FRM Part II · FRM Exam Part II · Case Study: Cyberthreats and Information Security Risks
Which feature of cyber risk most complicates its quantification relative to other operational risk categories?
Cyber risk is hard to quantify because historical loss data are limited and under-reported, threats evolve quickly, and losses can be highly correlated across systems and firms. These features create fat tails and make past data a weak guide, so scenario analysis supplements statistics.
- ACyber losses are always small and frequent, giving abundant data
- BLimited historical loss data, evolving threats and correlated losses across firms and systemsCorrect
- CCyber losses cannot have any financial impact
- DRegulators prohibit the use of scenario analysis for cyber risk
Explanation
Cyber threats change quickly, incident data are scarce and under-reported, and events such as a shared vendor failure or widespread malware can hit many systems at once, creating correlation and fat tails. Losses are not uniformly small, and scenario analysis is widely used.
Did you get it right without looking?
One question tells you little. A timed set on Case Study: Cyberthreats and Information Security Risks shows your real accuracy, how long you take and where you lose marks.
More Case Study: Cyberthreats and Information Security Risks questions
- When a bank builds a cyber loss distribution using a loss distribution approach, which statement about combining frequency and severity is m…
- An insider at an investment firm emails a spreadsheet of client portfolios to a personal account, but the spreadsheet remains unchanged and …
- A bank's risk team estimates that a ransomware event occurs on average 0.4 times per year (Poisson frequency). Each event causes an expected…
- A firm's business continuity plan relies on a single cloud provider for both production and backup data. Which weakness does this most clear…
- A bank's security team notes that its intrusion detection tools produce thousands of alerts daily, and analysts miss genuine attacks because…
- A bank's cyber risk team uses a three-lines model. An internal audit function reports that the IT security team both designs access controls…