By the end of this lesson you will be able to
- explain the difference between an asset, a threat, a vulnerability and a risk
- score a risk as likelihood × impact, and use the score to decide what to fix first
- name the four ways an organisation can treat a risk
- read a simple risk register
- run your first search of real-looking security records
Where do you even start?
It is Megan Hart's second day as a junior security analyst at Kestrel Freight, a company of about fifty people that moves goods by lorry for other businesses. Yesterday she was given a laptop, a desk near the window and a list of passwords to change. Today her manager, Richard Lawson, puts a mug of tea in front of her and asks a question.
“Suppose you had one afternoon to make this company safer. What would you do?”
Megan thinks. “Install better antivirus? Train everyone about phishing? Lock down the website?”
“All good ideas,” says Richard. “But you can't do everything at once, and some of those would protect things that hardly matter while leaving the crown jewels open. A defender's first job isn't to buy tools. It's to understand what we're protecting, what could go wrong, and how bad it would be. That's what this lesson is about.”
Four words that every defender uses
Security people use four words very precisely. It is worth learning them properly now, because everything else in the course builds on them.
| Word | Meaning | At Kestrel Freight |
|---|---|---|
| Asset | Anything valuable that needs protecting: information, systems, devices, money, people's time, even the company's good name. | The customer and delivery database; the payroll system; the finance files; staff laptops; the public website. |
| Threat | Something or someone that could cause harm. It can be a person (a criminal, a careless employee) or an event (a flood, a power cut). | Criminals guessing passwords; ransomware gangs; a lorry driver losing a tablet; a burst pipe in the server room. |
| Vulnerability | A weakness that a threat could use. | Four staff accounts without two-step sign-in; an old website plug-in that has not been updated; backups kept in the same room as the server. |
| Risk | The chance that a threat uses a vulnerability to harm an asset, together with how bad the harm would be. | “A criminal guesses the password of an account without two-step sign-in and reads confidential customer emails.” |
A handy way to remember it: a risk needs all three of the others. No asset, nothing to lose. No threat, no one to cause harm. No vulnerability, no way in. Take any one away, and the risk shrinks.
Richard writes on the whiteboard: “The finance share could be encrypted by ransomware because staff can open email attachments that run programs.”
The asset is the finance share (the folder of finance files on the file server).
The threat is a ransomware gang, a criminal group that locks files and demands payment.
The vulnerability is that attachments which run programs can be opened freely.
The risk is the whole sentence: the chance of it happening, and the harm if it does.
A common mix-up. A threat is who or what might attack; a vulnerability is the weakness they would use. “Phishing emails” is a threat. “Staff have never been shown how to report them” is a vulnerability. You usually cannot remove threats (criminals will always exist), but you can often remove vulnerabilities.
Scoring a risk: likelihood × impact
To decide what to fix first, defenders give each risk a rough score. The most common method uses two numbers, each on a scale from 1 (very low) to 5 (very high):
- Likelihood: how likely is it to happen in, say, the next year? 1 means very unlikely; 5 means almost certain.
- Impact: if it did happen, how bad would it be? 1 means a minor nuisance; 5 means the company could not work for days, or would lose a great deal of money or trust.
The risk score is the two multiplied together, so it runs from 1 to 25.
| Score | Rating | What it usually means |
|---|---|---|
| 15 to 25 | High | Deal with it now; tell the managers. |
| 8 to 14 | Medium | Plan to deal with it soon. |
| 1 to 7 | Low | Keep an eye on it. |
Risk: “A criminal guesses the password of one of the four accounts without two-step sign-in.”
Likelihood: password-guessing attacks hit companies like Kestrel every week, and four accounts are exposed. Richard scores it 4.
Impact: the criminal could read that person's email, and send convincing fake invoices from a real Kestrel address. Serious, but not company-stopping. Richard scores it 4.
Risk score = 4 × 4 = 16: high. It goes near the top of the list.
These numbers are judgements, not measurements. Two sensible people might score the same risk 3 or 4. What matters is that the scores are made carefully, written down, and used to compare risks with each other, so that effort goes where it does the most good.
Four ways to treat a risk
Once a risk is scored, the organisation decides what to do about it. There are only four choices:
- Reduce it: add a control that makes it less likely or less harmful. Turn on two-step sign-in for the four accounts. This is the most common choice.
- Avoid it: stop doing the risky thing altogether. Switch off the old customer upload page that nobody uses.
- Transfer it: pass some of the cost to someone else, usually through insurance or a contract. Buy cyber insurance; ask the website company to take responsibility for updates.
- Accept it: decide, knowingly, to live with it, because it is small or fixing it would cost more than the harm. A reception printer that holds no information. Accepting a risk is fine, as long as someone with the authority to decide has done so on purpose and written it down.
The risk register
Organisations keep their risks in a risk register: a simple table listing each risk, its scores, who owns it (the person responsible for dealing with it), and what is being done. Here is the first page of Kestrel's:
| Risk | L | I | Score | Owner | Treatment |
|---|---|---|---|---|---|
| Password guessed on an account without two-step sign-in | 4 | 4 | 16 High | Claire Dunmore (IT manager) | Reduce: turn on two-step sign-in this week |
| Ransomware encrypts the file server | 3 | 5 | 15 High | Claire Dunmore | Reduce: offline backups, block risky attachments |
| Fake “new bank details” email leads to a wrong payment | 3 | 4 | 12 Medium | Susan Pike (finance director) | Reduce: always ring the supplier on a known number |
| Driver loses a delivery tablet | 4 | 2 | 8 Medium | Ben Archer (help desk) | Reduce: screen lock and remote wipe |
| Reception printer is misused | 2 | 1 | 2 Low | Ben Archer | Accept |
Notice that every risk has a named owner. A risk that belongs to “everyone” tends to belong to no one.
Evidence: what the records say
How did Richard decide that password guessing was likely? Partly from experience, and partly from evidence: the records that Kestrel's systems keep of every sign-in. You will learn to search records properly in Module 5; here is a first taste.
The box below searches last week's sign-in records. Each line is one attempt to sign in: when, which account, from which address on the internet, and whether it worked. The search result=failure shows only the failed attempts. Try the examples, then try your own: for instance, user=susan.pike.
Counting failures by address tells a story straight away. Ordinary mistypes come from Kestrel's own office addresses (starting 10.20), one or two at a time. But three addresses outside the company produced almost all the failures. One of them, 203.0.113.45, tried 62 different accounts in the middle of Wednesday night. That is evidence of a real threat, aimed at real vulnerabilities. You will investigate it properly in Module 5.
Kestrel Freight, its staff and its records are made up for this course. Internet addresses beginning 192.0.2, 198.51.100 and 203.0.113 are set aside for teaching and never belong to real computers, and every web and email address ends in .example, which can never lead anywhere real.
Exercises
Exercise 1 · Name the parts
Match each item from Kestrel's notes with the word that describes it.
Exercise 2 · Score the risk
Richard rates the risk “ransomware encrypts the file server” as likelihood 3 and impact 5. What is its risk score?
Exercise 3 · Which are vulnerabilities?
Megan writes a list during her first walk round the office. Select every item that is a vulnerability (a weakness), not an asset or a threat.
Exercise 4 · What to fix first
Put these four risks in order, from the highest risk score at the top to the lowest at the bottom.
Exercise 5 · Your first search
Richard wants to see every failed sign-in from the address 203.0.113.45, and nothing else. Write a search that shows exactly those records. (Tip: you can put two conditions side by side, separated by a space.)
Quick check
Choose an answer to see whether you are right and why.
Which of these is a vulnerability?
A vulnerability is a weakness. The criminals and the flood are threats; the database is an asset.
A risk has likelihood 2 and impact 5. What is its score, and how is it rated?
2 × 5 = 10, which falls in the medium band (8 to 14).
Kestrel buys insurance that pays out if a cyber attack stops the business. Which treatment is that?
Insurance passes some of the cost of the harm to someone else: transfer. It does not make an attack any less likely, so it is usually combined with reducing the risk too.
Why does every risk in the register have a named owner?
An owner is the person responsible for seeing that the risk is treated and kept under review. It is about responsibility, not blame: a risk that belongs to everyone tends to belong to no one.
Summary
- An asset is something valuable; a threat could cause harm; a vulnerability is a weakness; a risk is the chance of harm and how bad it would be. A risk needs all three of the others.
- Score a risk as likelihood × impact, each from 1 to 5: 15 to 25 high, 8 to 14 medium, 1 to 7 low. The scores are careful judgements used to compare risks.
- A risk can be reduced, avoided, transferred or accepted (knowingly, by someone with authority).
- A risk register lists each risk with its scores, an owner and its treatment.
- Security records provide evidence of real threats. A search such as
source_ip=203.0.113.45 result=failureshows exactly the records you ask for.
Found a mistake on this page, or something unclear? Report a problem and mention “Cybersecurity Fundamentals Lesson 1.2”.
