Learning Objectives:

  • Understand the cyber risk assessment process.

  • Explain vulnerability assessment, penetration testing, and threat intelligence.

  • Describe cyber risk quantification frameworks.

4.1 The Cyber Risk Assessment Process

A thorough and proactive risk assessment is the first step in establishing a sound security program . This is the ongoing process of evaluating threats and vulnerabilities and establishing an appropriate risk management program to mitigate potential monetary losses. Threats have the potential to harm an institution, while vulnerabilities are weaknesses that can be exploited .

The risk assessment process includes four key stages :

  1. Asset Valuation: Identifying and cataloging critical data assets, systems, and infrastructure.

  2. Vulnerability Analysis: Systematic scanning and testing to discover security weaknesses.

  3. Impact Analysis: Determining the business impact of potential security breaches.

  4. Likelihood Determination: Assessing the probability of different threats materialising.

4.2 Vulnerability Assessment and Penetration Testing

Vulnerability assessment tools involve running scans on a system to proactively detect known vulnerabilities such as security flaws and bugs in software and hardware . These tools can also detect holes allowing unauthorised access to a network . Penetration analysis involves an independent party testing an institution’s information system security to identify vulnerabilities in the system and surrounding processes . Using vulnerability assessment tools and performing regular penetration analyses assist institutions in determining what security weaknesses exist in their information systems.

4.3 Cyber Risk Quantification

Cyber risk quantification frameworks (e.g., FAIR) help translate cyber risks into business impacts . This involves:

  • Using simulations and stress tests for cyber risk scenarios.

  • Communicating risk to the board with actionable metrics.

  • Developing cyber risk appetite statements.

  • Quantifying the potential financial impact of different risk scenarios.

4.4 Cyber Threat Intelligence

Building a cyber threat intelligence (CTI) program enables proactive threat identification . Key components include:

  • Intelligence-sharing networks (e.g., FS-ISAC).

  • Threat hunting techniques and tools.

  • Using threat intelligence to enhance Security Operations Centre (SOC) capabilities.

  • Real-world case studies of cyberattacks on banks .