Skip to content

FRM Exam Part II · Case Study: Cyberthreats and Information Security Risks

Cyber Threat Landscape and Threat Actors for FRM Part II

Updated 11 October 2026 · Fact-checked

The cyber threat landscape is the set of attack types (malware, ransomware, phishing, insider misuse, DDoS) and the actors behind them (criminals, nation-states, hacktivists, insiders). To answer questions, identify the attack method, the actor's motive, the asset hit, and the control that best fits.

Understand Cyber Threat Landscape and Threat Actors

A cyber threat is any event that can harm the confidentiality, integrity or availability of information or systems. These three properties are the CIA triad. Every attack type below breaks at least one of them.

Start with the attack types. Malware is the broad term for malicious software, including viruses, worms, trojans and spyware. Ransomware is a kind of malware that encrypts or locks data and demands payment. It mainly hits availability. Some groups also steal data first and threaten to publish it (double extortion), which hits confidentiality too. Phishing is not malware. It is social engineering: a deceptive email, message or call that tricks a person into giving credentials or running something. Phishing is often the delivery route for malware. A DDoS attack floods a service with traffic to make it unavailable. An insider attack comes from someone with legitimate access, either malicious or careless.

Now the threat actors, who differ by motive. Cyber criminals want money: ransom, fraud, stolen data to sell. Nation-states pursue espionage, disruption or strategic advantage. They are usually well resourced and patient, and run long campaigns known as advanced persistent threats (APTs). Hacktivists are driven by ideology or protest and favour DDoS, defacement and data leaks. Insiders include disgruntled staff, fraudsters and well-meaning employees who make mistakes. Others include terrorist groups and opportunistic individuals with low skill.

The key exam skill is separating method from actor. Ransomware is a method. A criminal gang, or occasionally a state-linked group, is the actor. The same actor uses several methods, and the same method serves several actors.

For a bank, the risk lands in operational risk (Basel event types such as external fraud and business disruption and system failures). It can also spread: a successful attack can cause liquidity strain, reputational damage and regulatory penalties.

Key formulas to remember

CIA triad
Confidentiality + Integrity + Availability
Map each attack to the property it breaks. Ransomware: availability (and confidentiality if data is stolen). Data theft: confidentiality. Tampering with records: integrity. DDoS: availability.
Actor to motive
Criminals → profit; Nation-states → espionage/disruption; Hacktivists → ideology; Insiders → grievance, gain or error
This is a general pattern, not a strict rule. Actors can overlap, and attribution is often uncertain.
Phishing vs malware
Phishing = deception of a person; Malware = malicious code
Phishing often delivers malware, but the two are different things.
Basel operational risk link
Cyber event → external fraud / internal fraud / business disruption and system failures
Which category fits depends on who acts and what is affected. An attack by an outsider is usually external fraud; a malicious employee is internal fraud.

How to solve Cyber Threat Landscape and Threat Actors questions

Use this sequence for any scenario question on cyber threats and actors.

  1. 1Read the scenario and underline the observable facts: what happened, who had access, what was lost or stopped.
  2. 2Name the attack method precisely: malware, ransomware, phishing, DDoS, insider misuse or another type.
  3. 3Identify the CIA property that was broken.
  4. 4Infer the likely actor from the motive and sophistication: money, espionage, protest or grievance. Treat it as likely, not certain.
  5. 5Classify the event in operational risk terms, such as external fraud, internal fraud or business disruption.
  6. 6Choose the control that targets the method: training and filtering for phishing, backups and segmentation for ransomware, access control and monitoring for insiders, traffic filtering for DDoS.
  7. 7Eliminate options that confuse method with actor or that overstate certainty.

Quickest way: Method, motive, property in 20 seconds

When to use it: Use it when you have about two minutes per question and four plausible options.

  1. Find the verb in the stem: encrypted, tricked, flooded, leaked, abused access.
  2. Match it: encrypted = ransomware, tricked = phishing, flooded = DDoS, abused access = insider.
  3. Check motive words: ransom = criminals, protest = hacktivists, long-term stealth = nation-state.
  4. Pick the option that matches both method and actor, and reject absolute words such as always or only.

Common mistakes in Cyber Threat Landscape and Threat Actors

  • Treating phishing as a type of malware.

    Phishing emails often carry malware, so the two blur together.

    Fix: Phishing is social engineering aimed at a person. Malware is code. Phishing is a delivery route.

  • Saying ransomware only affects availability.

    Encryption is the best-known feature.

    Fix: Remember double extortion: stolen data also breaches confidentiality.

  • Assuming nation-states only attack governments.

    Textbook examples focus on state targets.

    Fix: Banks and market infrastructure are targets for espionage and disruption. Financial stability is a state interest.

  • Ignoring insiders as a threat actor.

    Cyber seems like an outside-in problem.

    Fix: Insiders have legitimate access and knowledge. Include both malicious and accidental cases.

  • Naming the actor with certainty from the method alone.

    Students match ransomware to criminals as a fixed rule.

    Fix: Use the likely actor from motive and context. Attribution is hard and methods overlap.

  • Picking a technical control for a human-driven attack.

    Firewalls feel like the default answer.

    Fix: Phishing and insider risks need awareness, access governance and monitoring as well as technology.

Worked examples

Example 1

A bank's staff find that core files are encrypted and a note demands payment in cryptocurrency. Investigators also see that customer data was copied out before encryption. Which description is best? A) Phishing by hacktivists, affecting integrity only; B) Ransomware with data theft, affecting availability and confidentiality, most likely by criminals; C) DDoS by a nation-state, affecting availability only; D) Insider misuse, affecting integrity only.

Show the solution
  1. Method: files encrypted with a payment demand is ransomware.
  2. Data was copied before encryption, so this is double extortion.
  3. Encryption breaks availability. Data theft breaks confidentiality.
  4. A ransom demand points to profit, so criminals are the likely actor.
  5. Option A names phishing and integrity only, which does not fit. Option C names DDoS, which does not fit. Option D names insider misuse, which does not fit.

Answer: B

Example 2

An employee receives an email that looks like it is from the IT helpdesk and enters their login on a fake page. The attacker then uses the credentials to access internal systems. What is the initial attack type and the most direct preventive control? A) Malware; endpoint backups; B) Phishing; staff awareness training and multi-factor authentication; C) DDoS; traffic filtering; D) Ransomware; network segmentation.

Show the solution
  1. The attacker deceived a person into giving credentials, which is phishing.
  2. No malicious code was described as the first step, so it is not malware.
  3. No traffic flood or encryption occurred, so DDoS and ransomware do not fit.
  4. The best controls address the human and the stolen credential: awareness training and multi-factor authentication, which limits the value of a stolen password.

Answer: B

Exam tips

  • Practise telling method from actor. Many wrong options swap the two.
  • Link each scenario to a CIA property. It quickly removes options.
  • Be wary of absolutes such as always, only or never about actors and motives.
  • Expect cases that mention cloud, third parties or AI. Treat these as new routes for the same threat types.
  • Connect threats to Basel operational risk event types when the question asks for classification.

Practice questions from Case Study: Cyberthreats and Information Security Risks

Cyber Threat Landscape and Threat Actors in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Cyber Threat Landscape and Threat Actors: frequently asked questions

What is the difference between ransomware, phishing and malware?

Malware is any malicious software. Ransomware is a type of malware that locks or encrypts data for payment. Phishing is a deception technique that tricks a person, and it often delivers malware or steals credentials.

Who are the main cyber threat actors?

The main groups are cyber criminals driven by profit, nation-states pursuing espionage or disruption, hacktivists driven by ideology, and insiders acting from grievance, gain or error. Actors can overlap and attribution is often uncertain.

Is an insider attack always malicious?

No. Insiders can act deliberately, or they can cause harm by mistake, such as clicking a phishing link or misconfiguring a system. Both cases matter for risk management.

Where does this topic sit in FRM Part II?

It falls under Operational Risk and Resilience, in the cyber case study. Questions usually give a scenario and ask you to identify the threat, the property affected or the best control.