Cisco Certified Support Technician (CCST) CybersecurityRisk ManagementMedium

A security team is evaluating the risk of an insider threat stealing sensitive intellectual property. They estimate the probability of such an event occurring in a year is 0.01 (or 1%). The financial loss if this happens is estimated to be $10,000,000, and the reputational damage, though hard to quantify, is considered 'Catastrophic'. What component of the risk assessment is primarily being focused on when considering the 'Catastrophic' reputational damage?

  1. AAsset Value (AV)
  2. BImpact
  3. CExposure Factor (EF)
  4. DAnnualized Rate of Occurrence (ARO)
Show answer & explanation

Correct answer: B. Impact

The 'Catastrophic' reputational damage directly describes the consequence or severity of the insider threat event, which is a key component of assessing the impact of a risk. While financial loss is also impact, 'Catastrophic' specifically refers to the qualitative severity.

Why the other options are wrong

  • A. Asset Value (AV) refers to the financial worth of the intellectual property itself, not the damage incurred.
  • C. Exposure Factor (EF) is a percentage of asset value lost, used to calculate SLE, but 'Catastrophic' is a direct descriptor of consequences.
  • D. Annualized Rate of Occurrence (ARO) is the 0.01 probability mentioned, not the damage.

Risk Impact

The magnitude of harm or loss that would result if a risk event occurs, often assessed in terms of financial, operational, or reputational consequences.

  • Can be qualitative (e.g., Low, Medium, High) or quantitative (e.g., monetary value).
  • One of two primary factors in determining overall risk level (with likelihood).
  • Considers direct and indirect consequences.

Memory trick: Threats exploit Vulnerabilities, hitting Assets, causing Impact and Likelihood.

More Risk Management questions