A bank purchases a cyber-insurance policy to fund the financial impact of a customer-data breach. A regulator later asks who remains answerable for protecting that data following the purchase. What should the risk practitioner explain about transferring risk in this way?
- AThe insurer now bears accountability for safeguarding the customer data once the premium is paid.
- BTransfer moves the financial impact to the insurer, yet accountability for the risk stays with the bank. Correct
- CTransferring the risk removes the breach exposure entirely, so the register entry can now be closed.
- DBuying the policy converts the residual risk into an avoided risk for reporting purposes.
Why A is wrong: It is tempting to think paying a premium hands over the duty, but an insurer funds loss and never assumes the organisation's legal duty to protect data.
Why B is correct: Insurance shifts the cost of loss to a third party, but the organisation retains accountability and its regulatory duty to protect the data it holds.
Why C is wrong: Closing the entry looks tidy, but transfer addresses only financial impact and the underlying breach exposure and its ownership both remain.
Why D is wrong: Relabelling it as avoided seems convenient, but avoidance means ending the activity, which insuring the data plainly does not achieve.