As enterprises, the government and public moving towards digitalization, cybersecurity has become pivotal to their basic functioning nowadays. Cyberattacks have been on the rise over the past 12-18 months, affecting businesses of all nature and sizes, where the safety of the data network is essential to their operations. As a result, cybersecurity has come to occupy a prime position in a company’s list of governance priorities. As more companies shifted to work from home, there were database breaches and hackings, leading to loss of revenue opportunity across industries. Even systems believed to be highly secure could be breached in cyberattacks. Reports say almost 26,000 Indian websites were hacked in the 10-month period ended October. The hackers had been operating from different parts of the world with hidden identities.
While weak passwords are the common cause for such attacks, systems with unprotected or unchanged passwords are highly vulnerable. Second, different types of malwares in many cases hidden in another type of document only waiting to be executed by the target user. Third, working in unsecured environments such as a common Wi-Fi network to access private emails and USB drives may prove risky. The onus is on the organisation to take steps to prevent and counter potential threats. They should educate their employees to create strong passwords, follow proper protocols in keeping passwords secure. Also, an organisation should regularly ensure that its firewalls are capable to resist any malware attack, by installing regular software updates. This is also why virtual private networks are being insisted upon in organisations.
Internal threats could be a result of employee negligence or ignorance, while external threats could be from former employees, competitors, and hackers who steal corporate data and money through spoofing and phishing. These would obviously lead to reputational damage, financial loss, litigation, regulatory probes, and above all, loss of clients and thereby revenue. Ransomware attacks continue to evolve in the market, with the past 8-10 months witnessing the highest number of threats of sensitive data exposure. A leading social network platform suffered a data breach, wherein millions of profiles containing email addresses, names, dates of birth, and phone numbers were sold on the dark Web.
There are cyber insurance solutions available in the market to protect against losses caused by cyberattacks, including first-party and third-party losses, and cyber extortion.
First-party insurance covers loss caused due to electronic theft, loss of electronic communication, e-vandalism, business interruption (income loss due to fraudulent access causing impairment of operations), and the like. Third-party loss covers disclosure liability (any customer claims due to system security failures resulting in unauthorized access), content liability (for alleged copyright infringement). Cyber extortion occurs when cybercriminals threaten to disable the operations of a target business or compromise its confidential data unless they receive a payment. Companies usually get cyber insurance solution to eliminate the risk, without willingly. Cyber insurance helps cover legal expenses ___________________ from damages due to a cyberattack. It should be part of the company’s overall business continuity strategy, as it helps quickly recover post an incident.
What is cyber extortion?
Correct Answer :
It is a crime involving an attack or threat of an attack coupled with a demand for money in return for stopping or remediating the act.
Solution :
Based on the provided passage and general cybersecurity principles, we can determine the correct definition of cyber extortion by following these steps:
Step 1: Locate the definition of cyber extortion in the passage
The passage explicitly defines cyber extortion in the fifth paragraph:
"Cyber extortion occurs when cybercriminals threaten to disable the operations of a target business or compromise its confidential data unless they receive a payment."
Step 2: Match the passage definition with the options
We analyze the core components of cyber extortion:
1. An action or threat: Disabling operations or compromising confidential data (an attack or threat of an attack).
2. A demand: Demanding a payment (demand for money).
3. The resolution: The threat is withdrawn or remediated once the payment is made.
Step 3: Evaluate the correct option
The option "It is a crime involving an attack or threat of an attack coupled with a demand for money in return for stopping or remediating the act" aligns perfectly with these components and the definition given in the text.
Access expert-curated educational resources and study materials—completely free.
Create, conduct, and manage professional online assessments with Mindyard. Perfect for teachers and institutes.
Copyright © 2026 Mindyard. All Rights Reserved.