THE SHORT ANSWER
Common risks include phishing and impersonation, stolen or reused credentials, excessive access, lost devices, insecure sharing, outdated software, misconfiguration, ransomware, vendor compromise and accidental data exposure. Prioritize by business impact and exposure rather than fear.
Recognize risk without learning attack methods
| Risk | What can go wrong | Defensive focus |
|---|---|---|
| Credentials | An account is used by the wrong person | Strong authentication and recovery |
| Social engineering | A person is pressured into unsafe action | Independent verification |
| Access | Too many people or tools can act | Least privilege and reviews |
| Devices/software | Loss or outdated components expose work | Updates, inventory and protection |
| Data sharing | Information reaches the wrong place | Minimization and controlled sharing |
| Vendors | A partner connection becomes an exposure | Permission and offboarding review |
| Ransomware/disruption | Operations or data become unavailable | Detection, response and tested recovery |
Start from critical business assets
List essential services, privileged accounts, customer and employee data, payment processes, communications and recovery systems. Consider likelihood, impact and current safeguards; avoid unsupported universal rankings.
Ask seven questions
- What are we protecting?
- Who can access it?
- What could go wrong?
- How would we notice?
- Who responds?
- How do we recover?
- What changes afterward?
Turn guidance into an owned business action
Choose one relevant account, system, data set or workflow. Record the owner, current control, most important failure, detection signal, response step and recovery dependency. Escalate specialist, legal or regulatory questions to qualified advisers for the applicable context.
Sources & further reading
- The NIST Cybersecurity Framework 2.0
National Institute of Standards and Technology. Current outcome-based guidance for governing, identifying, protecting, detecting, responding to and recovering from cybersecurity risk. It does not prescribe one implementation.
- Phishing Guidance: Stopping the Attack Cycle at Phase One
Cybersecurity and Infrastructure Security Agency. Current defensive guidance on phishing resistance, MFA and organisational controls. Specific authentication choices depend on service support and risk.
Examples and exercises are illustrative unless attributed to a source. No independent expert review is claimed.
A correction, a counterexample or an experience worth sharing?
Join the conversation ↗