CompTIA CySA+ (CS0-003)Reporting and CommunicationMedium
During a post-incident review for a significant data breach, the security team is compiling a 'lessons learned' report. The report needs to clearly articulate the financial impact of the breach to inform future budget allocations and risk assessments. Which of the following components should be included to accurately represent the financial cost?
- AMean Time To Recover (MTTR) and Mean Time To Contain (MTTC)
- BTechnical details of the attack vector and vulnerabilities exploited
- CNumber of compromised records and type of data
- DRegulatory fines, legal fees, and customer compensation costs
Show answer & explanationAnswer & explanation
Correct answer: D. Regulatory fines, legal fees, and customer compensation costs
To accurately represent the financial cost of a breach, the 'lessons learned' report should include tangible financial impacts such as regulatory fines, legal fees, and customer compensation, which directly affect budget and financial risk.
Why the other options are wrong
- A. These are incident response metrics, not direct financial costs.
- B. These are technical details of the incident, not financial information.
- C. These are details about the breach, not direct financial costs.
Financial Impact Assessment (Breach)
The process of quantifying the monetary costs associated with a security incident or data breach, including direct expenses, indirect losses, and potential future financial liabilities.
- Includes regulatory fines, legal fees, and litigation costs.
- Covers customer notification and compensation expenses.
- Accounts for reputational damage, lost business, and increased insurance premiums.
Memory trick: Breaches hit the 'wallet' with 'Fines, Fees, and Funds' for customers.