FRM Part II · FRM Exam Part II · Risk Mitigation
A bank's board reviews a proposal for cyber insurance to mitigate losses from data breaches. Which statement best reflects a sound view of insurance as part of the bank's cyber risk mitigation?
Insurance transfers part of the financial loss but leaves reputational damage, regulatory consequences and operational disruption with the bank. Policies have limits, deductibles and exclusions, and they do not reduce breach probability, so insurance complements rather than replaces preventive and detective controls.
- AInsurance eliminates the need for preventive controls because losses are fully reimbursed
- BInsurance transfers part of the financial loss but leaves reputational damage, regulatory consequences and operational disruption largely with the bankCorrect
- CInsurance reduces the probability of a breach by shifting responsibility to the insurer
- DInsurance is only appropriate for risks that have already been fully controlled
Explanation
Insurance is a risk transfer tool for financial loss, subject to limits, deductibles and exclusions. It does not remove reputational harm, regulatory action or disruption, and it does not lower breach likelihood. It complements, not replaces, controls.
Did you get it right without looking?
One question tells you little. A timed set on Risk Mitigation shows your real accuracy, how long you take and where you lose marks.
More Risk Mitigation questions
- Which testing approach best demonstrates that a firm can actually remain within its impact tolerances for an important business service duri…
- A payments bank is drafting its business continuity plan for its card-authorisation service. Which measure defines the maximum amount of dat…
- A bank's payments unit identifies that a manual reconciliation step causes frequent errors. Management decides to automate the step and add …
- A bank's operational risk team reviews a payments process in which the same employee can create a new beneficiary, approve the payment and r…
- After a breach investigation, a bank finds that an attacker used stolen credentials of a vendor to move laterally from a low-sensitivity rep…
- During due diligence on a prospective cloud service provider, which finding should most concern a bank's risk committee when the service sup…