SMALL BUSINESS CYBERSECURITY

Simple, Easy to Follow Help
For the Small Business

Certified Information Systems Security Professional
ISC2 CISSP #473513 Since 2013

Home Credentials Coaching Contact

Clean Definitions

What is Cyber

What is Risk

What is a Threat

What is a Framework

What is the Cloud

What is a CISO or BISO

What is a decent Plan?

What is AI?



Resources

Measuring and Manageing Information Risk,
a FAIR Approach
1st Edition

Authors: Jack Freund and Jack Jones
Published by: Butterworth-Heinemann, Oxford, UK
2015
ISBN: 978-0-12-420231-3 (Paperback)

How to Measure Anything in Cybersecurity Risk

Authors: Douglas W. Hubbard and Richard Seiersen
Published by: John Wiley and Sons, Inc., Hoboken, New Jersey, USA
2023
ISBN: 978-0-11-1989230-4 (Hardback)
ISBN: 978-0-11-1989232-8 (ePDF)
ISBN: 978-0-11-1989231-1 (ePub)

What is a Threat?

A threat is anything that can cause damage to your business; in this instance and in particular, your business information. But do not completely separate one type of threat from the other, because they can affect each another and bleed over the edges. Examples: if you don't have good physical security, someone may steal your computer, put a sniffer on your network, or bug your phone, and then you will have bad information security. If you don't have good financial security, you may not be able to spend any money on information security, and your business could totally fail if you get fined for a data breach or your competitor learns your trade secrets.

What Threat Isn't

Threat is not risk, and risk is not threat, though they are closely related. They are like the subject and predicate in a sentence. You can't have one without the other, but one is not the other. This confuses many people; people in high places who should know better, and it leads them to make costly choices; not horrible, just costly. I am here to help you not do that. Just remember, a threat without a known impact value and a likelihood value is just something to chat about over the holiday dinner table.

Threat Examples

A software vulnerability, a virus (human or computer...doesn't matter), a rogue Internet site full of lies or malware laced code, a failing hard drive, a flakey network cable, a rogue employee, a rouge outsider, and so forth; these are threats. They can all cause financial harm to your business in one way or another. Threats come in as many varieties as they come from different places, and you need to be aware of them, but catagorize them in such a way that you don't worry about all of them equaly because some may have such a low likelihood or impact that they are not worth a whimper. Properly categorized, you will be able to apply your written standards for handling them without thinking as much as you might without any standards.

As an example: I drive a car. Others walk, ride bicycles or motorcycles. Some people fly in planes or take the bus, ferry or train. There are threats associated with all of these modes of transportation, just like there are threats against all forms of information collection, processing and storage. You have to decide which threats to worry about. This should be a calculated descision with each type, and one that is written down to model future, similar decisions. Because it is your business, and not mine (you are the CISO, and I am just the coach) I can only help you understand the process and some of the parameters. I'll explain what that means on the "CISO or BISO" link in the left column.

Testimonials

NULL at the moment.

Please email ronald@weist.net to schedule an appointment to talk about your cyber (can't we just say "data?") security.