ISC2 Certified in Cybersecurity (CC)Security PrinciplesHard

A financial institution is performing a risk assessment for its online banking platform. They identify a potential threat actor (a sophisticated hacking group) and a vulnerability (a known flaw in their web server software). They estimate the likelihood of this group exploiting the vulnerability is 'high' and the potential impact of a data breach would be 'catastrophic'. Their board of directors has a 'low' risk appetite for data breaches. Given this information, what is the most appropriate immediate action the institution should take regarding this specific risk?

  1. ATransfer the risk by purchasing a cyber insurance policy.
  2. BAccept the risk, as the platform is already operational.
  3. CAvoid the risk by shutting down the online banking platform.
  4. DMitigate the risk by immediately patching the web server vulnerability.
Show answer & explanation

Correct answer: D. Mitigate the risk by immediately patching the web server vulnerability.

Given a high likelihood, catastrophic impact, and low risk appetite, the most appropriate and immediate action is to mitigate the risk by addressing the known vulnerability. Patching directly reduces the likelihood of exploitation.

Why the other options are wrong

  • A. Transferring risk (insurance) helps with financial recovery but doesn't prevent the breach itself, which is critical given the catastrophic impact and low risk appetite.
  • B. Accepting the risk is inappropriate given the high likelihood, catastrophic impact, and low risk appetite. This would violate the board's stance.
  • C. Avoiding the risk by shutting down the platform is an extreme measure that would severely impact business, and mitigation is a more practical first step for an existing platform.

Risk Treatment (Mitigation)

The process of modifying risk by reducing the likelihood of an event, the impact of an event, or both, often through implementing controls.

  • One of four common risk treatment strategies (mitigate, accept, transfer, avoid).
  • Aims to reduce risk to an acceptable level.
  • Examples include implementing security controls, patching vulnerabilities, and employee training.

Memory trick: MAAT: Mitigate (shield it), Accept (live with it), Avoid (don't do it), Transfer (share it).

More Security Principles questions