nerdexam
Isaca

CISM · Question #662

An organization has recently purchased cybersecurity insurance after the board voiced concern about the potential for a security breach. With this response to the perceived risk, the organization:

The correct answer is A. remains ultimately accountable for the impact of a breach. Even with cybersecurity insurance, the organization retains ultimate accountability for managing the consequences of a breach, including legal, regulatory, and reputational impacts. Insurance may mitigate financial loss but does not transfer overall responsibility.

Submitted by fatima_kr· Apr 18, 2026Information Security Risk Management

Question

An organization has recently purchased cybersecurity insurance after the board voiced concern about the potential for a security breach. With this response to the perceived risk, the organization:

Options

  • Aremains ultimately accountable for the impact of a breach.
  • Bhas implemented redundant controls against a breach.
  • Ccan safely reduce its internal security expenditure.
  • Dhas avoided the risk associated with a security breach.

How the community answered

(47 responses)
  • A
    89% (42)
  • B
    2% (1)
  • C
    4% (2)
  • D
    4% (2)

Explanation

Even with cybersecurity insurance, the organization retains ultimate accountability for managing the consequences of a breach, including legal, regulatory, and reputational impacts. Insurance may mitigate financial loss but does not transfer overall responsibility.

Topics

#Risk management#Risk transfer#Cybersecurity insurance#Accountability

Community Discussion

No community discussion yet for this question.

Full CISM Practice