Skip to content

CS Professional · Environmental, Social and Governance (ESG) - Principles and Practice · Risk Management

Neelkanth Infra Ltd. has a risk register showing a cyber-breach risk rated high likelihood and high impact. The existing controls are weak, and the cost of full remediation exceeds the maximum expected loss. The Risk Management Committee wants a defensible response consistent with sound practice. Which course is best?

The best course is a cost-benefit assessment followed by proportionate controls and cyber insurance to bring the exposure within appetite, with any residual risk formally documented and reported. Silent acceptance, reactive waiting or total shutdown would be ungoverned or disproportionate.

  1. AAccept the risk silently since remediation costs more than the loss
  2. BIgnore the rating until a breach occurs, then respond
  3. CApply a cost-benefit assessment, implement proportionate controls and cyber insurance to bring the risk within appetite, and document and report any residual risk acceptedCorrect
  4. DAvoid it by shutting down all digital operations immediately

Explanation

Responses should be proportionate and aligned to risk appetite. Combining reduction and transfer, then formally documenting and reporting what is accepted, is defensible. Silent acceptance lacks governance, waiting is reactive, and shutting digital operations is disproportionate to the business.

Did you get it right without looking?

One question tells you little. A timed set on Risk Management shows your real accuracy, how long you take and where you lose marks.

More Risk Management questions