FRM Part II · FRM Exam Part II · Case Study: Cyberthreats and Information Security Risks
When a bank quantifies cyber risk using scenario analysis, which practice best improves the reliability of the resulting estimates?
Reliability improves by combining structured expert workshops with internal and external loss data, and by documenting assumptions and applying challenge. Single-expert views, internal-only data, or anchoring on last year's largest loss ignore bias and the scarcity of cyber loss data.
- ARelying on a single expert's estimate to ensure consistency
- BUsing only the bank's own historical losses, ignoring external data
- CCombining structured expert workshops with internal and external loss data and documenting assumptions and challengeCorrect
- DSetting the scenario severity equal to last year's largest loss
Explanation
Cyber loss data are scarce and evolving, so scenario analysis is most reliable when expert judgment is structured, informed by internal and external data, and subject to challenge and documentation. A single expert introduces bias; internal-only data omit rare events; last year's maximum is arbitrary.
Did you get it right without looking?
One question tells you little. A timed set on Case Study: Cyberthreats and Information Security Risks shows your real accuracy, how long you take and where you lose marks.
More Case Study: Cyberthreats and Information Security Risks questions
- A bank's security team discovers that a critical vulnerability patch was released by the software vendor four months ago but was never appli…
- A regional bank's risk committee wants a control framework that arranges cyber controls in sequence so that the failure of one control does …
- A bank's risk team wants to express cyber risk in financial terms for the board. Which approach best reflects a quantitative cyber risk meas…
- After a breach, a review finds that the bank's security tools generated alerts about unusual data transfers for several weeks, but the alert…
- Following a ransomware incident, a firm finds its backups were stored on the same network and were encrypted along with production data. Whi…
- A risk manager reviewing a past cyber incident notes the firm had patched critical vulnerabilities only on systems listed in its asset inven…