FRM Part II · FRM Exam Part II · Digital Resilience and Financial Stability: The Quest for Policy Tools in the Financial Sector
A regional bank suffers a ransomware attack and notices that attackers are using a technique that has not yet been publicly documented. The bank's risk officer wants peer institutions to be able to block the same technique quickly. Which action best supports the financial-sector objective of collective digital resilience?
The best action is sharing anonymized threat indicators with peers through a trusted sector information-sharing channel. This allows other institutions to block the technique quickly, strengthening collective resilience, whereas delaying disclosure, limiting it to an insurer, or waiting for public reports leaves the sector exposed longer.
- AShare anonymized threat indicators with peers through a trusted sector information-sharing channelCorrect
- BKeep the details confidential until the investigation is finished to avoid reputational damage
- CShare the indicators only with the bank's own cyber insurer
- DWait for regulators to publish a public report before notifying other firms
Explanation
Timely sharing of threat indicators through trusted sector channels lets peers update defenses before the same technique is reused, which reduces the system-wide impact of incidents. Withholding information until an investigation ends or relying on slow public reports delays protection. Sharing only with an insurer does not help peers defend themselves.
Did you get it right without looking?
One question tells you little. A timed set on Digital Resilience and Financial Stability: The Quest for Policy Tools in the Financial Sector shows your real accuracy, how long you take and where you lose marks.
More Digital Resilience and Financial Stability: The Quest for Policy Tools in the Financial Sector questions
- A financial stability authority is weighing capital buffers against operational-resilience requirements as a response to systemic cyber risk…
- A regulator considers using capital requirements as a tool against cyber risk. Which is the strongest argument that capital alone is an insu…
- A regulator is designing a policy toolkit for digital resilience in the financial sector. It considers five tools: (1) mandatory incident re…
- An insurer considers offering cyber coverage to many banks that all depend on the same software vendor. Which is the main concern for the in…
- A bank's risk committee reviews a cyber incident scenario. The bank's critical payment service has a maximum tolerable outage of 4 hours. Te…
- A supervisor wants a policy tool that addresses the risk that many financial institutions rely on the same cloud provider, so that one outag…