Cisco Certified Support Technician (CCST) CybersecurityRisk ManagementMedium

A small business is considering implementing a new customer relationship management (CRM) system. During the risk assessment, it's determined that a data breach could lead to significant financial losses and reputational damage. The business decides to purchase a cyber insurance policy to cover potential financial impacts from such a breach. Which risk mitigation strategy is being employed here?

  1. ARisk Acceptance
  2. BRisk Avoidance
  3. CRisk Transfer
  4. DRisk Reduction
Show answer & explanation

Correct answer: C. Risk Transfer

Purchasing a cyber insurance policy shifts the financial burden of a data breach from the business to the insurance provider. This action is a classic example of risk transfer.

Why the other options are wrong

  • A. Risk acceptance would mean doing nothing and bearing the full consequences.
  • B. Risk avoidance would mean not implementing the CRM system at all to avoid the risk.
  • D. Risk reduction (or mitigation) involves implementing controls to decrease the likelihood or impact of the breach itself, not just its financial aftermath.

Risk Transfer

A risk response strategy that involves shifting the potential impact of a risk to a third party, often through insurance or outsourcing.

  • Does not eliminate the risk, but changes who bears the cost.
  • Commonly achieved through insurance policies.
  • Can also involve contractual agreements with suppliers.

Memory trick: Accept, Transfer, Avoid, Reduce: The A.T.A.R. of risk.

More Risk Management questions