FRM Part II · FRM Exam Part II · Digital Resilience and Financial Stability: The Quest for Policy Tools in the Financial Sector
A regional bank's risk committee is debating why cyber risk can threaten financial stability and not just individual firms. Which feature of cyber incidents best explains their potential to become systemic?
Cyber incidents become systemic because common technology providers and interconnected networks create correlated exposures, allowing one failure or attack to spread across many institutions simultaneously. This concentration and interconnectedness prevents diversification and amplifies operational disruption into broader financial instability.
- ACyber losses are always larger than credit losses at any single bank
- BCommon technology providers and interconnected networks let a single failure propagate across many institutions at onceCorrect
- CCyber incidents only affect firms that hold insufficient regulatory capital
- DCyber risk is fully diversifiable across a large number of financial firms
Explanation
Shared third-party providers, common software and interconnected payment and messaging networks create correlated exposures, so one event can hit many firms simultaneously. Option A is not generally true, C is false because capital level does not determine exposure, and D is wrong because concentration makes the risk hard to diversify.
Did you get it right without looking?
One question tells you little. A timed set on Digital Resilience and Financial Stability: The Quest for Policy Tools in the Financial Sector shows your real accuracy, how long you take and where you lose marks.
More Digital Resilience and Financial Stability: The Quest for Policy Tools in the Financial Sector questions
- An analyst argues that cyber insurance can fully substitute for investment in operational resilience at financial institutions. Which is the…
- A supervisor is assessing the financial stability implications of a severe but plausible cyber event that disables a systemically important …
- A bank has 20 critical services. Provider A supports 8, Provider B supports 6, Provider C supports 4 and Provider D supports 2, each service…
- A regional bank suffers a ransomware attack and notices that attackers are using a technique that has not yet been publicly documented. The …
- A bank's critical payment processing runs on a single cloud service provider that also hosts the platforms of most of its peer banks in the …
- A major cloud provider used by many banks suffers a multi-day outage. Which crisis-coordination arrangement would most directly reduce the r…