Skip to content

FRM Part II · FRM Exam Part II · Cyber-resilience: Range of Practices

During a cyber incident, a bank's crisis team debates when to notify regulators and customers. Which practice is most consistent with sound cyber-resilience response planning?

Sound practice is to predefine communication protocols and escalation triggers, covering regulators, customers and other stakeholders, and to rehearse them through exercises. This enables timely, coordinated notification rather than waiting for complete forensics or confirmed losses.

  1. AWait until forensic analysis is complete before any communication is drafted
  2. BPredefine communication protocols and escalation triggers, including regulator and customer notification, and rehearse them in exercisesCorrect
  3. CLeave all external communication to the IT security team without senior involvement
  4. DAvoid notification unless customer losses have been confirmed

Explanation

Effective response relies on pre-agreed communication plans, clear triggers and roles, tested through exercises. Waiting for full forensics delays notification, and excluding senior management or requiring confirmed losses undermines timely, coordinated response.

Did you get it right without looking?

One question tells you little. A timed set on Cyber-resilience: Range of Practices shows your real accuracy, how long you take and where you lose marks.

More Cyber-resilience: Range of Practices questions