Skip to content

FRM Exam Part II · Cyber-resilience: Range of Practices

Cyber Information Sharing, Learning and Evolution

Updated 11 October 2026 · Fact-checked

This topic covers how firms improve cyber resilience over time. They share threat intelligence with peers and regulators, run post-incident reviews to find root causes, feed lessons into controls and plans, and build a cyber-aware culture through training and testing. Solve questions by linking each practice to the weakness it fixes.

Understand Information Sharing, Learning and Evolution

Cyber resilience is not a one-time project. Attackers change tactics, so a firm that stops learning falls behind. This topic covers the part of the framework that keeps defences current: sharing, learning and evolving.

Information sharing means exchanging threat information with other firms, sector bodies, vendors and authorities. Useful items include indicators of compromise (such as malicious IP addresses or file hashes), attacker tactics, vulnerabilities and incident details. The logic is simple. An attack on one bank is often a rehearsal for attacks on others. If one firm warns peers early, all of them can block the threat sooner. Sharing works best with trust, clear rules on what is shared, anonymisation where needed, and legal comfort on confidentiality and data protection. Barriers include fear of reputational damage, legal liability, competitive concerns and poor-quality or late information.

Learning from incidents means a structured review after an event or near miss. The aim is to find root causes, not to blame individuals. A good review covers the timeline, how the attack succeeded, how it was detected, how well the response and recovery worked, and what must change. Actions get owners and deadlines, and are tracked to closure. Near misses and exercise results are also valuable sources of lessons.

Evolution means turning lessons into change: updated controls, revised response and recovery plans, better monitoring, and refreshed risk assessments. Testing such as tabletop exercises, red-team tests and scenario drills checks whether changes work. Senior management and the board should receive reporting on progress.

Culture is the human layer. Staff are often the entry point for phishing and social engineering. Regular training, role-based awareness, a no-blame reporting environment and tone from the top make people part of the defence. Training should be tested, for example with simulated phishing, and updated as threats change.

How to solve Information Sharing, Learning and Evolution questions

Use this sequence for any scenario or definition question in this topic.

  1. 1Identify which practice the question targets: sharing, post-incident learning, continuous improvement or culture.
  2. 2Find the weakness or trigger in the scenario, such as a late warning, a repeated incident, an unreported phishing click or an untested plan.
  3. 3Match the weakness to the practice that fixes it. Late warning points to threat intelligence sharing. Repeat failure points to root-cause analysis and tracked actions.
  4. 4Check for conditions: trust, confidentiality, anonymisation, legal constraints and data protection for sharing; no-blame and ownership for lessons learned.
  5. 5Look for the feedback loop. The best answer usually turns lessons into updated controls, plans and testing.
  6. 6Check governance: board or senior management reporting and accountability.
  7. 7Eliminate options that blame individuals, treat the fix as one-off, or keep information inside the firm without good reason.

Quickest way: Weakness-to-practice match

When to use it: Use when time is short and options look similar.

  1. Name the problem in three words, for example 'repeat incident' or 'slow warning'.
  2. Pick the practice: sharing, review, update or culture.
  3. Choose the option that closes the loop with action and follow-up, not just detection or reporting.
  4. Reject options with blame, secrecy or one-time training.

Common mistakes in Information Sharing, Learning and Evolution

  • Treating information sharing as only a regulatory reporting duty.

    Incident notification to regulators is familiar, so all sharing is assumed to be compliance.

    Fix: Remember sharing also runs between peers, sector groups and vendors, and aims to give early warning, not only to meet rules.

  • Thinking a post-incident review should identify who is at fault.

    Accountability and blame get mixed up.

    Fix: Focus on root causes, process and control gaps. A no-blame approach encourages honest reporting.

  • Stopping the lessons-learned process at the report.

    Writing the review feels like the end of the task.

    Fix: Lessons count only when actions have owners, deadlines and tracking, and changes are tested.

  • Assuming one annual training session builds a cyber-aware culture.

    Training completion is easy to measure.

    Fix: Culture needs ongoing, role-based training, simulated attacks, easy reporting and visible tone from the top.

  • Ignoring near misses and exercises as learning sources.

    Only actual losses seem worth reviewing.

    Fix: Treat near misses, red-team results and drills as evidence of weaknesses before real loss occurs.

  • Ignoring legal and trust barriers to sharing.

    Sharing is assumed to be always beneficial and easy.

    Fix: Name the enablers: trusted forums, anonymisation, clear protocols and legal clarity on confidentiality and data protection.

Worked examples

Example 1

A bank suffers a phishing-led breach. A review finds the same phishing technique was reported by a peer bank through a sector group three weeks earlier, but the alert was never passed to the security team. Which action best addresses the root cause?

Show the solution
  1. The weakness is not detection technology. It is that received threat intelligence did not reach the people who could act.
  2. The relevant practice is information sharing, specifically internal handling of incoming intelligence.
  3. The fix is a defined process to receive, triage and distribute threat information, with owners and timelines, and to turn indicators into blocking rules.
  4. Blaming the person who missed the alert would not fix the process gap.

Answer: Set up a formal process for receiving, assessing and acting on shared threat intelligence, with clear owners, and track it as a lessons-learned action.

Example 2

After a ransomware incident, management proposes a review that records the timeline, closes the file and disciplines the employee who opened the email. Which improvements would a sound lessons-learned process make?

Show the solution
  1. A sound review looks for root causes: email filtering gaps, backup weaknesses, slow containment or unclear roles.
  2. It uses a no-blame approach so staff report incidents quickly in future.
  3. It assigns actions with owners and deadlines and tracks them to closure.
  4. It updates controls and response and recovery plans, tests changes through exercises, and reports progress to senior management or the board.
  5. It also considers sharing sanitised details with peers and authorities to help others.

Answer: Replace the blame-and-close approach with root-cause analysis, tracked remediation actions, updated plans, testing, governance reporting and appropriate sharing.

Exam tips

  • Expect scenario questions where one practice is missing. Name the gap first, then the fix.
  • Prefer answers that create a feedback loop from lessons to updated controls and testing.
  • Watch for blame-based or one-off options. They are usually wrong.
  • For sharing questions, look for trust, confidentiality and legal conditions as enablers or barriers.
  • Culture answers usually involve tone from the top, continuous training and easy reporting.

Practice questions from Cyber-resilience: Range of Practices

Information Sharing, Learning and Evolution: frequently asked questions

What is cyber threat information sharing in the financial sector?

It is the exchange of threat indicators, attacker methods, vulnerabilities and incident details between firms, sector bodies, vendors and authorities. The goal is earlier warning and faster defence across the sector.

What should a lessons-learned review after a cyber incident include?

It should cover the timeline, root causes, how the incident was detected, how response and recovery worked, and what must change. Actions need owners and deadlines and should be tracked to completion.

Why does cyber culture matter in banks?

Staff are a common entry point for attacks like phishing, so their behaviour affects resilience. Ongoing training, no-blame reporting and leadership tone help staff act as a line of defence.

How do I revise this topic quickly for FRM Part II?

Remember the loop: share intelligence, review incidents, update controls and plans, test them and build culture. For each scenario, match the weakness to the practice that fixes it.