Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Cyber Security
Cyber Security Risk Management and Incident Response
Updated 11 October 2026 · Fact-checked
Cyber security risk management is the process of identifying assets, assessing threats and vulnerabilities, rating risk, and treating it with controls. Incident response is the planned way to detect, contain, remove and recover from an attack, then learn from it. Answer by linking risk, controls, response and recovery.
Understand Cyber Security Risk Management and Incident Response
Cyber risk is the chance that a threat will exploit a weakness in an asset and cause loss. Loss may be financial, legal, operational or reputational. A simple way to hold it: risk depends on the threat, the vulnerability and the impact. Remove any one and the risk falls.
Risk management is a cycle, not a one-time task. You identify assets (data, systems, people, vendors), find threats and vulnerabilities, assess likelihood and impact, and rate each risk. Then you choose a treatment: mitigate (add controls), transfer (insure or outsource), avoid (stop the activity) or accept (record and monitor). What remains after controls is residual risk. The board should approve the risk appetite.
Security controls are the measures used to treat risk. By type they are preventive (access control, encryption, firewalls), detective (logging, monitoring, intrusion detection) and corrective (patching, restoring backups). By nature they are administrative (policies, training), technical and physical. A cyber security audit checks whether these controls exist, are designed well and actually work. It covers policy review, access reviews, vulnerability assessment, penetration testing and evidence checks, and ends with a report and follow-up on findings.
Incident response (IR) starts from the assumption that some attacks will succeed. A written plan names who decides, who acts and who informs. The usual phases are preparation; detection and analysis; containment; eradication; recovery; and post-incident review. Incidents must also be reported where the law requires, for example to CERT-In under the directions issued under the Information Technology Act, 2000.
Business continuity planning (BCP) keeps critical business functions running during a disruption. Disaster recovery (DR) is the narrower plan to restore IT systems and data. Cyber insurance transfers part of the financial loss, such as response costs and third-party claims, but it does not replace controls. The company secretary supports all this through governance: board reporting, policies, compliance tracking and records.
Key rules to remember
- Risk relationship
- Risk = Threat × Vulnerability × Impact
- A conceptual model, not an exact calculation. Reducing any factor reduces risk.
- Quantitative risk rating
- Risk score = Likelihood × Impact
- Used in risk matrices, for example 4 × 5 = 20 on a 5-point scale.
- Residual risk
- Residual risk = Inherent risk − Risk reduced by controls
- Conceptual. Residual risk must fall within the board's risk appetite.
- Risk treatment options
- Mitigate | Transfer | Avoid | Accept
- Name the option and give a reason for each risk.
- Incident response phases
- Preparation → Detection and analysis → Containment → Eradication → Recovery → Post-incident review
- Some models merge containment, eradication and recovery into one phase.
- Recovery targets
- RTO = maximum acceptable downtime; RPO = maximum acceptable data loss (measured in time)
- They drive BCP and DR design and backup frequency.
How to solve Cyber Security Risk Management and Incident Response questions
Use this order for any theory or case question on cyber risk, audit, incident response or continuity.
- 1Read the facts and mark the asset, the threat, the weakness and the loss.
- 2Name the concept being tested: risk assessment, control, audit, IR, BCP/DR or insurance.
- 3State the definition or provision in one or two lines.
- 4Apply it to the facts: rate the risk, pick a treatment, or place the event in an IR phase.
- 5List specific actions in order, with the person responsible, such as the CISO, IT team, board or company secretary.
- 6Add legal and compliance points, such as reporting to CERT-In and recording board decisions, only where you are sure of them.
- 7Close with a clear conclusion and a preventive step.
Quickest way: Asset–Risk–Control–Response
When to use it: Use for short answers and case questions when time is tight.
- Write the four headings: Asset, Risk, Control, Response.
- Fill each with one or two facts from the question.
- For incidents, list the phases in order and tick the one the facts are in.
- For BCP versus DR, state scope: whole business versus IT systems.
- Finish with the company secretary's role: policy, board reporting, compliance record.
Common mistakes in Cyber Security Risk Management and Incident Response
Treating BCP and disaster recovery as the same thing.
Both deal with disruption and are often discussed together.
Fix: Say BCP covers all critical business functions and people; DR is the IT part that restores systems and data.
Listing IR phases but not applying them to the facts.
Students memorise the list and stop.
Fix: For each phase, write what the company should do in the given case.
Jumping to controls without assessing the risk first.
Students know controls well and skip analysis.
Fix: Identify the asset, threat, likelihood and impact before proposing treatment.
Claiming cyber insurance removes the risk.
Transfer is confused with elimination.
Fix: State that insurance transfers financial loss only. Reputation, legal duties and recovery effort remain.
Confusing an audit with a vulnerability scan or penetration test.
All three test security.
Fix: An audit is a broad review of policy, design and operation. Scans and penetration tests are technical tests within it.
Ignoring reporting duties and the company secretary's role.
Students treat the topic as purely technical.
Fix: Add board escalation, documentation, and statutory reporting such as to CERT-In, as part of the response.
Worked examples
Example 1
Aarav Textiles Ltd. finds that an employee's laptop is infected with ransomware and files on a shared server are being encrypted. Explain the steps the company should take under an incident response plan.
Show the solution
- Detection and analysis: confirm the alert, identify affected systems, and classify the incident by severity. Start an incident log with times and actions.
- Containment: isolate the laptop and the server from the network, disable compromised accounts, and block the malicious traffic.
- Eradication: remove the malware, close the entry point (for example a phishing email or unpatched software) and reset credentials.
- Recovery: restore data from clean backups, test systems before returning them to use, and monitor closely for reinfection.
- Reporting: escalate to senior management and the board, and report to CERT-In within the time required by its directions. Inform affected parties where required.
- Post-incident review: record the root cause, update the plan, retrain staff and strengthen backups.
- Company secretary: ensure board minutes record decisions, and that the compliance record is complete.
Answer: The company should detect and classify, contain by isolation, eradicate the malware and root cause, recover from clean backups, report as required, and review lessons, with the board kept informed and records maintained.
Example 2
Distinguish business continuity planning from disaster recovery, and explain how a company secretary can support cyber risk management in a listed company.
Show the solution
- Business continuity planning: an organisation-wide plan that keeps critical functions running during a disruption, covering people, premises, suppliers and processes. It is built on a business impact analysis.
- Disaster recovery: a part of continuity that restores IT systems, applications and data after an outage or attack, guided by RTO and RPO.
- Difference: BCP asks how the business keeps operating; DR asks how the systems come back. DR supports BCP.
- Governance support: help the board adopt a cyber security policy and define risk appetite.
- Reporting and oversight: put cyber risk on the board and risk committee agenda and record decisions in minutes.
- Compliance: track applicable legal and regulatory requirements, including incident reporting, and keep evidence.
- Assurance: coordinate audits, follow up on audit findings and check that the BCP and incident plans are tested.
Answer: BCP keeps the whole business functioning; DR restores IT systems and data as one component of it. The company secretary supports risk management through policy adoption, board reporting, compliance tracking, audit follow-up and records.
Exam tips
- Structure answers as definition, application, conclusion. Cases reward application to the given facts.
- Draw the IR phases as a numbered sequence and tie each to an action in the case.
- Always give the BCP versus DR scope difference in one line when either is asked.
- Mention the company secretary's governance role in any answer on policy, audit or board oversight.
- Cite a statutory provision or reporting duty only where you are sure of it; otherwise describe it in plain words.
Practice questions from Cyber Security
- A forensic investigator must collect evidence from a running server suspected of a breach. Following the order of volatility, which item sho…
- In digital forensics, what is the purpose of maintaining a chain of custody document for a seized mobile phone?
- Which of the following best describes 'two-factor authentication' as a cyber security control?
- In the standard incident response lifecycle followed in cyber security practice, which phase comes immediately after 'Detection and Analysis…
- Rohit, an employee of a Pune firm, uses a colleague's login credentials without permission and downloads confidential client files from the …
Cyber Security Risk Management and Incident Response in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Cyber Security Risk Management and Incident Response: frequently asked questions
What are the steps in cyber risk management?
Identify assets, identify threats and vulnerabilities, assess likelihood and impact, rate the risk, and choose a treatment: mitigate, transfer, avoid or accept. Then implement controls, monitor and review. The cycle repeats as the environment changes.
What are the phases of an incident response plan?
The common phases are preparation, detection and analysis, containment, eradication, recovery and post-incident review. Some frameworks group them into fewer phases, so use the model given in your study material and apply it to the facts.
What is the difference between BCP and disaster recovery?
BCP keeps all critical business functions running during a disruption. Disaster recovery is the IT-focused plan to restore systems and data. Disaster recovery is one part of business continuity.
How is a cyber security audit conducted?
The auditor defines scope, reviews policies, tests controls, checks access and logs, may use vulnerability assessment and penetration testing, and collects evidence. A report with findings and recommendations follows, and management tracks corrective action.
What is the role of a company secretary in cyber security?
The company secretary supports governance. This includes helping the board adopt policies, putting cyber risk on board agendas, tracking legal compliance and reporting duties, coordinating audits and maintaining records of decisions.