Skip to content

FRM Exam Part II · Cyber-resilience: Range of Practices

Cyber Risk Identification and Assessment for FRM Part II

Updated 11 October 2026 · Fact-checked

Cyber risk identification finds the critical business services and assets that could be hit by cyber events. Assessment then combines threats, vulnerabilities and impact, using threat intelligence and scenario analysis, and quantifies the result. You solve questions by tracing service, asset, threat, weakness, impact, then choosing the right method.

Understand Cyber Risk Identification and Assessment

Start with a simple idea: you cannot protect everything equally. A bank has thousands of systems. Cyber risk identification begins by asking which business services matter most, such as payments, trading or customer access, and which assets support them: data, applications, infrastructure, people and third parties.

Once critical services are mapped, you assess risk. A threat is a source of harm, such as a criminal group, a state actor or an insider. A vulnerability is a weakness that a threat can exploit, such as unpatched software or weak access control. Impact is the damage if it happens: financial loss, outage, data loss, legal cost and reputational harm. Risk comes from all three together.

Threat intelligence feeds this process. It is information on attacker methods, tools and targets, from internal logs, industry sharing groups and commercial or government sources. Good intelligence is timely, relevant to your firm and actionable. It helps you rank which vulnerabilities to fix first.

Quantification is hard because loss data is scarce and attackers adapt. Firms use qualitative ratings, scoring, and frequency-severity models. Scenario analysis fills data gaps: experts build plausible severe events, such as a ransomware attack on a payment system, and estimate loss and recovery time. Scenarios also test whether the firm can stay within its impact tolerance for critical services.

Assessment is not one-off. The environment changes with new technology, new vendors and new attacker methods, so identification and assessment must be repeated and fed by incidents, testing and intelligence.

Key formulas to remember

Risk as a combination
Cyber risk = Threat × Vulnerability × Impact (conceptual)
A conceptual relationship, not a precise calculation. If any factor is near zero, risk is low.
Frequency-severity annual loss
Expected annual loss = Expected number of events per year × Average loss per event
Valid as an expected value when frequency and severity are treated as independent.
Residual risk
Residual risk = Inherent risk − Effect of controls
Conceptual. Inherent risk is before controls; residual is after controls.

How to solve Cyber Risk Identification and Assessment questions

Use this order for any scenario-style question on cyber identification and assessment.

  1. 1Identify the critical business service at stake and its impact tolerance.
  2. 2Map the assets that support it: data, systems, people, third parties.
  3. 3Name the relevant threat actors and their likely methods.
  4. 4Find the vulnerabilities or control gaps those threats could exploit.
  5. 5Estimate impact and likelihood, using data where available and scenario analysis where it is not.
  6. 6Use threat intelligence to prioritise and update the ratings.
  7. 7Compare residual risk with risk appetite and choose the response: mitigate, transfer, accept or avoid.
  8. 8Check that the answer reflects ongoing review, not a one-off exercise.

Quickest way: Service-first elimination

When to use it: Use when a multiple-choice question lists several plausible actions or methods and time is short.

  1. Find the keyword: asset, threat, vulnerability, quantification or scenario.
  2. Prefer answers that start from critical services rather than all systems equally.
  3. Prefer scenario analysis when historical loss data is limited.
  4. Reject options that treat assessment as one-time or purely technical.
  5. Pick the option linking threat intelligence to prioritisation.

Common mistakes in Cyber Risk Identification and Assessment

  • Confusing threat with vulnerability

    Both words sound like danger.

    Fix: A threat is the actor or event; a vulnerability is the weakness it exploits.

  • Starting with all IT assets rather than critical services

    Technical inventories feel complete.

    Fix: Begin with services the business cannot afford to lose, then map supporting assets.

  • Assuming cyber risk can be quantified from ample history

    Credit and market risk have long data series.

    Fix: Remember loss data is limited and attackers adapt, so scenarios and expert judgement are needed.

  • Ignoring third parties and insiders

    Focus stays on external hackers.

    Fix: Include vendors, cloud providers and insiders as sources of exposure.

  • Treating threat intelligence as just a data feed

    Volume is mistaken for value.

    Fix: Good intelligence is relevant, timely and actionable, and changes priorities.

  • Choosing a one-off assessment

    Risk assessments are seen as annual tasks.

    Fix: Choose answers with continuous review after incidents, tests and environmental change.

Worked examples

Example 1

A bank has little internal data on severe cyber losses. It wants to estimate the impact of a ransomware attack on its payments platform. Which approach is most appropriate, and why?

Show the solution
  1. The key constraint is scarce loss data.
  2. Pure statistical models need history, so they would be unreliable.
  3. Scenario analysis uses expert judgement to build a plausible severe event.
  4. The scenario should estimate loss, outage duration and recovery against the impact tolerance for payments.
  5. Results can be informed by threat intelligence and external incident data.

Answer: Use scenario analysis focused on the payments service, supported by threat intelligence, because historical data is insufficient.

Example 2

A bank expects 2 material cyber events per year, with an average loss of USD 3 million per event. What is the expected annual loss, and what does it not tell you?

Show the solution
  1. Expected annual loss = frequency × average severity.
  2. 2 × USD 3 million = USD 6 million.
  3. This is an average. It does not show tail loss from a rare severe event.
  4. It also assumes frequency and severity are independent and stable, which attacker adaptation may break.

Answer: Expected annual loss is USD 6 million; it understates tail risk and should be complemented by scenario analysis.

Exam tips

  • Look for the phrase critical business services; correct answers usually start there.
  • When data is limited, scenario analysis is usually the best answer.
  • Separate threat, vulnerability and impact precisely in definitions.
  • Prefer answers showing continuous, intelligence-informed assessment tied to risk appetite.

Practice questions from Cyber-resilience: Range of Practices

Cyber Risk Identification and Assessment in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Cyber Risk Identification and Assessment: frequently asked questions

How do banks identify cyber risks?

They map critical business services, then the assets that support them, and look for threats and vulnerabilities affecting those assets. Sources include risk self-assessments, testing, incident history and threat intelligence.

Why is cyber risk hard to quantify?

Loss history is limited and attackers change methods. Firms therefore combine frequency-severity estimates with scenario analysis and expert judgement.

What is the role of threat intelligence?

It tells you who is attacking, how and what they target. You use it to prioritise vulnerabilities and update scenarios.

How does scenario analysis help in cyber risk?

It builds severe but plausible events and estimates loss and recovery time. It tests whether critical services stay within impact tolerance.