Skip to content

FRM Part II · FRM Exam Part II

Cyberthreats and Information Security Risks for FRM Part II

This chapter uses real cyber incidents to test how you think about information security risk. You learn threat actors, the CIA triad (confidentiality, integrity, availability), control failures, frameworks, incident response and quantification. To solve questions, identify the threat, the control that failed, and the best risk-based fix.

What this chapter covers

This chapter sits in the Operational Risk and Resilience topic of FRM Part II. It treats cyber risk as a form of operational risk. A cyber event is a loss from people, processes, systems or external events, and it can hit a bank's data, its payments and its reputation at once.

The chapter moves from the outside in. You start with who attacks and how. You then link attacks to the CIA triad: confidentiality, integrity and availability. Case studies show how weak controls let small gaps become large losses. After that you study the frameworks that organise controls, how firms respond and recover, and how they put numbers on cyber risk.

It connects to the rest of the paper in three ways. Operational risk measurement and resilience use the same loss-event thinking. Liquidity and market risk can be hit when a cyber event stops payments or trading. Current Issues readings on artificial intelligence and digital resilience extend the same ideas, so the vocabulary carries over.

Questions in this chapter are applied. You are given a scenario and asked which threat, control weakness or response step fits best. These are marks you can win by reasoning, not by memorising numbers. The ideas also overlap with operational risk, resilience and digital resilience readings, so one solid study effort pays off across several parts of the paper. Candidates who skip it as a soft topic often lose marks to precise wording, such as the difference between a preventive and a detective control, or between recovery time and recovery point.

Case Study: Cyberthreats and Information Security Risks: topics in the order to study them

  1. 1Cyber Threat Landscape and Threat ActorsStart here to learn who attacks, their motives and common attack methods, which every later topic builds on.
  2. 2Information Security Risk and the CIA TriadThis gives you the core framework for classifying what an attack damages: confidentiality, integrity or availability.
  3. 3Cyber Case Study Lessons and Control FailuresWith threats and the CIA triad known, you can read cases and name which control failed and what it harmed.
  4. 4Cyber Risk Management and Control FrameworksFrameworks make sense once you have seen the failures they are designed to prevent.
  5. 5Incident Response, Resilience and RecoveryThis covers what happens when prevention fails, so study it after you know the controls.
  6. 6Measuring and Quantifying Cyber RiskQuantification comes last because it needs the loss events, controls and recovery concepts from earlier topics.

How to prepare Case Study: Cyberthreats and Information Security Risks

Treat this chapter as a scenario-reasoning exercise. Build a clear vocabulary first, then practise applying it to short cases.

  1. Read the threat topic once and make a one-page list of threat actors, their typical motives and the attack methods linked to each.
  2. Learn the CIA triad until you can map any described harm to one or more of its three parts without hesitation.
  3. For each case study, write three lines: what happened, which control failed, and which control would have helped most.
  4. Sort controls into preventive, detective and corrective, and tie each framework to the layer of defence it supports.
  5. Draw a simple timeline of an incident: detect, contain, eradicate, recover, review. Add recovery time and recovery point concepts to it.
  6. Practise quantification by describing, in words, how frequency and severity of cyber events feed a loss estimate, and note the limits of sparse data.
  7. Finish with timed mixed MCQs. For each miss, note whether you misread the scenario or confused two terms.

Common mistakes in Case Study: Cyberthreats and Information Security Risks

  • Mapping an attack to the wrong part of the CIA triad.

    Fix: Ask what the attacker actually did to the data or system: exposed it, changed it, or blocked it. Pick the answer that matches that action.

  • Confusing preventive, detective and corrective controls.

    Fix: Judge the control by when it acts. Before the event is preventive, during or just after discovery is detective, and after impact to limit or restore is corrective.

  • Blaming technology alone in case studies.

    Fix: Check for people and process causes too, such as poor oversight, unclear ownership, weak vendor checks and untested response plans.

  • Mixing up recovery time and recovery point objectives.

    Fix: Link time to how long an outage can last, and point to how far back in data you can afford to lose.

  • Treating cyber quantification as precise.

    Fix: State the inputs, frequency and severity, and remember that scarce loss data and fast-changing threats limit accuracy.

  • Choosing the most technical answer instead of the best risk-based one.

    Fix: Choose the answer that addresses the root cause in the scenario and fits the firm's risk appetite and priorities.

Last-day revision: Case Study: Cyberthreats and Information Security Risks

  • Cyber risk is a type of operational risk: loss from people, processes, systems or external events.
  • CIA triad: confidentiality (no unauthorised disclosure), integrity (no unauthorised change), availability (access when needed).
  • Ransomware mainly attacks availability; data theft mainly attacks confidentiality; tampering mainly attacks integrity.
  • Threat actors differ in motive: criminals seek money, state actors seek strategic goals, insiders may act from grievance or error.
  • Preventive controls stop events, detective controls spot them, corrective controls limit damage and restore.
  • Defence in depth uses several layers so one failure does not cause a breach.
  • Weak access management and slow patching are repeated causes of control failure in cases.
  • Third-party and supply chain links extend your risk beyond your own systems.
  • Incident response runs from preparation and detection through containment, recovery and lessons learned.
  • Recovery time objective is how fast service must return; recovery point objective is how much data loss is tolerable.
  • Cyber loss estimates combine event frequency and severity, but limited data makes them uncertain.
  • Good governance means board oversight and clear ownership of cyber risk, not only IT ownership.

Case Study: Cyberthreats and Information Security Risks practice questions

Case Study: Cyberthreats and Information Security Risks in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Case Study: Cyberthreats and Information Security Risks: frequently asked questions

Which FRM Part II topic does this chapter belong to?

It falls under Operational Risk and Resilience. Cyber risk is treated as an operational risk with its own threats, controls and recovery needs.

Do I need deep technical knowledge to handle these questions?

No. You need to understand concepts, not code. Focus on threat types, the CIA triad, control logic, response steps and how risk is measured.

How should I study the case studies?

Summarise each case in three lines: what happened, which control failed, and the best fix. Then test whether you could name the CIA element affected.

How does this chapter link to Current Issues readings?

The 2026 Current Issues readings include artificial intelligence and digital resilience. Both build on cyber threats, controls and recovery, so this chapter gives you the base vocabulary.