CRISC · Question #438
An organization operates in an environment where the impact of ransomware attacks is high, with a low likelihood. After quantifying the impact of the risk associated with ransomware attacks exceeds th
The correct answer is B. Ensure business continuity assessments are up to date.. When ransomware risk exceeds appetite and tolerance despite a low likelihood but high impact, the best recommendation is to ensure business continuity assessments are up to date to minimize the disruption and recovery time.
Question
An organization operates in an environment where the impact of ransomware attacks is high, with a low likelihood. After quantifying the impact of the risk associated with ransomware attacks exceeds the organization's risk appetite and tolerance, which of the following is the risk practitioner's BEST recommendation?
Options
- AObtain adequate cybersecurity insurance coverage.
- BEnsure business continuity assessments are up to date.
- CAdjust the organization's risk appetite and tolerance.
- DObtain certification to a global information security standard.
How the community answered
(37 responses)- A8% (3)
- B65% (24)
- C22% (8)
- D5% (2)
Why each option
When ransomware risk exceeds appetite and tolerance despite a low likelihood but high impact, the best recommendation is to ensure business continuity assessments are up to date to minimize the disruption and recovery time.
Cybersecurity insurance helps with financial recovery but does not prevent the operational disruption, address the underlying vulnerability, or guarantee full compensation for all types of losses (e.g., reputational damage).
Given the high impact of ransomware attacks that exceed risk appetite and tolerance, even with low likelihood, focusing on organizational resilience and rapid recovery is paramount. Ensuring business continuity (BC) assessments and plans are up to date directly addresses the high impact by minimizing downtime, facilitating recovery efforts, and reducing the overall damage from a successful attack, even if rare.
Adjusting risk appetite and tolerance should be a strategic decision made by leadership, not a primary recommendation from a risk practitioner in response to a specific risk that already exceeds defined limits; the initial action should be to manage the risk within existing parameters.
Certification to a global information security standard helps improve overall security posture, but it is a general control measure and may not directly and specifically address the 'high impact' problem of ransomware as effectively as robust, up-to-date business continuity plans focused on recovery.
Concept tested: Risk response for high-impact events
Source: https://csrc.nist.gov/publications/detail/sp/800-34/rev-1/final
Topics
Community Discussion
No community discussion yet for this question.