THE SHORT ANSWER

Common risks include phishing and impersonation, stolen or reused credentials, excessive access, lost devices, insecure sharing, outdated software, misconfiguration, ransomware, vendor compromise and accidental data exposure. Prioritize by business impact and exposure rather than fear.

Recognize risk without learning attack methods

Common business risks
RiskWhat can go wrongDefensive focus
CredentialsAn account is used by the wrong personStrong authentication and recovery
Social engineeringA person is pressured into unsafe actionIndependent verification
AccessToo many people or tools can actLeast privilege and reviews
Devices/softwareLoss or outdated components expose workUpdates, inventory and protection
Data sharingInformation reaches the wrong placeMinimization and controlled sharing
VendorsA partner connection becomes an exposurePermission and offboarding review
Ransomware/disruptionOperations or data become unavailableDetection, response and tested recovery

Start from critical business assets

List essential services, privileged accounts, customer and employee data, payment processes, communications and recovery systems. Consider likelihood, impact and current safeguards; avoid unsupported universal rankings.

Ask seven questions

  1. What are we protecting?
  2. Who can access it?
  3. What could go wrong?
  4. How would we notice?
  5. Who responds?
  6. How do we recover?
  7. What changes afterward?

Turn guidance into an owned business action

Choose one relevant account, system, data set or workflow. Record the owner, current control, most important failure, detection signal, response step and recovery dependency. Escalate specialist, legal or regulatory questions to qualified advisers for the applicable context.

Sources & further reading

  1. The NIST Cybersecurity Framework 2.0

    National Institute of Standards and Technology. Current outcome-based guidance for governing, identifying, protecting, detecting, responding to and recovering from cybersecurity risk. It does not prescribe one implementation.

  2. Phishing Guidance: Stopping the Attack Cycle at Phase One

    Cybersecurity and Infrastructure Security Agency. Current defensive guidance on phishing resistance, MFA and organisational controls. Specific authentication choices depend on service support and risk.

Examples and exercises are illustrative unless attributed to a source. No independent expert review is claimed.

A correction, a counterexample or an experience worth sharing?

Join the conversation ↗