🔥 3-day streak
ISACA CRISC — Certified in Risk and Information Systems Control115 / 150
Question 115 of 150
A manufacturer purchases a cyber insurance policy to transfer the financial impact of a ransomware event. During the annual policy review, the risk practitioner notices the policy excludes losses arising from unpatched systems and from any state-sponsored attack. The organization's current patching backlog is significant. What should the risk practitioner communicate to management regarding this risk response?
Reviewed for accuracy · Report an issueNext question