Skip to content

FRM Part II · FRM Exam Part II · Case Study: Cyberthreats and Information Security Risks

When a bank quantifies cyber risk using scenario analysis, which practice best improves the reliability of the resulting estimates?

Reliability improves by combining structured expert workshops with internal and external loss data, and by documenting assumptions and applying challenge. Single-expert views, internal-only data, or anchoring on last year's largest loss ignore bias and the scarcity of cyber loss data.

  1. ARelying on a single expert's estimate to ensure consistency
  2. BUsing only the bank's own historical losses, ignoring external data
  3. CCombining structured expert workshops with internal and external loss data and documenting assumptions and challengeCorrect
  4. DSetting the scenario severity equal to last year's largest loss

Explanation

Cyber loss data are scarce and evolving, so scenario analysis is most reliable when expert judgment is structured, informed by internal and external data, and subject to challenge and documentation. A single expert introduces bias; internal-only data omit rare events; last year's maximum is arbitrary.

Did you get it right without looking?

One question tells you little. A timed set on Case Study: Cyberthreats and Information Security Risks shows your real accuracy, how long you take and where you lose marks.

More Case Study: Cyberthreats and Information Security Risks questions