FRM Part II · FRM Exam Part II
Cyber-resilience: Range of Practices for FRM Part II
Cyber-resilience is an organisation's ability to keep delivering critical services despite cyber incidents. The chapter covers governance, risk identification, protection, detection, response, recovery and learning. To solve questions, identify the stage of the cycle in the scenario, then pick the practice that fits that stage and the firm's critical operations.
What this chapter covers
This chapter describes the range of practices that firms use to manage cyber risk and stay resilient. It follows the life cycle of a cyber event: setting governance and strategy, identifying and assessing risks, protecting and detecting, responding and recovering, and then sharing information and learning. The core idea is that you cannot prevent every attack, so you plan to keep critical services running and recover quickly.
The chapter sits within the Operational Risk and Resilience topic of FRM Part II. It links directly to operational risk ideas such as people, process, systems and external events, and to third-party and business continuity risk. Questions are usually case-like. You get a short scenario about a bank or market infrastructure and must pick the best practice, the weakest control or the right next step.
It also connects to the Current Issues topic, where digital resilience and artificial intelligence appear. Strong understanding here helps you answer those questions, because they share vocabulary: critical functions, impact tolerance, third-party dependencies and incident response.
The paper has 80 equally weighted multiple-choice questions, so every concept you can answer reliably is worth the same as any other. This chapter is conceptual and scenario-based, which means careful reading and clear definitions earn marks without heavy calculation. Candidates who skip it as soft material lose easy questions. It also reinforces operational resilience and digital resilience themes that recur across the paper, so the effort pays back in more than one place.
Cyber-resilience: Range of Practices: topics in the order to study them
- 1Cyber Risk and Cyber Resilience FundamentalsStart here to fix the definitions of cyber risk, cyber security and cyber resilience that every later topic relies on.
- 2Cyber Risk Governance and StrategyNext, learn who owns cyber risk and how strategy and risk appetite are set, since all other practices flow from this.
- 3Cyber Risk Identification and AssessmentYou need to know what assets, threats and vulnerabilities matter before you can choose controls.
- 4Protection, Detection and ControlsControls only make sense once you know the risks they address, so study them after assessment.
- 5Response, Recovery and Business ContinuityThis covers what happens when controls fail, and it builds on detection from the previous topic.
- 6Information Sharing, Learning and EvolutionFinish with feedback and improvement, which close the loop and tie the full cycle together.
How to prepare Cyber-resilience: Range of Practices
Treat the chapter as one cycle rather than six separate lists. Questions test whether you can place a practice at the right stage and judge its fit.
- Read the topics in the study order and draw a one-page cycle diagram: govern, identify, protect, detect, respond, recover, learn.
- Write short definitions for cyber risk, cyber security and cyber resilience, and note how resilience differs from prevention.
- For each stage, list three or four practices and the problem each one solves.
- Link each practice to operational risk ideas such as people, process, systems and external events, and to third-party dependence.
- Practise scenario questions: name the stage first, then eliminate options that belong to a different stage.
- Review your wrong answers and note whether the error was a definition, a stage mix-up or misreading the scenario.
- In the last week, reread your cycle diagram and the quick revision points, then link them to digital resilience in Current Issues.
Common mistakes in Cyber-resilience: Range of Practices
Treating cyber resilience as the same as cyber security.
Fix: Remember that security focuses on protecting assets, while resilience also covers response, recovery and continuing critical services.
Choosing a technical control when the scenario is about governance.
Fix: Ask who is accountable and what the stated gap is. If it is oversight, ownership or appetite, the answer is a governance fix.
Ignoring third-party and supply chain risk.
Fix: Include vendors, cloud providers and shared infrastructure when assessing dependencies and planning recovery.
Mixing up the stages of response and recovery.
Fix: Response contains and manages the incident. Recovery restores services and data. Place each option on that timeline.
Assuming a plan that exists is a plan that works.
Fix: Favour answers that include testing, exercises and updates based on lessons learned.
Skipping the chapter because it has no calculations.
Fix: Schedule it early, since each question counts equally and these are reachable with clear definitions and practice.
Last-day revision: Cyber-resilience: Range of Practices
- Cyber resilience is the ability to keep delivering critical services through and after a cyber incident.
- Prevention alone is not enough; assume some attacks will succeed and plan for recovery.
- Governance means the board and senior management set direction, risk appetite and accountability.
- Identify critical functions and the assets and data that support them before choosing controls.
- Risk assessment links threats, vulnerabilities and potential impact.
- Protection and detection controls work together; good protection without detection leaves breaches unseen.
- Defence in depth uses layered controls so one failure does not expose everything.
- Response plans need defined roles, escalation paths and communication to stakeholders.
- Recovery planning should be tested regularly, not only written down.
- Third-party and supply chain dependencies are part of your cyber risk.
- Information sharing with peers and authorities improves collective defence.
- Lessons from incidents and tests should feed back into strategy and controls.
Cyber-resilience: Range of Practices practice questions
- After a destructive malware attack, a bank's incident team wants to restore services from backups. Which practice best supports cyber-resili…
- A regional bank classifies its cyber defences into functions. Its security team installs firewalls and multi-factor authentication, runs a s…
- Under a three-lines model for cyber risk, which activity is the proper role of the second line of defence?
- Nordvik Bank's CISO reports to the head of IT, who also owns system delivery deadlines. An internal review finds that security findings are …
- A regulator-style review of a firm's cyber resilience finds that its incident response plan has never been tested against a scenario in whic…
- A bank segments its network so that the payments environment sits in a separate zone with tightly restricted traffic from the corporate netw…
- A mid-sized bank's cyber team receives a threat indicator from an industry sharing forum about a new phishing campaign. Which use of this in…
- A bank wants its cyber-resilience strategy to be integrated with enterprise risk management. Which approach best achieves this?
Cyber-resilience: Range of Practices in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Cyber-resilience: Range of Practices: frequently asked questions
Is this chapter calculation-heavy in FRM Part II?
No. It is mainly conceptual and scenario-based. You need to know definitions, the stages of the cyber-resilience cycle and which practice suits a given situation.
Where does this chapter sit in the FRM Part II syllabus?
It belongs to the Operational Risk and Resilience topic, one of six Part II topics. It also overlaps with digital resilience in Current Issues in Financial Markets.
How is cyber resilience different from cyber security?
Cyber security aims to protect systems and data from attack. Cyber resilience goes further and includes detecting, responding to and recovering from incidents so that critical services continue.
How should I practise this chapter?
Use scenario questions. First identify the stage of the cycle the scenario describes, then choose the practice that fits that stage. Review each wrong answer to find whether the issue was a definition or a stage mix-up.