8 Security in Practice

Learn how to assess cybersecurity risks, choose and combine safeguards, and review systems to confirm protections work.

Assess and respond to

Effective security is -based: prioritize situations that could cause serious harm, then check whether safeguards are working. A arises when a threat could exploit a weakness and cause harm.

Assess by considering:

  • Assets and impact: Identify what could be harmed, such as data, services, people, finances, or reputation, and estimate how serious the harm would be.

  • Threat and likelihood: Identify the event that could cause harm and consider how plausible it is in the system.

  • Vulnerability and exposure: Identify weaknesses that could allow the event to succeed and consider how accessible they are to a threat source.

A useful qualitative comparison is:

risk≈likelihood×impact\text{risk} \approx \text{likelihood} \times \text{impact}

This model helps prioritize concerns; it is not a precise prediction. For example, an online store might prioritize account takeover when customer accounts are valuable, passwords are reused, and attackers can reach the login page. A temporary outage of a nonessential internal report may have lower impact. Reassess risks as systems, threats, and business needs change.

For each significant , choose and document a response:

  • Mitigate the with safeguards.

  • Avoid the risky activity.

  • Transfer or share some consequences, for example through a contract or insurance.

  • Accept the remaining as an informed decision by someone with appropriate authority.

After applying safeguards, assess the and decide whether it is acceptable.

Takeaway: Prioritize risks by considering both how likely harm is and how serious its impact could be.

Build layered defenses

combines safeguards across people, technology, and operations so security does not depend on a single barrier. If one control fails, another may still prevent, detect, or limit harm.

For an online store, layers might include:

  1. People and policy: Train staff to recognize phishing and define who may approve refunds or access customer records.

  2. Identity and access: Require for administrators, give each account only the access needed for its tasks, and promptly remove access that is no longer needed.

  3. Devices and applications: Keep software updated, use secure configurations, and limit unnecessary exposure of administrative tools.

  4. Network and data: Separate systems according to their roles, restrict unnecessary connections, and protect sensitive information in storage and during transmission.

  5. Detection and recovery: Record important activity, review alerts, prepare an incident-response process, and keep backups that can be restored.

These layers work together. can reduce the value of a stolen password; access limits can restrict what a compromised account can do; monitoring can help reveal suspicious activity. No single measure guarantees security. Choose controls to address the system’s risks and verify that they operate as intended.

Ongoing management can also be organized through six connected functions: Govern, Identify, Protect, Detect, Respond, and Recover.

Takeaway: Combine complementary safeguards, and check that each one works in the system where it is used.

Review a system and verify safeguards

A is a structured check of what exists, what could go wrong, and whether protections are effective. A small team can follow this sequence:

  1. Set scope and purpose. Identify the system, its owner, its users, its important services, and the decisions the review should support.

  2. Map assets and dependencies. List devices, applications, data, accounts, network connections, cloud services, vendors, and backups. Note where sensitive data is stored and who can reach it.

  3. Trace likely threat paths. Consider how an attacker, mistake, or outage could affect the system. Examples include a phishing message leading to account compromise, an exposed service being exploited, or a failed backup delaying recovery.

  4. Check safeguards and evidence. Review access settings, authentication, updates, network boundaries, logging, incident procedures, and backup restoration. Look for evidence, such as configuration records or a test restore, rather than relying only on written policies.

  5. Prioritize and assign action. Record each important , its likely impact, existing controls, remaining , an owner, and a next step. Address high-impact weaknesses first and set a review date for each action.

  6. Reassess after change. Repeat the review after significant system changes or incidents, and check periodically that controls still work.

For example, a finding might state that if an administrator’s password is stolen, an attacker could change the store’s payment settings. The impact is high, and the current protection is password-only login. A useful action is to require for administrator accounts, test the configuration, and review privileged-account activity. Assign an owner, such as the system administrator, so the decision has clear follow-up.

Takeaway: A useful review identifies important assets, checks plausible attack and failure paths, verifies safeguards with evidence, and assigns specific improvements.

Connect decisions to ongoing improvement

Practical security starts by understanding assets, threats, weaknesses, and potential harm. Use that assessment to prioritize safeguards, combine independent layers, and make decisions about explicit.

Revisit assessments as systems and needs change. A repeatable review connects identification to tested controls, accountable action, and recovery planning.