FRM Exam Part II · Cyber-resilience: Range of Practices
Cyber Risk Governance and Strategy for FRM Part II
Updated 11 October 2026 · Fact-checked
Cyber risk governance is how a firm assigns accountability for cyber risk. The board and senior management set strategy and risk appetite, the three lines of defense split ownership, oversight and assurance, and the cyber framework plugs into enterprise risk management. To solve questions, match each duty to the right body.
Understand Cyber Risk Governance and Strategy
Cyber risk is the risk of loss from failure, misuse or attack on information and technology systems. It is treated as an operational risk with strategic and systemic reach. Governance answers one question: who is accountable, and how do they know it is working?
The board sets the tone. It approves the cyber strategy and the cyber risk appetite, challenges management, and makes sure resources are enough. It does not run controls day to day. Senior management turns strategy into policies, budgets, roles and reporting, and is accountable to the board for execution.
Cyber risk appetite is the amount and type of cyber risk the firm is willing to accept to reach its goals. It is usually written as qualitative statements plus quantitative tolerances, such as limits on critical-system downtime, time to detect and recover, unpatched critical vulnerabilities, or expected loss from incidents. Appetite is the broad level; tolerance is the measurable limit; KRIs warn when you approach it.
The three lines of defense assign roles. The first line (business and IT/security operations) owns and manages the risk and runs controls. The second line (independent cyber or operational risk management and compliance) sets the framework, challenges the first line and monitors. The third line (internal audit) gives independent assurance to the board on whether the framework works.
Cyber governance should align with enterprise risk management (ERM). That means the same risk taxonomy, appetite process, risk assessment scales, escalation and reporting as other risks, so cyber can be compared and aggregated with credit, market and other operational risks. A separate, isolated cyber programme is a weakness.
Key formulas to remember
- Board role
- Board = approve strategy and appetite + oversee + challenge
- The board does not design or operate technical controls.
- Appetite cascade
- Risk appetite → risk tolerances → limits and KRIs
- Appetite is broad; tolerances and KRIs are measurable and monitored.
- Three lines of defense
- 1st line = own and manage; 2nd line = oversee and challenge; 3rd line = independent assurance
- Internal audit is the third line and must stay independent of the first two.
- Risk tolerance test
- Actual metric ≤ tolerance → within appetite; actual > tolerance → escalate
- Applies when a higher value is worse, such as hours of downtime.
How to solve Cyber Risk Governance and Strategy questions
Governance questions test whether you can match a responsibility to the right party and spot a breach of governance principles.
- 1Identify what the question asks: a role, a framework element, an appetite issue or a weakness.
- 2Name the actors in the scenario: board, senior management, first, second or third line.
- 3Apply the split: board approves and oversees; management implements; lines own, challenge or assure.
- 4For appetite questions, check the cascade: appetite, then tolerance, then KRI and limit, then escalation.
- 5Check independence: second line and audit must not own the controls they review.
- 6Check ERM alignment: common taxonomy, reporting and aggregation with other risks.
- 7Eliminate options that give the board operational tasks or give audit ownership of controls.
- 8Pick the option that fits the principle most precisely.
Quickest way: Who-does-what filter
When to use it: Use when options list several parties and tasks and time is short.
- Label the task as set, run, challenge or assure.
- Map: set = board; run = first line or management; challenge = second line; assure = internal audit.
- Reject any option that mixes two labels in one party, such as audit running controls.
- If appetite is involved, prefer the option with measurable tolerances approved by the board.
Common mistakes in Cyber Risk Governance and Strategy
Giving the board day-to-day control responsibility.
Accountability is confused with operation.
Fix: The board approves, oversees and challenges. Management and the first line operate controls.
Treating internal audit as the second line.
Audit and risk management both feel like control functions.
Fix: Audit is the third line and provides independent assurance. The second line sets the framework and challenges.
Confusing risk appetite with risk tolerance.
Both words describe how much risk is acceptable.
Fix: Appetite is the overall level of risk accepted. Tolerance is the specific measurable limit that supports it.
Setting appetite as zero tolerance for all cyber incidents.
Security teams want no breaches.
Fix: Some residual cyber risk always remains. Appetite should be realistic, tied to critical services, and measurable.
Running cyber as a separate silo from ERM.
Cyber is seen as purely technical.
Fix: Use the enterprise taxonomy, scales and reporting so cyber can be compared and aggregated.
Worked examples
Example 1
A bank's security team in the first line also performs the independent testing of its own controls and reports results to the board. Which governance weakness is most evident? (A) Board has too much operational input (B) Lack of independent challenge and assurance (C) Risk appetite is too high (D) Cyber is aligned too closely with ERM
Show the solution
- The first line owns the controls.
- It is also testing and reporting on them, so no independent party reviews its work.
- Independent challenge belongs to the second line and assurance to the third line.
- Options A, C and D are not described in the scenario.
Answer: B. The firm lacks independent challenge and assurance because the control owner is assessing itself.
Example 2
A firm's board states it has low appetite for cyber risk. Management sets a tolerance that critical payment systems may be unavailable for no more than 2 hours, and recovery tests show 5 hours. What should happen? (A) Nothing, since appetite is qualitative (B) Escalate the breach of tolerance to senior management and board and agree remediation (C) Raise the tolerance to 5 hours silently (D) Ask internal audit to fix the recovery process
Show the solution
- Tolerance is 2 hours; measured recovery is 5 hours, so 5 > 2.
- The tolerance is breached, so the firm is outside appetite for this service.
- Breaches must be escalated through governance so the board can accept, remediate or change tolerance.
- Changing tolerance silently undermines governance, and audit must not own remediation to stay independent.
Answer: B. Escalate the breach and agree a remediation plan; any change to tolerance needs proper approval.
Exam tips
- Memorise the three-line split and watch for options that blur independence.
- Expect scenarios where a measured metric exceeds a tolerance. The answer is usually escalation.
- Board answers are about approving, overseeing and challenging, not operating.
- Look for ERM alignment words such as common taxonomy and aggregation.
- Distinguish appetite, tolerance and KRI by whether they are broad, limit or early warning.
Practice questions from Cyber-resilience: Range of Practices
- After a ransomware attack encrypts a payment processor's production systems, the firm restores from backups that were stored on the same net…
- A bank runs a cyber risk assessment and finds that a customer-facing payment application has a high-severity vulnerability. Threat intellige…
- A bank backs up its core ledger to an offsite site every 4 hours. A ransomware attack corrupts the primary system 3 hours after the last bac…
- A bank performs a cyber risk assessment of its payments platform. Inherent risk is rated 'High'. Existing controls are assessed as reducing …
- During a cyber incident, a bank's crisis team debates when to notify regulators and customers. Which practice is most consistent with sound …
Cyber Risk Governance and Strategy in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Cyber Risk Governance and Strategy: frequently asked questions
What are the board's responsibilities for cyber risk?
The board approves the cyber strategy and risk appetite, oversees management and challenges it. It makes sure resources and expertise are adequate and receives regular reporting. It does not operate technical controls.
How do you set cyber risk appetite?
Start from business objectives and critical services. Define appetite statements, then measurable tolerances such as maximum downtime or recovery time. Add KRIs and escalation triggers, and have the board approve and review them regularly.
How do the three lines of defense apply to cyber risk?
The first line owns and manages cyber risk and controls. The second line sets the framework, monitors and challenges. The third line, internal audit, independently assures the board that the framework works.
Why must cyber governance align with ERM?
Alignment gives a common taxonomy, assessment scales and reporting. This lets management compare and aggregate cyber risk with other risks and make consistent decisions on capital and resources.