Skip to content

FRM Part II · FRM Exam Part II · Cyber-resilience: Range of Practices

After a ransomware incident that was contained within hours, a bank's CISO wants the event to improve long-term resilience. Which action best reflects a mature post-incident learning process?

The best practice is a root-cause review whose findings update controls, scenarios and training, with remediation tracked to completion. Merely restoring systems, restricting the review to a few staff, or waiting for the annual assessment fails to turn the incident into lasting improvement.

  1. AClose the incident ticket once systems are restored and report only the recovery time to the board
  2. BConduct a root-cause review, feed findings into control, scenario and training updates, and track remediation actions to completionCorrect
  3. CLimit the review to the IT staff directly involved to avoid disclosing weaknesses
  4. DWait for the next scheduled annual risk assessment to consider any lessons

Explanation

Mature learning goes beyond restoration: root cause analysis, updating controls, scenarios and training, and tracking actions. Narrow or deferred reviews let the same weaknesses persist.

Did you get it right without looking?

One question tells you little. A timed set on Cyber-resilience: Range of Practices shows your real accuracy, how long you take and where you lose marks.

More Cyber-resilience: Range of Practices questions