Independent thinking. Informed defence.

CISO Times

Intelligence for the people behind the defence.

The CISO Decision Brief

Cyber Risk Scenario Library

Supplies a starting population of realistic, well-formed risk scenarios so a new register does not begin empty or generic.

Available soon

Format
Excel
Size
93 KB
Length
12 sheets
Version
1.1
Updated

What's inside

  • Instructions
  • Scenario Library
  • Threat List
  • Pick for My Register
  • Library Summary
  • Scoring Guide
  • Lists
  • Definitions
  • Framework References

Preview

The workbook's sheets as you will receive them, with its example rows and the values its formulas calculate. Highlighted [[text]] is for you to replace; rows marked EXAMPLE are for you to delete. Wide sheets scroll sideways. The cover, document control and changelog sheets are in the file.

Instructions

How to use this workbook

StepWhat to do
1Read the Scenario Library. Each row is one scenario written the way the Risk Assessment Methodology & Scoring Model asks (RM-01): who or what could cause harm (threat), the weakness it would use, the asset or service it would hurt, and what would happen. Filter on Category, Threat type or Applies where to see the scenarios that fit you.
2Leave out scenarios that cannot happen to you (Applies where helps), and keep the ones that can, even if you think they are well controlled: the register should show that a risk was considered and is under control, not only that it is high.
3Change the wording to fit your organisation — name your own service, system or supplier. A scenario naming a real asset is a risk someone can own; a generic one is not. Add scenarios of your own on the blank rows; the Well-formed check (calc) tells you when one of the four parts is missing.
4On Pick for My Register, delete the 12 EXAMPLE rows, then add one row per scenario you are taking: choose its Scenario ID, give it the register ID it will have (R-nn) and name its risk owner — the executive accountable for the service or asset it would hurt, not the security team (RM-02). Clear every Check (calc) that does not say OK.
5The starting impact and likelihood are a starting point — assess for yourself. They are typical inherent levels (before your own controls) for a small or mid-sized organisation, judged against the methodology's anchors on the Scoring Guide sheet. Score each picked scenario properly in the Risk Assessment Workbook or directly in the Information Security Risk Register: impact on the worst consequence, likelihood over the next 12 months, before and after existing controls (RM-03).
6Copy the picked rows (paste as values) into the Information Security Risk Register. The register is the single record of assessed risks (RM-11): this workbook is a source of scenarios, not a second list to maintain.
7Review the library when you reassess the register — at least once a year (RM-09) — and when a trigger arrives, especially new threat intelligence: a new attack method that affects your services is a new scenario or a change of likelihood (RM-10).

Legend

Yellow cells are inputs. Everything else is calculated or fixed — do not overwrite formulas.

EXAMPLERows marked EXAMPLE in the first column show how a completed row looks. Delete them before approval.

Scales (Risk Assessment Methodology & Scoring Model). Impact: 1 Minor, 2 Moderate, 3 Major, 4 Severe. Likelihood: 1 Unlikely, 2 Possible, 3 Likely, 4 Almost certain. Score = impact × likelihood; bands: Low 1–3, Medium 4–6, High 8–9, Critical 12–16.

The library rows are the template's content, not examples: keep, change or remove them as you tailor it. The rows marked 'In the EXAMPLE register as' are the scenarios the example organisation (a wholesale distributor with about 900 staff, three warehouses and an online ordering service that takes 60% of its orders) took into its register; their starting score is that register's inherent score. Only the rows on Pick for My Register marked EXAMPLE are to be deleted.

Tailoring — small organisation: start with the scenarios marked 'All organisations' and your own top services; 10 to 15 well-owned risks are better than 50 nobody reviews. Several scenarios share a cure (multi-factor authentication, tested backups, patching): one action can reduce many risks.

Tailoring — regulated entity: under NIS2 Article 21(1) and DORA Article 8(2) you are expected to identify sources of risk continuously and review risk scenarios at least yearly. Keep this library, your picks and the date of each review as evidence. Financial entities should add scenarios for each critical or important function and its ICT third-party providers. Where personal data is involved, GDPR Article 32 asks for security appropriate to the risk: the Data scenarios are a starting point for that judgement.

Tailoring — IT run by a service provider: many weaknesses sit with the provider. Keep the scenario and its owner inside your organisation, and ask the provider for the evidence behind the controls you rely on. The Third-party dependency scenarios and SC entries marked 'IT run by a service provider' apply directly.

Scenario Library

The library: 47 scenarios in 6 categories (RM-01). Starting impact and likelihood are a starting point — assess for yourself. Add your own scenarios on the blank rows at the foot.

Scenario IDCategory IDCategory (calc)Scenario titleThreat IDThreat type (calc)Threat — who or whatWeakness it usesAsset or service affectedConsequenceTypical impact areaLikelihood driversControls that usually reduce itApplies whereSector and size notesStarting impact (1–4)Starting likelihood (1–4)Starting score (calc)Starting band (calc)In the EXAMPLE register asFramework cross-referencesWell-formed check (calc)
SC-01RC-01Service availabilityRansomware takes online ordering offline for more than 2 daysTH-01Ransomware and extortionCriminal ransomware groupThe ordering platform cannot be restored from backup in less than 4 daysThe online ordering service (60% of orders)Loss of about €1.2m of orders per week; customer contracts breachedServiceInternet-facing systems or remote access without multi-factor authentication; backups reachable from the main network; slow or untested recovery; ransomware groups actively targeting the sector.Backups isolated from the network and tested by a full restore; a recovery time agreed with the business and proven; multi-factor authentication on all remote and administrator access; endpoint detection and response; network separation.All organisationsImpact is Severe wherever one service carries most of the revenue. The recovery time, not the attack, usually decides the impact.4312CriticalR-01CSF ID.RA-03, ID.RA-04OK
SC-02RC-01Service availabilityRansomware spreads from warehouse office PCs to warehouse systemsTH-01Ransomware and extortionRansomware brought in on a warehouse office PCWarehouse office PCs and warehouse systems share one networkWarehouse management and dispatch systems at the three warehousesDispatch stopped for 1 to 2 days while systems are rebuilt; orders taken online but not shippedServiceOffice PCs and operational systems on one flat network; staff with local administrator rights; phishing reaching site staff.Separate the office network from operational systems; remove local administrator rights; endpoint detection and response on both; offline backups of operational systems.Several sites or warehousesAlso fits manufacturing and logistics sites with production or warehouse systems. Smaller if operational systems are cloud-hosted.339HighR-04CSF ID.RA-03, ID.RA-04OK
SC-03RC-01Service availabilityCritical weaknesses on internet-facing systems exploited before they are fixedTH-02Exploitation of unpatched or exposed systemsAttackers scanning the internet for known weaknessesCritical security updates on internet-facing systems are applied later than the agreed deadlineInternet-facing systems (websites, ordering or customer portals, remote access)Attacker gains a foothold for ransomware or data theft; service disrupted while systems are rebuiltServiceWeaknesses being exploited within days of publication; a patching backlog; staff shortages; no list of what faces the internet.An up-to-date list of internet-facing systems; patching deadlines by severity, with known-exploited weaknesses first; weekly external scanning; a web application firewall; tracking of on-time patching.All organisationsLikelihood rises sharply when the on-time patching figure falls. The Vulnerability & Exposure Management pack sets the deadlines.339HighR-05CSF ID.RA-03, ID.RA-04OK
SC-04RC-01Service availabilityBackups cannot restore a critical systemTH-12Technical or environmental failureAny event that needs a system restored (ransomware, hardware failure, deletion)Backups are taken but a full restore of the system has not been tested, or failed its testCritical business systems and their dataThe system cannot be recovered, or only after days, and some data is lost for goodServiceNo restore test in the last year; backups of the data but not the configuration; backup job failures not monitored; the only copy online and reachable.A restore test of each critical system at least yearly, timed against the agreed recovery time; monitoring of backup failures; one copy offline or immutable.All organisationsOften rated Unlikely until a test fails. Score it after the last restore test, not before.428HighR-10CSF ID.RA-03, ID.RA-04OK
SC-05RC-01Service availabilityRansomware through remote desktop exposed to the internetTH-01Ransomware and extortionCriminal ransomware groupRemote desktop is reachable from the internet with password-only sign-inServers and the services they runServers encrypted and data stolen; services stopped until rebuilt from backupServiceRemote desktop open to the internet; weak or reused passwords; no account lockout; seen in many small-organisation ransomware cases.Close remote desktop to the internet and put it behind a gateway with multi-factor authentication; account lockout; alerting on failed sign-ins; offline backups.Servers run on own premisesCommon where a supplier opened remote access for support and it was never closed. Check with an external scan.4312CriticalCSF ID.RA-03, ID.RA-04OK
SC-06RC-01Service availabilityRemote access gateway weakness exploited to enter the networkTH-02Exploitation of unpatched or exposed systemsCriminal groups and state-sponsored attackersThe VPN or remote access appliance is not patched within days of a critical vendor fixThe internal network behind the gatewayAttacker inside the network with no password needed, leading to ransomware or data theftServiceRemote access appliances are among the most exploited products; fixes are often released after exploitation has begun; appliances managed by a supplier may be patched late.Emergency patching of remote access appliances within days; subscribe to vendor security notices; multi-factor authentication; logging from the appliance to central monitoring; replace appliances out of vendor support.All organisationsTreat a newly published critical weakness in your appliance as a trigger for reassessment.4312CriticalCSF ID.RA-03, ID.RA-04OK
SC-07RC-01Service availabilityDenial of service makes the website or customer portal unusableTH-06Denial of serviceExtortionists or activists flooding the service with trafficNo denial-of-service protection in front of the public website or portalPublic website, customer portal or online orderingCustomers cannot reach the service for hours or days; lost sales and complaintsServiceOnline revenue; high-profile events or sales periods; being in a sector targeted by activists; extortion demands seen by peers.A denial-of-service protection service from the hosting or network provider; a tested plan to switch it on; a static fallback page; contacts with the provider.Online sales or customer portalLow impact for a brochure website. Much higher when a large share of orders or service is taken online.326MediumCSF ID.RA-03, ID.RA-04OK
SC-08RC-01Service availabilityA failed change stops a core systemTH-08Human errorAn administrator or supplier making a changeChanges to core systems are not reviewed, tested or given a way backA core business systemThe system is unavailable for hours while the change is undone; data may be damagedServiceChanges made directly in live systems; no test environment; changes out of hours without a second person; supplier changes not notified.A change process with review and a back-out plan; testing before release; changes in agreed windows; the provider's changes notified in advance.All organisationsNot a cyber attack, but a leading cause of outages; include it where the risk register covers availability.326MediumCSF ID.RA-03, ID.RA-04OK
SC-09RC-01Service availabilityPower or cooling failure in the server room stops on-site systemsTH-12Technical or environmental failurePower cut, equipment failure or overheatingOn-site servers without a tested backup power supply or cooling alarmSystems hosted in the organisation's own server roomOn-site systems stop and some hardware is damaged; recovery takes a day or moreServiceAgeing uninterruptible power supply batteries; a single air-conditioning unit; no temperature alert; the server room also used as a store.Uninterruptible power supply tested yearly; temperature and power alerts to on-call staff; a generator or hosted fallback for critical systems; moving systems to hosted services.Servers run on own premisesFalls away as systems move to cloud hosting; the equivalent there is a hosting region outage (Third-party dependency).326MediumCSF ID.RA-03, ID.RA-04OK
SC-10RC-01Service availabilityCompany domain hijacked or allowed to expireTH-11MisconfigurationAn attacker taking over the domain registrar account, or a missed renewalThe registrar account has no multi-factor authentication and renewal depends on one personThe organisation's website and email domainWebsite and email redirected or stopped; customers sent to a fake site; emails interceptedServiceRegistrar account in a former employee's name; renewal reminders going to an unread mailbox; no registry lock.Registrar account under a shared role address with multi-factor authentication; automatic renewal for several years; registry lock on the main domains; a yearly check.All organisationsUncommon, but quick and severe when it happens. Easy to reduce at almost no cost.313LowCSF ID.RA-03, ID.RA-04OK
SC-11RC-02Customer and personal dataCustomer data exposed through the ordering serviceTH-02Exploitation of unpatched or exposed systemsAttackers targeting the customer databaseA weakness in the ordering service's web application or its customer accountsCustomer records in the online ordering serviceCustomer personal data exposed at scale. Regulatory fine, notification cost and lost trade; about €0.8mDataA large customer database behind an internet-facing application; custom code; no recent security test; weak customer passwords.Security testing of the application at least yearly and after major change; a web application firewall; encryption of the customer database; least access to customer data; monitoring of unusual data access.Online sales or customer portalWhere personal data is involved GDPR Article 32 asks for security appropriate to the risk; a breach may also have to be notified.428HighR-03CSF ID.RA-03, ID.RA-04; GDPR 32(1)OK
SC-12RC-02Customer and personal dataCloud storage misconfigured and customer files exposedTH-11MisconfigurationAnyone who finds an open storage link, including automated scannersCloud storage set to public or shared by link, with no check of sharing settingsCustomer files held in cloud storageCustomer files exposed to the internet; a notifiable data breach and customer complaintsDataStorage created by teams outside IT; sharing by link as a habit; no policy blocking public sharing; no inventory of storage.Block public sharing by default; a regular report of externally shared files; a cloud configuration check tool; an owner for each storage location.Cloud services in useOne of the most common causes of reported data breaches. Scanners find open storage within hours.326MediumR-11CSF ID.RA-03, ID.RA-04; GDPR 32(1)OK
SC-13RC-02Customer and personal dataCustomer data on an unencrypted laptop at the smaller warehouse site is lost or stolenTH-09Loss or theft of equipmentTheft or loss of a laptopSix older laptops at the smaller warehouse site are not encrypted: encrypting the old models before their March 2027 refresh would cost more than the riskCustomer delivery lists held on those laptopsBusiness customers' contact names and delivery addresses exposed; a data incident to assess for notificationDataUnencrypted laptops; customer lists exported to laptops for convenience; laptops left in vehicles or unlocked offices.Full-disk encryption on every laptop; device management able to wipe remotely; no customer exports to local drives; a quick way to report a lost device.Several sites or warehousesLow impact where only a few records are held; higher for large exports or sensitive data.224MediumR-12CSF ID.RA-03, ID.RA-04; GDPR 32(1)OK
SC-14RC-02Customer and personal dataCustomer accounts taken over by credential stuffingTH-05Password attacks on customer or staff accountsCriminals trying passwords leaked from other websitesCustomer login has no rate limiting, bot detection or optional multi-factor authenticationCustomer accounts on the portal or ordering siteAccounts taken over, fraudulent orders placed, and customers' personal data exposedDataA large customer base; saved payment methods or credit accounts; login pages without protection against automated attempts.Rate limiting and bot detection on login; checks against known leaked passwords; multi-factor authentication offered or required for business accounts; alerts on unusual sign-ins.Online sales or customer portalRises with the value held in an account (credit terms, saved cards, loyalty points).339HighCSF ID.RA-03, ID.RA-04; GDPR 32(1)OK
SC-15RC-02Customer and personal dataPersonal data sent to the wrong recipient by emailTH-08Human errorA member of staff making a mistakeEmail addresses auto-complete and spreadsheets with personal data are sent as attachments without a checkCustomer or employee personal data sent by emailPersonal data disclosed to an outside party; a data incident to assess for notificationDataHigh email volume; spreadsheet exports used for routine work; external recipients with similar names; no warning for external recipients.A warning when sending outside the organisation; a short delay before sending; sharing links with access control instead of attachments; data loss prevention rules for bulk personal data.All organisationsFrequent but usually small. Rate the impact on the largest routine export, not a single record.236MediumCSF ID.RA-03, ID.RA-04; GDPR 32(1)OK
SC-16RC-02Customer and personal dataLost or stolen phone gives access to work email and filesTH-09Loss or theft of equipmentLoss or theft of a phonePhones used for work email are not managed: no enforced screen lock and no remote wipeWork email and files on staff phonesCustomer and internal information readable by whoever has the phoneDataStaff use their own phones for work; no device management; long-lived sign-ins on phones.Device management or app protection policies on phones with work data; enforced screen lock; remote wipe of work data; a quick way to report a lost phone.All organisationsUsually Minor to Moderate impact; higher for executives and staff who handle sensitive data.236MediumCSF ID.RA-03, ID.RA-04; GDPR 32(1)OK
SC-17RC-02Customer and personal dataCopy of live customer data exposed from a test systemTH-11MisconfigurationAttackers or unauthorised staff reaching a less protected test environmentTest and development systems hold copies of live customer data with weaker securityCustomer data copied into test systemsCustomer personal data exposed from a system nobody watchesDataDevelopers or suppliers refresh test systems from live; test systems open to the internet; test accounts with simple passwords.Masked or synthetic data in test systems; the same access controls as live where real data must be used; test systems not reachable from the internet; a register of copies.In-house software developmentAlso applies where a software supplier takes copies of live data to investigate problems.326MediumCSF ID.RA-03, ID.RA-04; GDPR 32(1)OK
SC-18RC-02Customer and personal dataCard details skimmed by malicious code on the checkout pageTH-13Software and web supply-chain attackCriminals injecting card-skimming code into the websiteThird-party scripts on payment pages are not controlled or monitoredThe website's checkout or payment pageCustomers' card and personal details stolen over weeks; notification, card scheme costs and lost trustDataPayment details entered on the organisation's own page; many third-party scripts (analytics, chat, marketing); an e-commerce platform not kept up to date.Use the payment provider's hosted payment page; an inventory of scripts on payment pages; content security policy; monitoring for changes to payment pages.Card payments taken onlineLargely removed where card details are entered only on the payment provider's own page.428HighCSF ID.RA-03, ID.RA-04; GDPR 32(1)OK
SC-19RC-02Customer and personal dataStaff see personal data they should not, through over-broad file sharesTH-11MisconfigurationCurious or careless staff, or an attacker using any staff accountShared folders holding HR or customer data are open to everyone in the organisationHR records and customer data on shared drivesPersonal data seen or copied by people without a need to know; complaints and a data incidentDataPermissions granted to 'everyone' for convenience; no owner for each shared folder; no periodic access review.An owner for each shared location; access by role or group; a yearly access review; a report of folders open to everyone.All organisationsAlso increases the impact of any single compromised account: the attacker sees everything that account sees.236MediumCSF ID.RA-03, ID.RA-04; GDPR 32(1)OK
SC-20RC-03Financial fraudPayment fraud through a compromised supplier email accountTH-04Payment and invoice fraudA fraudster who has taken over a supplier's email accountChanges to supplier bank details are accepted by email without a call-backSupplier paymentsSingle losses of €50k to €400k; not recoverable once paidFinancialSuppliers with weak email security; changes to bank details accepted by email; urgent payment runs; attacks on the sector reported.Call-back to a known number for every change of bank details; a payment verification service; two people to approve new or changed payees; staff awareness for the finance team.All organisationsLosses are rarely recovered once paid. Likelihood is high for any organisation paying many suppliers.3412CriticalR-02CSF ID.RA-03, ID.RA-04OK
SC-21RC-03Financial fraudExecutive impersonated to order an urgent paymentTH-04Payment and invoice fraudA fraudster posing as a senior executive by email, message or cloned voiceUrgent payment requests from senior people are acted on without an independent checkPayments made by the finance teamMoney paid to the fraudster; single losses up to the payment limitFinancialExecutives' names and travel visible online; a culture of acting quickly on senior requests; payments approved by one person.A rule that no payment is made on an email or message alone; call-back to a known number; two-person approval above a threshold; awareness for finance and executive assistants.All organisationsVoice cloning has made telephone requests less reliable; the check must use a number already on file.339HighCSF ID.RA-03, ID.RA-04OK
SC-22RC-03Financial fraudFinance mailbox taken over and customers told to pay a new accountTH-03Phishing and account takeoverA criminal who has taken over a finance mailboxFinance mailboxes without multi-factor authentication; no alert on new mail forwarding rulesCustomer invoicing and receiptsCustomers pay the fraudster; the money is lost to the organisation or disputed with customersFinancialPhishing aimed at finance staff; invoices sent by email; customers not told how bank details are changed.Multi-factor authentication on all mailboxes; alerts on new forwarding rules; invoices stating that bank details never change by email; customers asked to confirm by phone.All organisationsThe loss may fall on the customer, but the relationship damage falls on the organisation.326MediumCSF ID.RA-03, ID.RA-04OK
SC-23RC-03Financial fraudSalary diverted after a fake request to change bank detailsTH-04Payment and invoice fraudA fraudster posing as an employeePayroll accepts changes of bank details by emailPayrollAn employee's salary paid to the fraudster; repaid by the organisationFinancialPayroll changes by email; staff names and roles visible on social media; no confirmation to the employee.Bank details changed only through the HR system after sign-in, or confirmed in person or by call-back; a notice to the employee's known address when details change.All organisationsUsually small single losses, but frequent.236MediumCSF ID.RA-03, ID.RA-04OK
SC-24RC-03Financial fraudOnline banking credentials stolen and fraudulent transfers madeTH-03Phishing and account takeoverCriminals using malware or a fake banking siteOnline banking used from general-purpose PCs, with one person able to create and release paymentsThe organisation's bank accountsLarge fraudulent transfers before they are noticedFinancialFinance PCs used for email and browsing; banking tokens left connected; single-person release of payments.Two-person release of payments in the banking platform; payment limits; banking from a dedicated or locked-down device; bank alerts for new payees.All organisationsBanks' own controls make this rarer than it was, but the impact of one success is Severe.414MediumCSF ID.RA-03, ID.RA-04OK
SC-25RC-03Financial fraudRefunds or credit notes manipulated by an employeeTH-07Malicious insiderA dishonest employeeRefunds and credit notes can be raised and approved by the same personCustomer refunds and credits in the ordering or finance systemMoney paid out to accounts the employee controls, over months before it is noticedFinancialSingle-person refunds; no report of refunds by user; staff under financial pressure.Separation of raising and approving refunds above a limit; a monthly report of refunds by user reviewed by a manager; refunds only to the original payment method.Online sales or customer portalSee the Segregation of Duties Conflict Matrix in the P02 pack for the duties to keep apart.224MediumCSF ID.RA-03, ID.RA-04OK
SC-26RC-04Regulatory complianceSignificant incident not reported to the authority on time (NIS2)TH-15Failure to meet a legal or regulatory obligationA significant incident, whatever its causeNo agreed way to decide quickly whether an incident is significant and who reports itThe organisation's reporting obligation to the national authorityEarly warning or notification made late; enforcement and loss of trust with the authorityLegal and regulatoryIncidents out of hours; unclear significance criteria; the reporting decision depending on one person; incidents handled by a supplier.Written significance criteria; an incident procedure that names who decides and who reports; the authority's reporting route tested; the provider's contract requiring prompt notice.Entities in scope of NIS2NIS2 sets short reporting deadlines for significant incidents; check the national law for the exact steps.224MediumR-08CSF ID.RA-03, ID.RA-04; NIS2 21(1)OK
SC-27RC-04Regulatory compliancePersonal data breach not notified to the data protection authority in timeTH-15Failure to meet a legal or regulatory obligationAny personal data breachNo procedure to assess a breach and decide on notification within the legal deadlineThe organisation's notification obligations as a controllerLate or missing notification; a fine and an investigation on top of the breach itselfLegal and regulatoryBreaches found by staff who do not know to report them; no data protection lead; breaches at processors reported late.A breach procedure with an assessment template; staff told how to report; processors contractually bound to notify promptly; a breach log kept.All organisationsApplies wherever personal data is processed. The notification deadline runs from when the organisation becomes aware.326MediumCSF ID.RA-03, ID.RA-04OK
SC-28RC-04Regulatory complianceMajor ICT-related incident not classified and reported on timeTH-15Failure to meet a legal or regulatory obligationA major ICT-related incidentClassification criteria and reporting steps are not built into incident handlingThe financial entity's reporting obligation to its supervisorInitial notification late; supervisory findings and closer oversightLegal and regulatoryClassification criteria not applied during the incident; outsourced ICT providers slow to share facts; reporting templates unfamiliar.Classification criteria in the incident procedure; a named reporting owner and deputy; provider contracts requiring timely facts; a yearly reporting exercise.Financial entities (DORA)For financial entities under DORA. The reporting deadlines are short; practise them.326MediumCSF ID.RA-03, ID.RA-04; DORA 8(2)OK
SC-29RC-04Regulatory complianceCard data security requirements not metTH-15Failure to meet a legal or regulatory obligationA card payment security assessment, or a card breachThe payment environment has drifted from the card industry's security standard (PCI DSS)The ability to take card paymentsFines or higher fees from the acquiring bank; in the worst case, card acceptance withdrawnLegal and regulatoryCard details handled on own systems or phone lines; no one owning card security; the annual self-assessment done as a formality.Reduce scope by using the payment provider's hosted pages and terminals; an owner for card security; the yearly self-assessment done with evidence.Card payments taken onlineMuch smaller when card details never touch the organisation's own systems.326MediumCSF ID.RA-03, ID.RA-04OK
SC-30RC-04Regulatory complianceControls cannot be evidenced to a regulator, auditor or customerTH-15Failure to meet a legal or regulatory obligationAn audit, supervisory review or customer assessmentSecurity activities happen but leave no record: reviews, tests and approvals are not keptCertification, regulatory standing and customer contractsFindings, a failed audit or a lost tender; remediation under time pressureLegal and regulatoryInformal ways of working; evidence held in personal mailboxes; staff turnover; no calendar of recurring controls.A calendar of recurring control activities with an owner each; evidence kept in one place; a yearly internal check before the external one.All organisationsMost common in organisations new to certification or regulation.236MediumCSF ID.RA-03, ID.RA-04OK
SC-31RC-04Regulatory compliancePersonal data transferred abroad without a lawful basis for the transferTH-15Failure to meet a legal or regulatory obligationA new supplier or tool processing personal data outside the EEASuppliers are chosen without a check of where they process personal dataPersonal data processed by suppliersAn unlawful transfer; orders to stop processing and possible finesLegal and regulatoryTeams buying online tools directly; suppliers using sub-processors abroad; no data protection review in purchasing.A data protection check in purchasing; a register of processors and where they process; standard transfer clauses where needed.All organisationsApplies to organisations subject to GDPR that use cloud or software services.326MediumCSF ID.RA-03, ID.RA-04OK
SC-32RC-04Regulatory complianceSecurity commitments in customer contracts are not metTH-15Failure to meet a legal or regulatory obligationA customer audit, questionnaire or incidentSales agree security terms without checking them against what the organisation actually doesCustomer contracts and renewalsBreach of contract, penalties or termination; loss of a major customerLegal and regulatoryLarge customers imposing their own security schedules; no review of contracts by security; commitments not tracked.Security review of non-standard security terms before signature; a register of commitments with owners; a standard security schedule to offer instead.All organisationsMost relevant to suppliers of services to larger or regulated customers.326MediumCSF ID.RA-03, ID.RA-04OK
SC-33RC-05Third-party dependencyManaged IT provider fails or is compromisedTH-10Supplier failure or compromiseAn attack on, or failure of, the managed IT providerThe provider holds privileged access to all systems, and there is no plan for its failureEvery system the provider managesSystems stopped or compromised through the provider; recovery depends on the providerServiceProvider access with standing administrator rights; attacks on managed service providers to reach their customers; a small provider with few staff.Provider access through named accounts with multi-factor authentication and logging; security terms and a right to audit in the contract; an exit plan; insurance or contractual liability (transfer).IT run by a service providerThe treatment is often partly Transfer (contract and insurance), but the risk owner still owns the risk.326MediumR-06CSF ID.RA-03, ID.RA-04OK
SC-34RC-05Third-party dependencySupplier holding our customer data is breachedTH-10Supplier failure or compromiseAttackers targeting a supplierSuppliers receiving personal data are not assessed for security before or during the contractCustomer or employee data held by suppliersOur customers' data exposed through a supplier; we remain responsible as controllerDataMany suppliers with copies of personal data; no supplier security assessment; data shared beyond what the supplier needs.Security assessment of suppliers that receive personal data; data processing terms; share the minimum data; ask for incident notification within a set time.All organisationsCommon with marketing, payroll, delivery and software suppliers.326MediumCSF ID.RA-03, ID.RA-04; GDPR 32(1)OK
SC-35RC-05Third-party dependencyCloud or software service outage stops a core business activityTH-12Technical or environmental failureAn outage at a cloud or software providerA core activity depends on one provider or hosting region with no fallbackA core business service hosted by a providerThe activity stops until the provider recovers; hours to daysServiceSingle-region hosting; no manual workaround; provider service levels that do not match business needs.Know each core service's provider and its recovery commitments; a manual workaround for critical activities; multi-region or failover where the impact justifies the cost.Cloud services in useRate impact on your own tolerance for the outage, not the provider's service level.326MediumCSF ID.RA-03, ID.RA-04OK
SC-36RC-05Third-party dependencyMalware delivered through a compromised software updateTH-13Software and web supply-chain attackAttackers who have compromised a software vendorVendor updates are installed automatically on critical systems with no monitoringSystems running the vendor's softwareAttacker access to many systems at once through trusted softwareServiceWidely used management or monitoring software with high privileges; automatic updates; no detection on servers.Endpoint detection and response on servers; least privilege for vendor software; staged updates on critical systems; vendor security notices followed.All organisationsUncommon but high impact; the controls that limit it also limit ransomware.414MediumCSF ID.RA-03, ID.RA-04OK
SC-37RC-05Third-party dependencyCritical supplier stops trading or ends the serviceTH-10Supplier failure or compromiseA supplier failing or withdrawing a productNo exit plan and no copy of our data in a usable formA service provided by one supplierThe service lost at short notice; costly emergency replacement; data hard to recoverServiceSmall or financially weak suppliers; products near end of life; contracts without exit terms.An exit plan for each critical supplier; regular export of our data; contract terms for termination assistance; watch for signs of supplier distress.All organisationsDORA expects exit strategies for ICT services supporting critical or important functions.313LowCSF ID.RA-03, ID.RA-04OK
SC-38RC-05Third-party dependencyPayment provider outage stops online paymentsTH-12Technical or environmental failureAn outage at the payment service providerOne payment provider with no alternative way to take paymentOnline paymentsOrders cannot be completed while the outage lasts; lost salesFinancialPeak trading periods; one provider; no invoice or account payment option.An alternative payment route (a second provider, or payment on account for business customers); provider status monitoring; a customer message ready.Card payments taken onlineMostly a revenue risk; impact depends on the length of outage you can absorb.326MediumCSF ID.RA-03, ID.RA-04OK
SC-39RC-05Third-party dependencySupplier's remote access account used to break inTH-03Phishing and account takeoverAn attacker who has compromised a supplier or its credentialsSuppliers have always-on remote access with shared accounts and no multi-factor authenticationSystems the supplier supportsAttacker inside the network with the supplier's rights; ransomware or data theftServiceMany suppliers with remote access; shared supplier accounts; access not removed when the contract ends.Supplier access switched on only when needed; named accounts with multi-factor authentication; session logging; a quarterly review of supplier accounts.IT run by a service providerAlso applies to equipment vendors with remote support access to warehouse or building systems.326MediumCSF ID.RA-03, ID.RA-04OK
SC-40RC-06People and insiderAdministrator misuses privileged accessTH-07Malicious insiderAn administrator acting deliberately against the organisationAdministrators hold standing privileged access and their activity is not reviewed by anyone elseSystems and data under administrator controlData stolen, changed or destroyed, and the traces removedDataFew administrators with full rights; shared administrator accounts; disgruntlement or financial pressure; no independent log review.Named administrator accounts separate from daily accounts; least privilege; logs sent where administrators cannot change them; a second person reviews privileged activity.All organisationsSee the Segregation of Duties Conflict Matrix in the P02 pack for administration and log review.326MediumR-07CSF ID.RA-03, ID.RA-04; GDPR 32(1)OK
SC-41RC-06People and insiderStaff account taken over through phishingTH-03Phishing and account takeoverPhishing emails and fake sign-in pagesStaff accounts protected by password only, or by multi-factor methods that can be phishedStaff email and cloud accountsAttacker reads and sends email as the member of staff, and uses the account to reach data or to launch fraudDataHigh volume of phishing; staff working from phones; no multi-factor authentication; legacy sign-in methods left open.Multi-factor authentication for every account, phishing-resistant for administrators and finance; block legacy sign-in; phishing awareness; alerts on risky sign-ins.All organisationsLikelihood stays high for almost everyone; the controls mostly reduce what an attacker can do with the account.248HighR-09CSF ID.RA-03, ID.RA-04; GDPR 32(1)OK
SC-42RC-06People and insiderDeparting employee takes customer dataTH-07Malicious insiderAn employee leaving for a competitorStaff can export or download customer data in bulk, and exports are not monitoredCustomer lists, pricing and contractsCustomers approached by a competitor; a data incident; legal costsDataSales staff with full customer exports; personal cloud storage allowed; long notice periods with full access.Limit bulk exports to those who need them; block personal cloud storage; review exports and access when notice is given; confidentiality terms enforced.All organisationsOften discovered only when customers mention being approached.326MediumCSF ID.RA-03, ID.RA-04; GDPR 32(1)OK
SC-43RC-06People and insiderLeaver's account still active and used after they leaveTH-07Malicious insiderA former employee, or an attacker using their credentialsAccounts are not disabled on the last working day, and cloud services are missedEmail, cloud services and business systemsData accessed or changed by someone no longer entitled to itDataHR not telling IT promptly; accounts in services outside single sign-on; contractors not tracked.A leaver process triggered by HR with a same-day deadline; single sign-on for cloud services; a monthly check of active accounts against the staff list.All organisationsAn access review regularly finds these; count them to judge the likelihood.224MediumCSF ID.RA-03, ID.RA-04; GDPR 32(1)OK
SC-44RC-06People and insiderImportant data deleted by mistake and not recoverableTH-08Human errorA member of staff or administrator making a mistakeBroad delete rights on shared data, and retention or version history switched offShared files, mailboxes or a business databaseData lost for good or restored only in part; work redoneDataSync tools that spread deletions; clean-up scripts run in live systems; cloud services assumed to keep backups.Version history and recycle-bin retention on shared storage; backup of cloud data (the provider may not keep it); least privilege for bulk deletion.All organisationsCloud services protect their own availability, not your data from your own mistakes.326MediumCSF ID.RA-03, ID.RA-04; GDPR 32(1)OK
SC-45RC-06People and insiderOnly one person can run or recover a critical systemTH-14Loss of key people or knowledgeThe key person leaving, being ill or unreachableKnowledge and access for a critical system sit with one person, with no documentationA critical systemFaults and incidents last longer; changes and patching stallServiceSmall IT team; bespoke systems; knowledge never written down; no deputy.Named deputies; recovery and operating procedures written down and tested by someone else; emergency access held securely; supplier support as a backstop.All organisationsOften the real cause behind slipping patching or slow recovery: check the other scenarios for it.326MediumCSF ID.RA-03, ID.RA-04OK
SC-46RC-06People and insiderConfidential data pasted into unapproved online toolsTH-08Human errorStaff using online AI or file-sharing tools to get work doneNo approved alternative and no guidance on what may be sharedCustomer, employee and commercial informationConfidential or personal data held by a third party outside any contractDataEasy-to-use free tools; pressure to work faster; no approved business version; no guidance.Approved tools with business terms; clear guidance on what may be shared; blocking of unapproved file-sharing where needed; awareness.All organisationsUsually Moderate impact; higher where staff handle special category or client-confidential data.236MediumCSF ID.RA-03, ID.RA-04; GDPR 32(1)OK
SC-47RC-06People and insiderService desk tricked into resetting a password or multi-factor authenticationTH-03Phishing and account takeoverAn attacker phoning the service desk while posing as a member of staffCallers are verified on information an attacker can findStaff accounts, including administratorsAttacker controls a staff or administrator account and bypasses multi-factor authenticationServiceOutsourced service desk; pressure to resolve calls quickly; executives' details public.Strong caller verification (call back on a known number, manager confirmation); extra checks for administrator and executive accounts; alerts to the user on resets.IT run by a service providerA method used in several well-known ransomware attacks on large organisations.326MediumCSF ID.RA-03, ID.RA-04OK

Threat List

What could cause harm. The Risk Assessment Workbook's threat checklist uses the same list. Add your own threats here and on the Lists sheet.

Threat IDThreat typeWhat it looks likeScenarios in the library (calc)Starting band High or Critical (calc)
TH-01Ransomware and extortionCriminals get in, steal data and encrypt systems, then demand payment to restore them or not to publish what they took.33
TH-02Exploitation of unpatched or exposed systemsAttackers use a known weakness in an internet-facing system (remote access gateway, web server, remote desktop) before it is fixed.33
TH-03Phishing and account takeoverA member of staff is tricked into giving away a password or approving a sign-in, and the attacker uses their account.51
TH-04Payment and invoice fraudA fraudster impersonates a supplier, an executive or an employee to have money paid to the wrong bank account (business email compromise).32
TH-05Password attacks on customer or staff accountsAttackers try passwords leaked from other websites, or guess common ones, against login pages (credential stuffing).11
TH-06Denial of serviceA flood of traffic makes a website or online service unusable, sometimes with a demand for payment to stop.10
TH-07Malicious insiderSomeone with legitimate access — an employee, contractor or administrator — misuses it to steal, change or destroy information or money.40
TH-08Human errorA mistake by someone with legitimate access: data sent to the wrong person, files deleted, a change that breaks a system.40
TH-09Loss or theft of equipmentA laptop, phone or storage device holding the organisation's information is lost, stolen or not returned.20
TH-10Supplier failure or compromiseA supplier the organisation depends on is attacked, has an outage, or stops trading, and its problem becomes the organisation's.30
TH-11MisconfigurationA system or cloud service is set up so that information or access is open to people who should not have it.40
TH-12Technical or environmental failureHardware, power, cooling, a hosting region or a failed recovery stops a service, with no attacker involved.41
TH-13Software and web supply-chain attackMalicious code arrives through a trusted route: a vendor's software update, a code library, or a script on the organisation's own website.21
TH-14Loss of key people or knowledgeThe only people who can run, fix or recover a system leave or are unavailable when needed.10
TH-15Failure to meet a legal or regulatory obligationA deadline, notification or requirement under law, regulation or contract is missed, whatever the underlying event.70

Pick for My Register

One row per scenario you take into your register. Yellow columns are yours; the rest calculate. Delete the 12 EXAMPLE rows first: they show the example organisation's register starting from the library.

ExampleRegister IDScenario IDScenario title (calc)Category ID (calc)Category (calc)Risk ownerStarting impact (calc)Starting likelihood (calc)Starting score (calc)Starting band (calc)Check (calc)Notes
EXAMPLER-01SC-01Ransomware takes online ordering offline for more than 2 daysRC-01Service availabilityChief Operating Officer4312CriticalOKAssessed in the EXAMPLE register: inherent 4 × 3 = 12; residual 4 × 2 = 8 (High), outside appetite, within tolerance. Treatment: Reduce.
EXAMPLER-02SC-20Payment fraud through a compromised supplier email accountRC-03Financial fraudChief Financial Officer3412CriticalOKAssessed in the EXAMPLE register: inherent 3 × 4 = 12; residual 3 × 3 = 9 (High), outside appetite, within tolerance. Treatment: Reduce.
EXAMPLER-03SC-11Customer data exposed through the ordering serviceRC-02Customer and personal dataChief Operating Officer428HighOKAssessed in the EXAMPLE register: inherent 4 × 2 = 8; residual 4 × 1 = 4 (Medium), within appetite. Treatment: Reduce.
EXAMPLER-04SC-02Ransomware spreads from warehouse office PCs to warehouse systemsRC-01Service availabilityHead of Logistics339HighOKAssessed in the EXAMPLE register: inherent 3 × 3 = 9; residual 2 × 2 = 4 (Medium), within appetite. Treatment: Reduce.
EXAMPLER-05SC-03Critical weaknesses on internet-facing systems exploited before they are fixedRC-01Service availabilityHead of IT339HighOKAssessed in the EXAMPLE register: inherent 3 × 3 = 9; residual 3 × 2 = 6 (Medium), within appetite. Treatment: Reduce.
EXAMPLER-06SC-33Managed IT provider fails or is compromisedRC-05Third-party dependencyHead of IT326MediumOKAssessed in the EXAMPLE register: inherent 3 × 2 = 6; residual 3 × 1 = 3 (Low), within appetite. Treatment: Transfer.
EXAMPLER-07SC-40Administrator misuses privileged accessRC-06People and insiderHead of IT326MediumOKAssessed in the EXAMPLE register: inherent 3 × 2 = 6; residual 3 × 1 = 3 (Low), within appetite. Treatment: Reduce.
EXAMPLER-08SC-26Significant incident not reported to the authority on time (NIS2)RC-04Regulatory complianceHead of Information Security224MediumOKAssessed in the EXAMPLE register: inherent 2 × 2 = 4; residual 2 × 1 = 2 (Low), within appetite. Treatment: Reduce.
EXAMPLER-09SC-41Staff account taken over through phishingRC-06People and insiderHR Director248HighOKAssessed in the EXAMPLE register: inherent 2 × 4 = 8; residual 2 × 3 = 6 (Medium), within appetite. Treatment: Reduce.
EXAMPLER-10SC-04Backups cannot restore a critical systemRC-01Service availabilityHead of IT428HighOKAssessed in the EXAMPLE register: inherent 4 × 2 = 8; residual 4 × 1 = 4 (Medium), within appetite. Treatment: Reduce.
EXAMPLER-11SC-12Cloud storage misconfigured and customer files exposedRC-02Customer and personal dataHead of IT326MediumOKAssessed in the EXAMPLE register: inherent 3 × 2 = 6; residual 3 × 1 = 3 (Low), within appetite. Treatment: Reduce.
EXAMPLER-12SC-13Customer data on an unencrypted laptop at the smaller warehouse site is lost or stolenRC-02Customer and personal dataHead of Logistics224MediumOKAssessed in the EXAMPLE register: inherent 2 × 2 = 4; residual 2 × 2 = 4 (Medium), within appetite. Treatment: Accept.

Library Summary

Library and picks summary

Calculated from the Scenario Library and Pick for My Register. EXAMPLE picks are counted until you delete them.

Checks

CheckResultTargetStatus
Library rows with a Well-formed check to resolve00OK
Picks with a Check to resolve00OK
Scenarios picked more than once00OK
Picks with no risk owner00OK

By category

CategoryIn the libraryStarting LowStarting MediumStarting HighStarting CriticalPicked
RC-01 Service availability1013334
RC-02 Customer and personal data906303
RC-03 Financial fraud604111
RC-04 Regulatory compliance707001
RC-05 Third-party dependency716001
RC-06 People and insider807102
All categories472338412

Starting bands are typical inherent levels, not your assessment. A category with nothing picked is worth a second look: is it really not a risk for you?

Scoring Guide

Scoring guide

The Risk Assessment Methodology & Scoring Model's anchors. The library's starting impact and likelihood were judged against them; judge yours the same way.

Impact — the worst consequence decides (RM-03)

Area1 Minor2 Moderate3 Major4 Severe
Financialless than [[€50,000]][[€50,000]] to [[€250,000]][[€250,000]] to [[€1,000,000]]more than [[€1,000,000]]
Servicean internal service degraded for hoursa customer service degraded, or an internal service stopped, for up to [[1]] daya core customer service stopped for up to [[2]] daysa core customer service stopped for more than [[2]] days
Datainternal, non-personal datainternal confidential data, or personal data of a few peoplepersonal or customer data of [[hundreds]] of people, or commercially sensitive datapersonal or customer data at scale
Legal and regulatoryno notification or breacha minor breach of contract or policy, put right without penaltya formal enquiry by a regulator or customer, or a contract breach with penaltiesa notifiable breach, enforcement or contract termination
Reputationnot noticed outside the teamnoticed by some customers or supplierscomplaints from several major customers, or regional or trade pressnational press, or loss of a major customer

Where personal data is involved, score the Data area on the worse of the harm to the organisation and the harm to the people whose data it is (GDPR Article 32).

Likelihood — the chance over the next 12 months (RM-03)

LevelChanceSigns
1 Unlikelyless than [[20]]% in the next 12 monthsNot seen at organisations like ours in recent years, or only with rare skill or access.
2 Possible[[20]]% to [[50]]% in the next 12 monthsHappens regularly to organisations like ours; our controls make it harder but not rare.
3 Likely[[50]]% to [[90]]% in the next 12 monthsHappening now to organisations like ours, or has happened to us, and the gap is still open.
4 Almost certainmore than [[90]]% in the next 12 months, or already happeningBeing attempted against us now, with little in the way.

Score = impact × likelihood. Bands: Low 1–3, Medium 4–6, High 8–9, Critical 12–16.

Lists

CategoryIDCategoryNameThreatIDThreatNameImpactAreaAppliesWhereBandNameBandMin
RC-01Service availabilityTH-01Ransomware and extortionFinancialAll organisationsLow1
RC-02Customer and personal dataTH-02Exploitation of unpatched or exposed systemsServiceOnline sales or customer portalMedium4
RC-03Financial fraudTH-03Phishing and account takeoverDataCard payments taken onlineHigh8
RC-04Regulatory complianceTH-04Payment and invoice fraudLegal and regulatoryServers run on own premisesCritical12
RC-05Third-party dependencyTH-05Password attacks on customer or staff accountsReputationCloud services in use
RC-06People and insiderTH-06Denial of serviceIT run by a service provider
TH-07Malicious insiderIn-house software development
TH-08Human errorSeveral sites or warehouses
TH-09Loss or theft of equipmentEntities in scope of NIS2
TH-10Supplier failure or compromiseFinancial entities (DORA)
TH-11Misconfiguration
TH-12Technical or environmental failure
TH-13Software and web supply-chain attack
TH-14Loss of key people or knowledge
TH-15Failure to meet a legal or regulatory obligation

Definitions

Definitions

TermMeaning in this workbook
Risk scenarioA short story of how harm could happen: a threat, the weakness it uses, the asset or service it affects, and the consequence (RM-01). A scenario is something an owner can act on; a single word such as 'ransomware' is not.
ThreatWho or what could cause harm: an attacker, a mistake, a failure or an event. The Threat List groups threats into types.
WeaknessThe gap the threat would use: a missing or weak control, an exposed system, a process that relies on trust.
Asset or serviceWhat would be hurt: a system, a set of information, or a business service. Name your own.
ConsequenceWhat would happen to the organisation: money lost, a service stopped, data exposed, a legal breach, reputation damaged.
Impact areaOne of the 5 kinds of consequence impact is judged on: Financial, Service, Data, Legal and regulatory, Reputation. Impact is scored on the worst of them (RM-03).
Impact 1 — MinorAffects one system of Standard criticality or non-sensitive data; no customer or regulatory effect.
Impact 2 — ModerateAffects a High criticality system or internal confidential data; limited, recoverable disruption.
Impact 3 — MajorAffects a Critical system, personal or customer data, or a regulated service; notifiable if it went wrong.
Impact 4 — SevereCould stop a core business service, expose sensitive data at scale, or breach a legal obligation.
Likelihood 1 — UnlikelyNot reachable from the internet or by ordinary users; no known exploitation; strong compensating control in place.
Likelihood 2 — PossibleReachable internally; exploitation needs skill or insider access.
Likelihood 3 — LikelyReachable by many users or from partner networks; exploitation techniques are public.
Likelihood 4 — Almost certainInternet-facing or known to be actively exploited, with no effective compensating control.
Starting impact and likelihoodA typical inherent level (before your own controls) for a small or mid-sized organisation. A starting point only — assess for yourself.
Inherent and residualInherent: the risk before your existing controls are counted. Residual: the risk with the controls you have today.
Score and bandScore = impact × likelihood (1 to 16). The band follows from the score: Low 1–3, Medium 4–6, High 8–9, Critical 12–16.
Likelihood driversWhat makes the scenario more likely: exposure, missing controls, how often attackers try it.
Applies whereThe kind of organisation in which the scenario can arise. Filter on it to leave out what cannot happen to you.
Risk categoryThe six categories used across the pack: RC-01 Service availability; RC-02 Customer and personal data; RC-03 Financial fraud; RC-04 Regulatory compliance; RC-05 Third-party dependency; RC-06 People and insider. Each has an appetite set in the Cyber Risk Appetite Statement Template.
Risk ownerThe executive accountable for the service or asset the risk would hurt, not the security team (RM-02).
Register IDThe risk's reference in the Information Security Risk Register (R-nn).
Threat intelligenceInformation about current attacks and attackers, used to add scenarios and change likelihoods.
RM-nnThe rules in the Risk Assessment Methodology & Scoring Model.
(calc)A column or cell the workbook calculates. Do not type or paste over it.
EXAMPLE rowA row on Pick for My Register showing the example organisation's register starting from the library. Delete before approval.

Framework References

Framework references

These references indicate relevance only and do not reproduce the text of any standard.

FrameworkReferenceSupported by
ISO/IEC 27001:2022Clause 6.1.2 — Information security risk assessmentScenario Library (RM-01 form, typical impact and likelihood); Pick for My Register
ISO/IEC 27001:2022Annex A 5.7 — Threat intelligenceThreat List; Instructions step 7 (new threat intelligence becomes a scenario or a change of likelihood)
NIST CSF 2.0ID.RA-03 — “Internal and external threats to the organization are identified and recorded”Threat List; Scenario Library threat and weakness columns
NIST CSF 2.0ID.RA-04 — “Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded”Scenario Library: typical impact area, likelihood drivers, starting impact and likelihood
DORA — Regulation (EU) 2022/2554Article 8(2) — identify all sources of ICT risk on a continuous basis and review the risk scenarios at least yearlyThe library as the set of risk scenarios reviewed at least yearly; Instructions step 7
NIS2 — Directive (EU) 2022/2555Article 21(1) — appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of network and information systemsTailoring for regulated entities; scenarios marked 'Entities in scope of NIS2'
GDPR — Regulation (EU) 2016/679Article 32(1) — appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the likelihood and severity of risk to people's rights and freedomsScenarios whose typical impact is on personal data

Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0; Directive (EU) 2022/2555 (NIS2); Regulation (EU) 2022/2554 (DORA); Delegated Regulation (EU) 2024/1774; Regulation (EU) 2016/679 (GDPR)