Certified Information Security Manager (CISM)Incident ManagementHard
A global e-commerce company experiences a significant distributed denial-of-service (DDoS) attack that overwhelms its public-facing web servers, making the website inaccessible for several hours. The incident response team successfully mitigates the attack, but the CISO is concerned about the financial impact. When calculating the cost of the incident (COI), which of the following components would be MOST challenging to accurately quantify?
- ALost revenue from customers unable to complete purchases during the outage.
- BDirect costs of incident response services (e.g., third-party DDoS mitigation).
- COvertime wages for internal staff involved in incident recovery.
- DReputational damage and loss of customer trust.
Show answer & explanationAnswer & explanation
Correct answer: D. Reputational damage and loss of customer trust.
Reputational damage and loss of customer trust are intangible costs that are extremely difficult to quantify accurately in monetary terms. While they have a significant long-term impact on business, assigning a precise dollar value is subjective and often requires complex, indirect analyses.
Why the other options are wrong
- A. Lost revenue can be estimated with reasonable accuracy based on historical sales data and conversion rates.
- B. These are direct, quantifiable expenses with invoices or clear service agreements.
- C. Overtime wages are direct, calculable costs based on hourly rates and hours worked.
Intangible Costs of Incidents
Costs associated with an incident that are not easily quantifiable in monetary terms, such as reputational damage, loss of customer trust, and decreased employee morale.
- Difficult to assign a precise monetary value.
- Often have long-term business impacts.
- Require qualitative assessment and estimation.
Memory trick: Some costs are a 'clear receipt,' others are a 'fuzzy feeling' about future business.