Skip to content

FRM Exam Part II · Case Study: Cyberthreats and Information Security Risks

Information Security Risk and the CIA Triad Explained

Updated 11 October 2026 · Fact-checked

The CIA triad is the base of information security: confidentiality (only authorised parties see data), integrity (data stays accurate and unaltered) and availability (systems and data are usable when needed). A cyber incident breaks one or more of these. Its losses are classed as operational risk. To solve questions, find which property failed, then map the loss.

Understand Information Security Risk and the CIA Triad

Information security protects information and the systems that hold it. Banks hold money records, customer data and payment instructions. If these are exposed, changed or unreachable, the bank suffers harm. The CIA triad gives you a simple test for what went wrong.

Confidentiality means only authorised people or systems can access information. A breach of confidentiality is a data theft or leak. Typical controls are encryption, access controls and authentication. Integrity means data and systems are accurate, complete and not changed without authorisation. A breach of integrity is tampering, such as altering payment details or corrupting records. Typical controls are hashing, change controls, segregation of duties and reconciliations. Availability means authorised users can reach systems and data when needed. A breach of availability is an outage, such as ransomware locking systems or a denial-of-service attack. Typical controls are redundancy, backups, recovery plans and capacity.

One incident can hit more than one property. Ransomware that also steals data hits availability and confidentiality. Match each attack to the property it damages first. Do not match it to the attacker's motive.

How does this fit into risk? Basel defines operational risk as the risk of loss from inadequate or failed internal processes, people and systems, or from external events. It includes legal risk but excludes strategic and reputational risk. Cyber events are a cause. They are not a separate Basel risk type. They appear under event types such as external fraud, business disruption and system failures, and internal fraud. Information security risk is the narrower concept: risk to the CIA of information assets. Cyber risk is broader in scope in some definitions, as it covers any loss from attacks on or failures of digital systems, including those that do not target information. Check how the question defines each term.

Losses come in direct and indirect forms. Direct: incident response and forensics, system restoration, customer remediation, legal costs, regulatory fines and theft. Indirect: lost business and reputational damage. Under Basel, reputational loss is outside the operational risk definition, but you should still mention it as a consequence in a case study.

Key formulas to remember

Confidentiality
Confidentiality = only authorised access to information
Breach examples: data theft, leaked customer records, phishing credential capture.
Integrity
Integrity = accuracy and completeness, no unauthorised change
Breach examples: altered payment instructions, tampered ledgers, corrupted data.
Availability
Availability = authorised access when needed
Breach examples: ransomware lockout, DDoS, system outage, failed recovery.
Basel operational risk definition
Operational risk = loss from inadequate or failed processes, people and systems, or from external events
Includes legal risk. Excludes strategic and reputational risk.
Expected operational loss (frequency-severity)
Expected annual loss = expected number of events × average loss per event
Use it to compare cyber scenarios. Assumes frequency and severity are independent.

How to solve Information Security Risk and the CIA Triad questions

Use this method on any case or scenario question about cyber incidents and information security.

  1. 1Read the scenario and list what actually happened to the data or systems.
  2. 2Map each effect to confidentiality, integrity or availability. More than one can apply.
  3. 3Identify the cause: process, people, system or external event.
  4. 4Classify under the Basel operational risk event type, such as external fraud, internal fraud, or business disruption and system failures.
  5. 5Separate direct losses (response, restoration, fines, theft) from indirect ones (lost business, reputation).
  6. 6Match the control or response to the failed property, for example encryption for confidentiality or backups for availability.
  7. 7Check the options for wording traps such as 'only', 'always' and 'separate risk type'.

Quickest way: Property-first elimination

When to use it: Use it when time is short and the options mix controls, properties and loss types.

  1. Ask one question: was data seen, changed or blocked?
  2. Seen means confidentiality. Changed means integrity. Blocked means availability.
  3. Pick the control that targets that property.
  4. Eliminate options that call cyber a separate Basel risk type or that count reputational loss as operational risk loss.

Common mistakes in Information Security Risk and the CIA Triad

  • Treating cyber risk as a separate Basel risk category.

    Cyber gets its own headlines and teams, so it feels separate.

    Fix: Remember it is a cause of operational risk loss. Losses fall in event types such as external fraud or business disruption and system failures.

  • Calling ransomware only a confidentiality breach.

    Students link 'breach' with stolen data.

    Fix: Locked systems are an availability failure. Add confidentiality only if data was also exfiltrated.

  • Confusing integrity with confidentiality.

    Both involve unauthorised actors.

    Fix: Ask whether the attacker read the data or changed it. Reading is confidentiality. Changing is integrity.

  • Including reputational damage in the Basel operational risk loss.

    Reputation is a real consequence of incidents.

    Fix: Basel's definition excludes strategic and reputational risk. Treat it as an indirect consequence outside the definition.

  • Assuming strong confidentiality controls protect availability.

    Students think security is one single control set.

    Fix: Each property needs its own controls. Encryption does not restore a system after an outage.

  • Using information security risk and cyber risk as exact synonyms.

    Textbooks and regulators use them loosely.

    Fix: Information security risk is about the CIA of information assets. Cyber risk is broader in scope. Follow the definition given in the question.

Worked examples

Example 1

A bank's payment system is hit by malware. Attackers change beneficiary account numbers on outgoing wire instructions, and USD 8 million is sent to fraudulent accounts. Which CIA property is mainly breached, and how is the loss classed under Basel operational risk?

Show the solution
  1. The attackers altered payment data. Data was changed, not only read or blocked.
  2. Changing data without authorisation is a breach of integrity.
  3. The cause is an external attacker exploiting a system weakness.
  4. The loss is a theft of funds by a third party, so the event type is external fraud.
  5. The USD 8 million is a direct loss.

Answer: Integrity is the main property breached. The loss is operational risk, event type external fraud, and the USD 8 million is a direct loss.

Example 2

A bank suffers a ransomware attack. Core systems are encrypted for three days and customers cannot transact. The attackers also copy customer files. Costs: restoration ₹4,00,00,000, legal and notification ₹1,00,00,000, and estimated lost future business ₹6,00,00,000. Which properties fail, and what is the direct loss?

Show the solution
  1. Encrypted systems stopped access, so availability fails.
  2. Copying customer files exposes data to unauthorised parties, so confidentiality fails.
  3. No evidence data was altered, so integrity is not shown to fail.
  4. Direct costs are restoration and legal and notification: ₹4,00,00,000 + ₹1,00,00,000 = ₹5,00,00,000.
  5. Lost future business of ₹6,00,00,000 is an indirect, reputation-driven effect and sits outside the Basel loss definition.
  6. The event type is business disruption and system failures, with an external fraud element.

Answer: Availability and confidentiality fail. The direct operational loss is ₹5,00,00,000. The ₹6,00,00,000 is an indirect effect and not counted.

Exam tips

  • Name the CIA property first. Most options differ only by which property they pick.
  • Watch for scenarios that breach two properties, such as ransomware with data theft.
  • Remember that Basel operational risk includes legal risk but excludes reputational and strategic risk.
  • Match controls to properties: encryption and access control to confidentiality, change control and reconciliation to integrity, backups and recovery to availability.
  • Read definitions in the question. If it defines cyber risk more broadly than information security risk, follow it.

Practice questions from Case Study: Cyberthreats and Information Security Risks

Information Security Risk and the CIA Triad in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Information Security Risk and the CIA Triad: frequently asked questions

What is the CIA triad in simple terms?

It is three goals for protecting information. Confidentiality keeps data private, integrity keeps it accurate, and availability keeps it accessible when needed. Any incident can be analysed by asking which goal failed.

How does cyber risk fit into operational risk?

Cyber events are a cause of operational risk loss, not a separate Basel risk type. Losses are classed under event types such as external fraud, internal fraud, and business disruption and system failures.

What is the difference between cyber risk and information security risk?

Information security risk concerns the confidentiality, integrity and availability of information assets. Cyber risk is often defined more broadly, covering losses from attacks on or failures of digital systems. Definitions vary, so use the one given in the question.

Is ransomware an availability or confidentiality problem?

Ransomware mainly attacks availability because it locks systems. If attackers also steal data, which is common, confidentiality is breached too.