FRM Part II · FRM Exam Part II · Cyber-resilience: Range of Practices
During a cyber incident, a bank's crisis team debates when to notify regulators and customers. Which practice is most consistent with sound cyber-resilience response planning?
Sound practice is to predefine communication protocols and escalation triggers, covering regulators, customers and other stakeholders, and to rehearse them through exercises. This enables timely, coordinated notification rather than waiting for complete forensics or confirmed losses.
- AWait until forensic analysis is complete before any communication is drafted
- BPredefine communication protocols and escalation triggers, including regulator and customer notification, and rehearse them in exercisesCorrect
- CLeave all external communication to the IT security team without senior involvement
- DAvoid notification unless customer losses have been confirmed
Explanation
Effective response relies on pre-agreed communication plans, clear triggers and roles, tested through exercises. Waiting for full forensics delays notification, and excluding senior management or requiring confirmed losses undermines timely, coordinated response.
Did you get it right without looking?
One question tells you little. A timed set on Cyber-resilience: Range of Practices shows your real accuracy, how long you take and where you lose marks.
More Cyber-resilience: Range of Practices questions
- After a destructive malware attack, a bank's incident team wants to restore services from backups. Which practice best supports cyber-resili…
- A regional bank classifies its cyber defences into functions. Its security team installs firewalls and multi-factor authentication, runs a s…
- Nordvik Bank's CISO reports to the head of IT, who also owns system delivery deadlines. An internal review finds that security findings are …
- A regulator-style review of a firm's cyber resilience finds that its incident response plan has never been tested against a scenario in whic…
- A bank segments its network so that the payments environment sits in a separate zone with tightly restricted traffic from the corporate netw…
- A mid-sized bank's cyber team receives a threat indicator from an industry sharing forum about a new phishing campaign. Which use of this in…