Beau-TieBow tie template

Cybersecurity data breach

Loss of sensitive customer or staff data via cyber attack.

Open in Beau-TieHow bow ties workFree · no account · nothing leaves your browser
Cybersecurity data breach: 4 causes and 3 consequences either side of the risk event, with 17 controls positioned along the pathways. Everything below repeats this in text.

The risk event

Loss of sensitive customer data

Unauthorised access to or exfiltration of customer-identifying information.

What could cause it, and what stops it

The left-hand side. Each cause is a plausible pathway to the event; the controls beneath it are the barriers that reduce the chance of that pathway completing.

Phishing of staff credentials

Targeted social engineering tricks an employee into surrendering credentials.

  • Phishing awareness trainingPreventive · Limited

    Quarterly simulated-phishing program for all staff.

  • Email filteringPreventive · Effective

    Cloud anti-spam and link-rewrite filtering at the gateway.

  • Phishing-resistant MFA rolloutPreventive · Planned · 0 to 3 months

    Hardware-backed MFA on all SSO-protected applications.

Unpatched software vulnerability

An exploitable defect in a deployed software component is left unpatched.

  • Patch management processPreventive · Limited

    Monthly review and rollout of vendor security patches.

  • Vulnerability scanningDetective · Effective

    Weekly automated scans across the production estate.

  • Automated patching pipelinePreventive · Planned · 3 to 6 months

    CI-driven rollout of OS and library patches with canary stages.

Insider threat

A privileged user misuses their access to exfiltrate data.

  • Periodic access reviewsDetective · Limited

    Quarterly recertification of access entitlements.

  • Data loss preventionDetective · Planned · 6 to 12 months

    Endpoint and email DLP for sensitive data classes.

Third-party supplier compromise

A processor or vendor with privileged access is compromised.

  • Vendor risk assessmentsPreventive · Limited

    Annual security questionnaires and contractual security controls.

  • Network segmentationPreventive · Planned · 6 to 12 months

    Micro-segmented vendor access paths with continuous monitoring.

What happens if it occurs, and what limits it

The right-hand side. Each consequence is an outcome the event could produce; the controls beneath it are what contains or recovers from that outcome once the event has already happened.

Regulatory fines and penalties

Financial penalties from privacy regulators.

  • Breach notification protocolCorrective · Effective

    Documented 72-hour regulator notification workflow.

  • Privacy compliance programDirective · Highly effective

    Annual privacy reviews and DPIA for new initiatives.

Reputational damage

Brand and customer trust impact from public disclosure of the breach.

  • Crisis communications planCorrective · Limited

    Pre-approved messaging templates and escalation paths.

  • Customer notification processCorrective · Effective

    Templated, tested customer-impact notification flow.

  • External PR retainerCorrective · Planned · 0 to 3 months

    On-call public-relations partner for incident response.

Direct financial loss

Remediation, legal, forensic and notification costs.

  • Cyber insuranceCorrective · Effective

    Policy with breach-response coverage and ransomware extension.

  • Incident response retainerCorrective · Effective

    Pre-arranged forensic and DFIR partner.

Where this template starts you

Ratings are a starting position, not a finding. They describe a generic organisation with the controls above in place; yours will differ, and the point of opening the template is to make them yours.

Residual
High
Likelihood 4 · Consequence 4
Target
Moderate
Likelihood 2 · Consequence 3

Make it yours

Opening the template loads it into the editor with everything above already in place. Rename the event, cut the causes that do not apply, and re-rate against your own matrix. Exports to PNG, PDF, Excel and PowerPoint are built in.