| DATA INCIDENTS | THEFT or CORRUPTION | LOSS or UNVOLUNTARY DISCLOSURE |
|---|---|---|
| EXTERNAL CAUSES or THIRD PARTIES | 1. Digital: Hacking, Virus infection, phishing and other cyberattacks 2. Physical: Theft, social engineering |
3. Disaster, systems disruptions, third-party failure |
| INTERNAL CAUSES | 4. Theft and transfer of digital or physical information by infiltrated employee or contractor 5. Departing employees take proprietary information or intellectual property from the firm (mishandled exits) |
Digital: 6. Database loss, back-up loss 7. Loss of devices by staff members 8. Errors when sending documents (e-mail recipients or attachments) Physical: 9. Loss of printed documents (e.g., by accidentally disposing of them in a wastebasket) 10. Errors or accidental mentions of confidential information when communicating to outsiders 11. Loss of archives |
A Typology of Information Security Risks
| High Profile, Egregious Data Hacks |
|---|
|
|
| Data Leaks: Transfer Of Confidential Information |
|---|
|
|
|
|
|
| Control 1: Inventory and Control of Enterprise Assets |
| Control 2: Inventory and Control of Software Assets |
| Control 3: Data Protection |
| Control 4: Secure Configuration of Enterprise Assets and Software |
| Control 5: Account Management |
| Control 6: Access Control Management |
| Control 7: Continuous Vulnerability Management |
| Control 8: Audit Log Management |
| Control 9: E-mail and Web Browser Protections |
| Control 10: Malware Defences |
| Control 11: Data Recovery |
| Control 12: Network Infrastructure Management |
| Control 13: Network Monitoring and Defense |
| Control 14: Security Awareness and Skills Training |
| Control 15: Service Provider Management |
| Control 16: Application Software Security |
| Control 17: Incident Response Management |
| Control 18: Penetration Testing |
CIS Critical Security Control – Version 8
| Behavioral Controls | |
|---|---|
| Awareness and Prudence | Awareness campaign Training Fake phishing test Password cracking attempt (from IT department) |
| Conduct Rules | Rules of confidentiality Code of conduct Sanction rules |
| Data Governance | Data transfer rules |
| Technical Controls | |
|---|---|
| Architecture | Network partitioning Access Management Firewalls |
| Encryption | Password rules Encryption levels and rules |
| Detection | DLPD Honeypot |
| Testing | Penetration testing |
| Overdue vulnerability patching |
| Overdue penetration tests/overdue resolution of penetration tests recommendations |
| Overdue replacement of obsolescent software |
| Results of phishing tests, of password cracking attempts |
| Number of computers with inadequate access and overdue revisions of access |
| % change in # of IT help-desk requests/change requests/issues per IT managers |
| % vacancies in IT/cybersecurity teams |
| Overcapacity usage of systems |
| Conduct metrics on employee compliance |
| Number of reported breaches of conduct and information rules on social media |
| Number of “Repeat offenders” (staff failing more than one phishing test) in sensitive data areas |
| Number of devices or access cards lost/stolen |
as Key Risk Indicators (KRIs). This table provides examples of KRIs for information security.
Information security risks include data theft, loss, or unintentional disclosure caused by internal or external factors like hacking, phishing, or insider threats.
The NIST cybersecurity framework helps organizations manage and reduce cybersecurity risks by providing guidance on risk identification, protection, detection, response, and recovery.
ISO 27001 is an international standard for managing information security that focuses on risk management, governance, and continual improvement of security processes through an Information Security Management System (ISMS).
The Equifax cyberattack occurred due to unpatched vulnerabilities, poor communication, expired SSL certificates, and weak cybersecurity practices, resulting in a massive data breach.
KRIs in cybersecurity measure the effectiveness of security controls and help monitor unusual activities, such as overdue vulnerability patching, failed phishing tests, or lost devices.
Insider threats, whether malicious or accidental, account for a significant portion of data breaches, as employees may leak, steal, or unintentionally disclose sensitive information.
Behavioral controls involve training, awareness programs, conduct rules, and password management to reduce human-related security risks, such as phishing or unintentional data leaks.
High-profile cyberattacks include the Paradise Papers leak, Equifax breach, and cryptocurrency theft from platforms like bZx and BXH Exchange.
The CIS framework comprises 18 critical controls that help organizations prioritize cybersecurity defenses, including inventory management, secure configurations, continuous vulnerability management, and incident response.
Businesses should create a comprehensive incident response plan, conduct regular penetration testing, implement strong access controls, and continuously monitor for suspicious activities.