Skip to content

FRM Exam Part II · Case Study: Cyberthreats and Information Security Risks

Cyber Case Study Lessons and Control Failures for FRM Part 2

Updated 11 October 2026 · Fact-checked

A cyber case study traces how an attacker moved through a firm, which controls failed at each step, and how governance gaps let the loss grow. To solve questions, map the attack path (kill chain), name the failed control, then give the fix and the risk category affected.

Understand Cyber Case Study Lessons and Control Failures

A cyber breach is rarely one big failure. It is a chain of small failures. The attacker needs to get in, gain more access, find data or systems, and then act. A good control at any link can break the chain.

The kill chain is a simple way to describe this path: reconnaissance (find targets), initial access (phishing, stolen credentials, an exposed system or a software flaw), privilege escalation and lateral movement (gain wider rights and move across systems), data theft or disruption (exfiltration, encryption, fraudulent payments), and finally covering tracks or demanding payment. Exam cases follow this order.

Take the 2019 Capital One breach as a standard example. A misconfigured web application firewall in a cloud environment let an attacker make a server-side request. This exposed temporary credentials for an over-permissioned role. Those credentials were used to list and copy data from cloud storage. The lessons are about configuration management, least privilege, and monitoring for unusual data access. Cloud providers secure the platform, but the customer remains responsible for its own configuration. This is the shared responsibility idea.

Other typical cases include the Bangladesh Bank 2016 payment fraud via SWIFT credentials, where weak network segregation and payment controls allowed fraudulent messages, and ransomware events where poor backups and flat networks spread damage. The pattern is the same: weak preventive controls, slow detection, and poor response.

Governance failures sit behind the technical ones. Typical examples are unclear ownership of controls, ignored audit findings, missing asset inventories, weak third-party oversight, and slow escalation to senior management. Losses include direct costs, regulatory fines, remediation, legal costs and reputation damage. Firms classify these as operational risk events, often under external fraud or business disruption and system failures.

Key formulas to remember

Kill chain order
Reconnaissance → Initial access → Privilege escalation → Lateral movement → Data theft or disruption → Cover tracks or extort
Use it to place each case fact at the right stage and pick a control for that stage.
CIA triad
Confidentiality, Integrity, Availability
Data theft hits confidentiality, fraudulent payments hit integrity, ransomware hits availability.
Control types
Preventive, Detective, Corrective (response and recovery)
Match the failed control to its type. Many cases show detection failing even when prevention is partly in place.
Shared responsibility rule
Provider secures the cloud; customer secures what it configures and deploys in the cloud
Customer misconfiguration is not the provider's failure.
Total incident loss
Total loss = direct loss + response and remediation cost + legal and regulatory cost + reputational and business loss
A conceptual breakdown. Reputational loss is hard to measure.

How to solve Cyber Case Study Lessons and Control Failures questions

Use the same sequence for any cyber case question. It keeps you from being distracted by technical detail.

  1. 1Read the last sentence first to see what is asked: the cause, the failed control, the lesson or the best action.
  2. 2Identify the kill chain stage described in the case: entry, escalation, movement or impact.
  3. 3Name the root weakness: misconfiguration, excessive privilege, weak authentication, missing monitoring, poor segregation or slow response.
  4. 4Classify the control that failed as preventive, detective or corrective.
  5. 5Identify which CIA element was hit and whether the event is external fraud, system failure or another operational risk category.
  6. 6Look for a governance failure: ownership, ignored findings, third-party oversight or escalation.
  7. 7Pick the answer that fixes the root cause at the right layer, not a generic or purely reactive step.
  8. 8Check for traps such as blaming the provider or choosing a tool when the issue is process or governance.

Quickest way: Stage, control, fix

When to use it: Use when you have about two minutes per question and the case is short.

  1. Find the stage of the attack in the stem.
  2. Ask which control type should have stopped or spotted it.
  3. Eliminate options that are reactive when the stem shows a prevention gap.
  4. Prefer least privilege, segmentation, monitoring and tested response over single-tool answers.
  5. Choose the option that addresses the root cause.

Common mistakes in Cyber Case Study Lessons and Control Failures

  • Blaming the cloud provider for a customer misconfiguration.

    Students assume the platform owner is accountable for everything hosted on it.

    Fix: Apply shared responsibility: the customer owns its configuration, identity and access settings.

  • Treating the breach as one event instead of a chain.

    Case summaries focus on the headline impact.

    Fix: Walk the kill chain and note which control would have broken each link.

  • Choosing a purely technical fix for a governance failure.

    Technical answers look concrete.

    Fix: If the stem mentions ignored audit findings, unclear ownership or poor escalation, choose the governance or process remedy.

  • Confusing the CIA element affected.

    Data theft and fraud both feel like confidentiality events.

    Fix: Theft means confidentiality, altered or forged transactions mean integrity, outage or encryption means availability.

  • Picking a corrective control when prevention was the gap.

    Incident response sounds like the natural answer after a breach.

    Fix: Ask what failed first. Response only limits damage; it does not remove the root weakness.

  • Assuming encryption or a firewall alone would have prevented the loss.

    Students overstate single controls.

    Fix: Remember defence in depth. A control can be present yet misconfigured or bypassed with valid credentials.

Worked examples

Example 1

A bank runs a customer application in a public cloud. An attacker exploits a misconfigured firewall to obtain temporary credentials for a server role. The role has broad rights, and the attacker copies large volumes of customer data from cloud storage. No alert is raised for weeks. Which is the best primary root-cause finding? A) The cloud provider's data centre was breached. B) Misconfiguration combined with excessive privileges and weak monitoring. C) Customer data was not stored in the cloud. D) The attacker used a zero-day flaw in the hardware.

Show the solution
  1. Stage: the initial access came from the misconfigured firewall, then privilege use via the role credentials, then exfiltration.
  2. Root weaknesses: a configuration error, a role with excessive rights (least privilege breached) and no detection of unusual data access.
  3. Option A conflicts with shared responsibility, since the stem points to the bank's own configuration.
  4. Option C is irrelevant, and D is not supported by the stem.
  5. Option B names all three root weaknesses.

Answer: B. The breach came from misconfiguration, over-broad permissions and failed detection, all the customer's responsibility.

Example 2

After a payment-fraud incident, a review finds that the operations network was connected to the payment messaging system without segregation, one set of credentials could approve and release messages, and alerts were not monitored out of hours. Which CIA element was mainly damaged, and which single control improvement best addresses the cause? A) Confidentiality; stronger encryption of archives. B) Availability; faster backup restoration. C) Integrity; segregation of duties with network segmentation. D) Confidentiality; more staff training on data labels.

Show the solution
  1. Fraudulent messages released as genuine mean transaction integrity was damaged.
  2. Root causes: no network segmentation and no segregation of duties on approval and release.
  3. Options A and D target confidentiality, which is not the main loss. B targets availability, but nothing was unavailable.
  4. Option C targets integrity and addresses both root causes.

Answer: C. Integrity was the main element damaged, and segregation of duties with network segmentation addresses the cause.

Exam tips

  • Practise placing every case fact on the kill chain. Most options differ by stage or control type.
  • Know the Capital One path: firewall misconfiguration, role credentials, cloud storage copy, weak detection.
  • Expect questions that mix technical facts with governance failures. Read for both.
  • Be precise: say least privilege, segmentation, monitoring and tested response, not just 'better security'.
  • If two options both look good, pick the one that fixes the root cause earlier in the chain.

Practice questions from Case Study: Cyberthreats and Information Security Risks

Cyber Case Study Lessons and Control Failures: frequently asked questions

What is the kill chain in a cyber case study?

It is the step-by-step path an attacker follows, from reconnaissance and initial access to escalation, movement and final impact. You use it to find where controls failed and where the chain could have been broken.

What were the main control failures in the Capital One breach?

A misconfigured firewall allowed a server-side request that exposed role credentials. The role had broad permissions, and unusual access to stored data was not detected quickly. These are configuration, least privilege and monitoring failures.

Is a cyber breach an operational risk event for FRM?

Yes. Firms treat cyber events as operational risk, commonly under external fraud or business disruption and system failures. The loss can also create legal, regulatory and reputational consequences.

How do I tell a governance failure from a technical one?

Technical failures are about settings, code, access rights or tools. Governance failures are about ownership, ignored audit findings, weak oversight of vendors or slow escalation. Fix each at its own level.