; 3rd line = independent assurance
Internal audit is the third line and must stay independent of the first two.
Risk tolerance test
Actual metric ≤ tolerance → within appetite; actual > tolerance → escalate
Applies when a higher value is worse, such as hours of downtime.
Risk as a combination
Cyber risk = Threat × Vulnerability × Impact (conceptual)
A conceptual relationship, not a precise calculation. If any factor is near zero, risk is low.
Frequency-severity annual loss
Expected annual loss = Expected number of events per year × Average loss per event
Valid as an expected value when frequency and severity are treated as independent.
Residual risk
Residual risk = Inherent risk − Effect of controls
Conceptual. Inherent risk is before controls; residual is after controls.
Preventive vs detective
Preventive = before or during an attack (reduce likelihood); Detective = during or after (reduce dwell time and impact)
Classify by what the control does at the moment it acts, not by the tool name.
Penetration test vs red team
Penetration test = scoped, specific systems, usually announced; Red team = goal-based, realistic adversary, tests people, process and technology and defender response
Red teaming tests detection and response as well as technical weaknesses.
Vulnerability scan vs penetration test
Scan = automated, finds known weaknesses; Penetration test = manual exploitation to prove impact
A scan does not show whether a weakness can actually be chained into a breach.
Least privilege
Access granted = minimum needed for the role, for the time needed
Pair with periodic access recertification and privileged access management.
Defence in depth
Several independent layers, so one control failure does not cause a breach
Use it to justify combining preventive and detective controls.
Third-party risk lifecycle
Due diligence → contract terms → ongoing monitoring → exit planning
Accountability remains with the bank, not the provider.
Recovery time objective (RTO)
RTO = maximum acceptable time from disruption to restored service
Measures downtime tolerance. Actual recovery time must be ≤ RTO.
Recovery point objective (RPO)
RPO = maximum acceptable data loss, measured as time between the last good copy and the incident
Backup or replication interval must be ≤ RPO. It is about data, not time to restore.
Response sequence
Detect → Triage → Contain → Eradicate → Recover → Learn
Containment comes before eradication and recovery. Do not restore into a still-compromised environment.
Recovery must fit tolerance
Time to restore critical service ≤ RTO ≤ impact tolerance
Recovery objectives should sit inside the firm's tolerance for disruption of the critical operation.

Quick revision

  • Cyber resilience is the ability to keep delivering critical services through and after a cyber incident.
  • Prevention alone is not enough; assume some attacks will succeed and plan for recovery.
  • Governance means the board and senior management set direction, risk appetite and accountability.
  • Identify critical functions and the assets and data that support them before choosing controls.
  • Risk assessment links threats, vulnerabilities and potential impact.
  • Protection and detection controls work together; good protection without detection leaves breaches unseen.
  • Defence in depth uses layered controls so one failure does not expose everything.
  • Response plans need defined roles, escalation paths and communication to stakeholders.
  • Recovery planning should be tested regularly, not only written down.
  • Third-party and supply chain dependencies are part of your cyber risk.
  • Information sharing with peers and authorities improves collective defence.
  • Lessons from incidents and tests should feed back into strategy and controls.

Common mistakes

  • Treating cyber resilience and cyber security as the same thing. Fix: Security prevents and protects. Resilience also covers detection, response, recovery and learning, and assumes breaches happen.
  • Treating cyber risk as separate from operational risk. Fix: Under Basel it is a source of operational risk loss. Map it to event types such as external fraud or system failures.
  • Giving the board day-to-day control responsibility. Fix: The board approves, oversees and challenges. Management and the first line operate controls.
  • Treating internal audit as the second line. Fix: Audit is the third line and provides independent assurance. The second line sets the framework and challenges.
  • Confusing threat with vulnerability Fix: A threat is the actor or event; a vulnerability is the weakness it exploits.
  • Starting with all IT assets rather than critical services Fix: Begin with services the business cannot afford to lose, then map supporting assets.
  • Calling monitoring or logging a preventive control. Fix: Monitoring finds activity; it is detective unless it is an automated blocking tool. Check what the question says the control does.
  • Treating penetration testing and red teaming as the same thing. Fix: A penetration test is scoped and usually announced. Red teaming is goal-based, adversary-like and tests detection and response too.
  • Mixing up RTO and RPO Fix: RTO is about downtime. RPO is about lost data. Think T for time to restore, P for the point in time you go back to.
  • Restoring systems before containing the threat Fix: Contain and eradicate first, or the attacker may re-enter or destroy the restored data.

Exam tips

  • Expect scenario questions that test the distinction between security and resilience. Look for words like 'recover', 'critical services' and 'continue'.
  • Always link cyber to the Basel operational risk definition when asked about classification.
  • Reject absolute answers such as 'eliminate' or 'fully prevent'.
  • Remember why banks are targets: valuable assets, interconnection, technology dependence and systemic importance.
  • Third-party and shared-vendor dependence often appears as the feature that distinguishes cyber from traditional operational risk.
  • Memorise the three-line split and watch for options that blur independence.
  • Expect scenarios where a measured metric exceeds a tolerance. The answer is usually escalation.
  • Board answers are about approving, overseeing and challenging, not operating.