CRISC Certified in Risk and Information Systems ControlRisk Response and ReportingMedium

A financial services organization has identified a significant risk of data exfiltration due to sophisticated phishing attacks targeting its employees. The current controls include email filters and basic security awareness training. To effectively reduce this risk, which of the following control enhancements would be MOST appropriate for implementation?

  1. ADeploying an intrusion detection system (IDS) at the network perimeter to identify suspicious outbound traffic.
  2. BEnhancing security awareness training with simulated phishing exercises and specific guidance on identifying advanced threats.
  3. CImplementing a more robust data loss prevention (DLP) system to monitor and block sensitive data transfers.
  4. DPurchasing cyber insurance to cover potential financial losses resulting from data breaches.
Show answer & explanation

Correct answer: B. Enhancing security awareness training with simulated phishing exercises and specific guidance on identifying advanced threats.

To address the risk of data exfiltration specifically from sophisticated phishing attacks, improving employee awareness and their ability to detect such attacks is the most direct and effective preventive control. While other options have merit, they are either reactive, focus on a different stage, or transfer the risk rather than directly reducing the likelihood of the attack vector.

Why the other options are wrong

  • A. An IDS primarily detects network intrusions and suspicious traffic but may not prevent the initial successful phishing attempt that leads to data exfiltration.
  • C. DLP is a detective/preventive control for data exfiltration but doesn't directly address the initial phishing vector as effectively as training.
  • D. Cyber insurance is a risk transfer mechanism, not a control enhancement that reduces the likelihood or impact of the risk itself.

Risk Likelihood Reduction

Strategies and controls implemented to decrease the probability or frequency of a specific risk event occurring.

  • Focuses on preventing the risk from materializing.
  • Often involves preventive controls.
  • Can include process improvements, training, and technology safeguards.

Memory trick: Likelihood's low when prevention's strong, so phishing's gone.

More Risk Response and Reporting questions