FRM Part II · FRM Exam Part II · Case Study: Cyberthreats and Information Security Risks
A bank's risk team estimates that a ransomware event occurs on average 0.4 times per year (Poisson frequency). Each event causes an expected loss of USD 5 million. Which is the bank's expected annual loss from ransomware?
Expected annual loss equals expected frequency multiplied by expected severity, so 0.4 events per year times USD 5 million gives USD 2.0 million. Other options use the wrong operation, such as dividing or adding the two inputs.
- AUSD 2.0 millionCorrect
- BUSD 12.5 million
- CUSD 5.4 million
- DUSD 4.6 million
Explanation
Expected annual loss = frequency x average severity = 0.4 x 5 = USD 2.0 million. Dividing severity by frequency gives 12.5, which is the wrong operation. Adding the numbers (5.4) or subtracting them (4.6) has no meaning.
Did you get it right without looking?
One question tells you little. A timed set on Case Study: Cyberthreats and Information Security Risks shows your real accuracy, how long you take and where you lose marks.
More Case Study: Cyberthreats and Information Security Risks questions
- A bank estimates a cyber outage of its online platform would occur once every 4 years on average. Each event would cost USD 2.4 million in l…
- A payments firm sets a recovery time objective (RTO) of 4 hours and a recovery point objective (RPO) of 15 minutes for its card authorizatio…
- A bank estimates that a ransomware event has a 5% annual probability. If it occurs, expected loss is USD 20 million. A new offline-backup co…
- After a breach, a review finds that the bank's security tools generated alerts about unusual data transfers for several weeks, but the alert…
- After a cyber incident, a bank's post-incident review finds that the response playbook was sound but staff had never rehearsed it, causing d…
- A bank's threat intelligence unit reports that a criminal group compromised a small software vendor and pushed a malicious update that was t…