Skip to content

FRM Exam Part II · Cyber-resilience: Range of Practices

Cyber Risk and Cyber Resilience Fundamentals for FRM Part II

Updated 11 October 2026 · Fact-checked

Cyber risk is the risk of loss from failures or attacks on a firm's information and technology systems. Cyber resilience is the ability to keep delivering critical services during and after a cyber event. To answer exam questions, separate prevention (security) from continuity and recovery (resilience), then link both to operational risk.

Understand Cyber Risk and Cyber Resilience Fundamentals

Cyber risk is the risk of financial, operational or reputational loss from the failure or compromise of information systems, data or networks. The cause can be a deliberate attack, an insider, a vendor failure or a simple error. In Basel terms, it sits inside operational risk: loss from inadequate or failed processes, people, systems or external events. Cyber events usually map to external fraud, internal fraud, or business disruption and system failures.

Information security (or cyber security) aims to protect confidentiality, integrity and availability of information. It is mostly about prevention: access controls, encryption, patching, monitoring. Security assumes you try to keep attackers out.

Cyber resilience goes further. It assumes some attacks will succeed. It asks whether the firm can still deliver critical services, limit the damage, recover quickly and learn from the event. It covers governance, identification, protection, detection, response, recovery and continuous improvement. Security is a part of resilience, not a substitute for it.

Cyber risk differs from traditional operational risk in several ways. Threats are adversarial and adapt to your controls. Events can spread fast across connected systems and firms. Losses are hard to model because history is short and incidents are often not disclosed. One weak point, such as a shared vendor, can hit many institutions at once.

Financial institutions are prime targets for four reasons. They hold money and valuable data. They are highly connected through payment systems, markets and shared vendors. They depend on technology for almost every service. And disruption can cause wider financial stability concerns, which attracts criminals, state actors and activists.

Key formulas to remember

CIA triad
Confidentiality + Integrity + Availability
The three security objectives. A cyber event breaches at least one of them.
Cyber risk in Basel terms
Cyber risk ⊂ Operational risk
Operational risk is loss from inadequate or failed processes, people, systems or external events. It includes legal risk but excludes strategic and reputational risk in the Basel definition.
Security vs resilience
Resilience = Security (prevent) + Detect + Respond + Recover + Learn
A memory aid, not a regulatory formula. Resilience assumes breaches will happen.
Lifecycle of cyber resilience
Govern → Identify → Protect → Detect → Respond → Recover → Learn
Use as a checklist to place any control or action in the right phase.

How to solve Cyber Risk and Cyber Resilience Fundamentals questions

Use this method for any definition, scenario or control-classification question on cyber risk and resilience.

  1. 1Read the scenario and note what happened: attack, failure, or error, and which service or data was affected.
  2. 2Decide whether the question is about prevention (security) or about continuity and recovery (resilience).
  3. 3Identify the CIA element breached: confidentiality, integrity or availability.
  4. 4Map the event to a Basel operational risk event type, such as external fraud or business disruption and system failures.
  5. 5Place the action in the lifecycle: identify, protect, detect, respond, recover or learn.
  6. 6Check for features that make cyber different: adaptive adversary, speed, interconnection, third-party dependence.
  7. 7Eliminate options that overstate security as total protection or treat cyber as only an IT issue.
  8. 8Choose the option that matches the precise definition and the firm-wide, governance-led view.

Quickest way: Prevent or continue? Two-question filter

When to use it: Use when two options look similar and you have under a minute per question.

  1. Ask: does the option keep attackers out? If yes, it is security.
  2. Ask: does it keep critical services running or restore them after a breach? If yes, it is resilience.
  3. If the stem says 'assume breach', 'critical services' or 'recovery time', lean to resilience.
  4. If the option says cyber is purely an IT matter or can be fully eliminated, reject it.

Common mistakes in Cyber Risk and Cyber Resilience Fundamentals

  • Treating cyber resilience and cyber security as the same thing.

    Both terms appear together in guidance and sound alike.

    Fix: Security prevents and protects. Resilience also covers detection, response, recovery and learning, and assumes breaches happen.

  • Treating cyber risk as separate from operational risk.

    Cyber gets its own teams and budgets, so it feels like its own risk type.

    Fix: Under Basel it is a source of operational risk loss. Map it to event types such as external fraud or system failures.

  • Assuming strong controls can eliminate cyber risk.

    Candidates think of cyber like a compliance task with a pass state.

    Fix: Cyber risk can be reduced and managed, not removed. Adversaries adapt, so residual risk always remains.

  • Confusing the CIA elements.

    A data theft and a ransomware lock-out both feel like 'data loss'.

    Fix: Theft breaches confidentiality. Altered records breach integrity. A system outage or ransomware lock-out breaches availability.

  • Seeing cyber as an IT-only issue.

    Technical language hides the business and governance side.

    Fix: Board and senior management own cyber risk appetite and strategy. IT is a key function, not the owner.

  • Ignoring third-party and interconnection risk.

    Focus stays on the firm's own perimeter.

    Fix: Include shared vendors, cloud providers and market infrastructure as channels through which one event spreads.

Worked examples

Example 1

A bank's core payment system is locked by ransomware for two days. No customer data is stolen. Which CIA element is mainly breached, and is the bank's response a security or resilience matter? Choose: (A) Confidentiality, security; (B) Integrity, security; (C) Availability, resilience; (D) Confidentiality, resilience.

Show the solution
  1. Identify the effect: the system cannot be used, so services are unavailable.
  2. No data was stolen, so confidentiality is not the main issue. No data was altered, so integrity is not the main issue.
  3. The key question is whether the bank can keep or restore critical payments, which is about continuity and recovery.
  4. That is the resilience question, not just prevention.

Answer: (C) Availability, resilience.

Example 2

A risk committee says: 'We spent heavily on firewalls and encryption, so cyber risk is now eliminated and resilience planning is unnecessary.' Evaluate this statement.

Show the solution
  1. Firewalls and encryption are protective controls. They are part of security.
  2. Adversaries adapt, and insiders and vendors create other routes in, so some attacks may still succeed.
  3. Resilience covers detection, response, recovery and learning, which protective controls do not provide.
  4. Cyber risk is part of operational risk and is managed within appetite, not eliminated.

Answer: The statement is wrong. Protective controls reduce likelihood but cannot remove cyber risk. The bank still needs detection, response, recovery and testing so it can keep critical services running after a breach.

Exam tips

  • Expect scenario questions that test the distinction between security and resilience. Look for words like 'recover', 'critical services' and 'continue'.
  • Always link cyber to the Basel operational risk definition when asked about classification.
  • Reject absolute answers such as 'eliminate' or 'fully prevent'.
  • Remember why banks are targets: valuable assets, interconnection, technology dependence and systemic importance.
  • Third-party and shared-vendor dependence often appears as the feature that distinguishes cyber from traditional operational risk.

Practice questions from Cyber-resilience: Range of Practices

Cyber Risk and Cyber Resilience Fundamentals in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Cyber Risk and Cyber Resilience Fundamentals: frequently asked questions

What is cyber resilience in FRM Part II?

It is the ability of a firm to continue delivering critical services during and after a cyber event. It includes prevention, detection, response, recovery and learning. It assumes some attacks will succeed.

What is the difference between cyber security and cyber resilience?

Cyber security focuses on protecting systems and data from attack. Cyber resilience also covers keeping services running and recovering after an incident. Security is one component of resilience.

Is cyber risk a type of operational risk?

Yes, in Basel terms it is a source of operational risk loss, arising from failed systems, people, processes or external events. It often maps to external fraud or business disruption and system failures.

Why are financial institutions prime cyber targets?

They hold money and sensitive data, rely heavily on technology and are closely connected through payments, markets and shared vendors. Disruption can also spread widely, which raises the payoff for attackers.