CompTIA CySA+ (CS0-003)Reporting and CommunicationMedium

A security analyst is drafting an incident report for a successful ransomware attack. The report needs to clearly articulate the immediate financial impact of the attack to executive leadership. Which of the following would be MOST appropriate to include in the 'Impact Assessment' section?

  1. AA detailed technical analysis of the ransomware variant.
  2. BA list of all compromised user accounts and their associated privileges.
  3. CThe estimated revenue loss due to downtime and cost of recovery efforts.
  4. DThe total number of encrypted files and affected servers.
Show answer & explanation

Correct answer: C. The estimated revenue loss due to downtime and cost of recovery efforts.

For executive leadership, the financial impact is a primary concern. Estimating revenue loss due to downtime and outlining the cost of recovery efforts directly addresses the financial implications of the ransomware attack, which is central to an 'Impact Assessment' for executives.

Why the other options are wrong

  • A. This is a technical detail more relevant to the 'Analysis' section, not direct financial impact for executives.
  • B. This relates to the scope of compromise and potential for further risk, not the immediate financial impact of the attack.
  • D. While important for scope, this quantifies technical impact, not the immediate financial impact for executive leadership.

Financial Impact Assessment

Quantifying the monetary costs associated with a cybersecurity incident, including direct costs (e.g., recovery, legal) and indirect costs (e.g., lost revenue, reputational damage).

  • Crucial for executive decision-making.
  • Includes both tangible and intangible costs.
  • Often involves business continuity and disaster recovery metrics.

Memory trick: For executives, impact means money lost, not just tech details.

More Reporting and Communication questions