QuestionQ893

Risk Response and Reporting

An organization operates in an environment in which ransomware attacks have a high impact but a low likelihood. After quantifying that the impact of the ransomware-related risk exceeds the organization's risk appetite and tolerance, which of the following is the risk practitioner’s BEST recommendation?

  • A Ensure business continuity assessments are up to date.
  • B Obtain adequate cybersecurity insurance coverage.
  • C Obtain certification to a global information security standard.
  • D Adjust the organization's risk appetite and tolerance.
Explanation

Cybersecurity insurance is a risk-transfer measure that can limit the organization’s financial exposure from a ransomware event. It is particularly appropriate for a low-likelihood, high-impact risk whose exposure exceeds established risk appetite and tolerance.

Community Discussion

No comments yet. Be the first to start the discussion!