Cybersecurity data breach
Loss of sensitive customer or staff data via cyber attack.
The risk event
Loss of sensitive customer data
Unauthorised access to or exfiltration of customer-identifying information.
What could cause it, and what stops it
The left-hand side. Each cause is a plausible pathway to the event; the controls beneath it are the barriers that reduce the chance of that pathway completing.
Phishing of staff credentials
Targeted social engineering tricks an employee into surrendering credentials.
- Phishing awareness trainingPreventive · Limited
Quarterly simulated-phishing program for all staff.
- Email filteringPreventive · Effective
Cloud anti-spam and link-rewrite filtering at the gateway.
- Phishing-resistant MFA rolloutPreventive · Planned · 0 to 3 months
Hardware-backed MFA on all SSO-protected applications.
Unpatched software vulnerability
An exploitable defect in a deployed software component is left unpatched.
- Patch management processPreventive · Limited
Monthly review and rollout of vendor security patches.
- Vulnerability scanningDetective · Effective
Weekly automated scans across the production estate.
- Automated patching pipelinePreventive · Planned · 3 to 6 months
CI-driven rollout of OS and library patches with canary stages.
Insider threat
A privileged user misuses their access to exfiltrate data.
- Periodic access reviewsDetective · Limited
Quarterly recertification of access entitlements.
- Data loss preventionDetective · Planned · 6 to 12 months
Endpoint and email DLP for sensitive data classes.
Third-party supplier compromise
A processor or vendor with privileged access is compromised.
- Vendor risk assessmentsPreventive · Limited
Annual security questionnaires and contractual security controls.
- Network segmentationPreventive · Planned · 6 to 12 months
Micro-segmented vendor access paths with continuous monitoring.
What happens if it occurs, and what limits it
The right-hand side. Each consequence is an outcome the event could produce; the controls beneath it are what contains or recovers from that outcome once the event has already happened.
Regulatory fines and penalties
Financial penalties from privacy regulators.
- Breach notification protocolCorrective · Effective
Documented 72-hour regulator notification workflow.
- Privacy compliance programDirective · Highly effective
Annual privacy reviews and DPIA for new initiatives.
Reputational damage
Brand and customer trust impact from public disclosure of the breach.
- Crisis communications planCorrective · Limited
Pre-approved messaging templates and escalation paths.
- Customer notification processCorrective · Effective
Templated, tested customer-impact notification flow.
- External PR retainerCorrective · Planned · 0 to 3 months
On-call public-relations partner for incident response.
Direct financial loss
Remediation, legal, forensic and notification costs.
- Cyber insuranceCorrective · Effective
Policy with breach-response coverage and ransomware extension.
- Incident response retainerCorrective · Effective
Pre-arranged forensic and DFIR partner.
Where this template starts you
Ratings are a starting position, not a finding. They describe a generic organisation with the controls above in place; yours will differ, and the point of opening the template is to make them yours.
Make it yours
Opening the template loads it into the editor with everything above already in place. Rename the event, cut the causes that do not apply, and re-rate against your own matrix. Exports to PNG, PDF, Excel and PowerPoint are built in.