Skip to content

FRM Part II · FRM Exam Part II · Case Study: Cyberthreats and Information Security Risks

Which feature of cyber risk most complicates its quantification relative to other operational risk categories?

Cyber risk is hard to quantify because historical loss data are limited and under-reported, threats evolve quickly, and losses can be highly correlated across systems and firms. These features create fat tails and make past data a weak guide, so scenario analysis supplements statistics.

  1. ACyber losses are always small and frequent, giving abundant data
  2. BLimited historical loss data, evolving threats and correlated losses across firms and systemsCorrect
  3. CCyber losses cannot have any financial impact
  4. DRegulators prohibit the use of scenario analysis for cyber risk

Explanation

Cyber threats change quickly, incident data are scarce and under-reported, and events such as a shared vendor failure or widespread malware can hit many systems at once, creating correlation and fat tails. Losses are not uniformly small, and scenario analysis is widely used.

Did you get it right without looking?

One question tells you little. A timed set on Case Study: Cyberthreats and Information Security Risks shows your real accuracy, how long you take and where you lose marks.

More Case Study: Cyberthreats and Information Security Risks questions