FRM Part II · FRM Exam Part II · Case Study: Cyberthreats and Information Security Risks
A bank estimates that a phishing-led breach occurs with annual frequency 0.4 and an average loss of USD 5 million per event. A proposed control program costing USD 600,000 per year would cut frequency to 0.25 and cut average loss to USD 4 million. Based on expected annual loss, what is the net annual benefit of the program?
The net annual benefit is USD 400,000. Expected loss falls from USD 2.0 million (0.4 x 5 million) to USD 1.0 million (0.25 x 4 million), a saving of USD 1.0 million, and subtracting the USD 600,000 program cost leaves USD 400,000.
- AUSD 400,000Correct
- BUSD 1,000,000
- CUSD 600,000
- DUSD 1,600,000
Explanation
Current expected loss = 0.4 x 5m = 2.0m. After the program = 0.25 x 4m = 1.0m. Reduction = 1.0m. Net of the 0.6m cost = 0.4m. Ignoring cost gives 1.0m; ignoring the loss-size change (0.15x5m=0.75m, less 0.6m) gives 0.15m; 1.6m adds cost wrongly.
Did you get it right without looking?
One question tells you little. A timed set on Case Study: Cyberthreats and Information Security Risks shows your real accuracy, how long you take and where you lose marks.
More Case Study: Cyberthreats and Information Security Risks questions
- After a cyber incident, a bank's post-incident review finds that the response playbook was sound but staff had never rehearsed it, causing d…
- A bank's threat intelligence unit reports that a criminal group compromised a small software vendor and pushed a malicious update that was t…
- A bank classifies its critical information assets and applies controls based on that classification. What is the primary risk management pur…
- A bank assesses an information asset's risk using inherent risk of 80 (on a 0-100 scale of loss exposure before controls). Preventive contro…
- A bank classifies four threat scenarios by actor motivation to prioritize controls. Which pairing of actor and primary motivation is most ac…
- After an incident, a bank's investigation finds that a former employee's account was never deactivated and was used to download client files…