nerdexam
Isaca

CRISC · Question #438

An organization operates in an environment where the impact of ransomware attacks is high, with a low likelihood. After quantifying the impact of the risk associated with ransomware attacks exceeds th

The correct answer is B. Ensure business continuity assessments are up to date.. When ransomware risk exceeds appetite and tolerance despite a low likelihood but high impact, the best recommendation is to ensure business continuity assessments are up to date to minimize the disruption and recovery time.

Submitted by ahmad_uae· Apr 18, 2026Risk Response and Reporting

Question

An organization operates in an environment where the impact of ransomware attacks is high, with a low likelihood. After quantifying the impact of the risk associated with ransomware attacks exceeds the organization's risk appetite and tolerance, which of the following is the risk practitioner's BEST recommendation?

Options

  • AObtain adequate cybersecurity insurance coverage.
  • BEnsure business continuity assessments are up to date.
  • CAdjust the organization's risk appetite and tolerance.
  • DObtain certification to a global information security standard.

How the community answered

(37 responses)
  • A
    8% (3)
  • B
    65% (24)
  • C
    22% (8)
  • D
    5% (2)

Why each option

When ransomware risk exceeds appetite and tolerance despite a low likelihood but high impact, the best recommendation is to ensure business continuity assessments are up to date to minimize the disruption and recovery time.

AObtain adequate cybersecurity insurance coverage.

Cybersecurity insurance helps with financial recovery but does not prevent the operational disruption, address the underlying vulnerability, or guarantee full compensation for all types of losses (e.g., reputational damage).

BEnsure business continuity assessments are up to date.Correct

Given the high impact of ransomware attacks that exceed risk appetite and tolerance, even with low likelihood, focusing on organizational resilience and rapid recovery is paramount. Ensuring business continuity (BC) assessments and plans are up to date directly addresses the high impact by minimizing downtime, facilitating recovery efforts, and reducing the overall damage from a successful attack, even if rare.

CAdjust the organization's risk appetite and tolerance.

Adjusting risk appetite and tolerance should be a strategic decision made by leadership, not a primary recommendation from a risk practitioner in response to a specific risk that already exceeds defined limits; the initial action should be to manage the risk within existing parameters.

DObtain certification to a global information security standard.

Certification to a global information security standard helps improve overall security posture, but it is a general control measure and may not directly and specifically address the 'high impact' problem of ransomware as effectively as robust, up-to-date business continuity plans focused on recovery.

Concept tested: Risk response for high-impact events

Source: https://csrc.nist.gov/publications/detail/sp/800-34/rev-1/final

Topics

#Risk Response#Business Continuity#Impact Mitigation#Risk Appetite

Community Discussion

No community discussion yet for this question.

Full CRISC Practice