CRO Cybersecurity Risk Management 3 — Questions and Answers
Question 1: A CRO must evaluate whether to purchase cyber liability insurance. Which factor most directly determines the appropriateness of the coverage limit?
- The insurer's financial strength rating
- The organization's maximum probable cyber loss exposure (Correct answer)
- The number of prior claims filed by the organization
- The premium cost relative to the IT budget
Correct answer: The organization's maximum probable cyber loss exposure
Coverage limits should be calibrated to the organization's maximum probable loss exposure so that the policy meaningfully transfers residual risk.
Question 2: Under the SEC's 2023 cybersecurity disclosure rules, public companies must disclose material cybersecurity incidents within how many business days of determining materiality?
- 3 business days
- 5 business days
- 10 business days (Correct answer)
- 30 business days
Correct answer: 10 business days
The SEC's 2023 rules require public companies to file Form 8-K disclosing material cybersecurity incidents within four business days of determining the incident is material (approximately equivalent to 10 calendar days in practice — but the rule states four business days).
Question 3: Which cybersecurity control type is classified as 'detective' rather than 'preventive'?
- Multi-factor authentication
- Network segmentation
- Security Information and Event Management (SIEM) (Correct answer)
- Data loss prevention (DLP) blocking rules
Correct answer: Security Information and Event Management (SIEM)
SIEM systems aggregate and analyze logs to identify suspicious activity after it occurs, making them detective controls rather than preventive ones.
Question 4: A CRO is performing a Business Impact Analysis (BIA) for cyber risk. What does the Recovery Time Objective (RTO) specifically measure?
- The maximum tolerable data loss measured in time
- The maximum acceptable time to restore a system to normal operations (Correct answer)
- The financial cost of system downtime per hour
- The time required to detect a cybersecurity breach
Correct answer: The maximum acceptable time to restore a system to normal operations
RTO defines the maximum acceptable duration for restoring a business function or system after disruption before unacceptable consequences occur.
Question 5: An organization is assessing supply chain cyber risk. Which vendor due diligence approach provides the most objective assurance about a vendor's security posture?
- Reviewing the vendor's self-completed security questionnaire
- Requiring a SOC 2 Type II report from an independent auditor (Correct answer)
- Checking the vendor's marketing materials for security claims
- Conducting an informal phone interview with the vendor's IT team
Correct answer: Requiring a SOC 2 Type II report from an independent auditor
A SOC 2 Type II report provides independent, audited evidence that security controls were operating effectively over a sustained period, unlike self-assessments.
Question 6: Which term describes the practice of simulating an adversary's tactics, techniques, and procedures (TTPs) to test an organization's detection and response capabilities?
- Vulnerability scanning
- Red team exercise (Correct answer)
- Penetration testing
- Tabletop exercise
Correct answer: Red team exercise
Red team exercises simulate realistic adversary behavior using real-world TTPs to test whether the organization can detect and respond to sophisticated attacks.
Question 7: A CRO is implementing a cyber risk register. Which attribute is most important to capture for each identified cyber risk?
- The name of the IT staff member responsible for the system
- Likelihood, impact, control effectiveness, and risk owner (Correct answer)
- The original purchase price of affected technology assets
- The vendor contact information for relevant software
Correct answer: Likelihood, impact, control effectiveness, and risk owner
A complete risk register entry must capture likelihood, impact, current control effectiveness, and assigned risk owner to enable prioritization and accountability.
A CRO must evaluate whether to purchase cyber liability insurance.
Which factor most directly determines the appropriateness of the coverage limit?