IT rates a ransomware event as low consequence because 'we have backups,' without verifying restore time or integrity. What rating practice is wrong?
Select an answer to reveal the explanation.
Short Explanation
Saying 'we have backups' is not the same as proving a fast, clean restore. Do not shrink the blast radius on faith. Score the harm honestly, then show how controls cut residual risk.
Full Explanation
Inherent consequence reflects potential magnitude if the event occurs; residual consequence reflects remaining impact after effective controls. Assuming untested backups justify a low consequence rating conceals exposure. Restore time, integrity checks, and recovery objectives must be verified. Separate control effectiveness from the underlying event severity.