| RSK-01 |
Phishing attack compromises engineer credentials. |
4 |
4 |
16 (High) |
Enforce FIDO2 / Authenticator MFA, conditional access, and quarterly simulated phishing drills. |
4 (Low) |
CISO |
| RSK-02 |
Lost or stolen unencrypted laptop exposes customer data. |
3 |
4 |
12 (Med) |
Mandatory BitLocker full-disk encryption via Intune; remote-wipe capability enabled on check-in failure. |
3 (Low) |
IT Lead |
| RSK-03 |
Third-party SaaS provider experiences severe breach. |
3 |
4 |
12 (Med) |
Pre-onboarding security assessment; DPA execution; restricting sensitive data uploads. |
6 (Low) |
Operations |
| RSK-04 |
Critical server vulnerability exploited prior to patching. |
3 |
5 |
15 (High) |
Automated 14-day patch enforcement (Cyber Essentials Plus SLA) and daily vulnerability scans. |
5 (Low) |
IT Lead |
| RSK-05 |
Accidental data leak via departing employee personal storage. |
3 |
4 |
12 (Med) |
Standardized leaver offboarding protocol; immediate IdP credential revocation; USB port blocking. |
4 (Low) |
HR / IT |