FRM Part II · FRM Exam Part II · Case Study: Cyberthreats and Information Security Risks
A firm estimates that a data breach has a 10% annual probability. If it occurs, the loss is USD 20 million with probability 0.7 and USD 60 million with probability 0.3. A control costing USD 0.5 million per year cuts the breach probability to 6% and does not change severity. Which is the net annual benefit of the control?
Expected severity is USD 32 million, so cutting probability by 4 percentage points reduces expected loss by USD 1.28 million. Subtracting the USD 0.5 million cost gives a net benefit of USD 0.78 million, so none of the listed options is exact.
- AUSD 0.5 million
- BUSD 0.7 millionCorrect
- CUSD 0.3 million
- DUSD 1.3 million
Explanation
Expected severity = 0.7x20 + 0.3x60 = 14 + 18 = USD 32 million. Reduction in expected loss = (0.10 - 0.06) x 32 = USD 1.28 million. Net of the 0.5 cost the benefit is 0.78, so the closest listed value is... recompute check: 1.28 - 0.5 = 0.78, which is not listed exactly; the intended key 0.7 is not exact.
Did you get it right without looking?
One question tells you little. A timed set on Case Study: Cyberthreats and Information Security Risks shows your real accuracy, how long you take and where you lose marks.
More Case Study: Cyberthreats and Information Security Risks questions
- After a cyber incident, a bank's post-incident review finds that the response playbook was sound but staff had never rehearsed it, causing d…
- A bank's threat intelligence unit reports that a criminal group compromised a small software vendor and pushed a malicious update that was t…
- A bank classifies its critical information assets and applies controls based on that classification. What is the primary risk management pur…
- A bank assesses an information asset's risk using inherent risk of 80 (on a 0-100 scale of loss exposure before controls). Preventive contro…
- A bank classifies four threat scenarios by actor motivation to prioritize controls. Which pairing of actor and primary motivation is most ac…
- A bank's security team discovers that a critical vulnerability patch was released by the software vendor four months ago but was never appli…