Foundry Academy · Cybersecurity Fundamentals · Lesson 1 of 6

Threats, assets, and shared responsibility

Identify the business assets and plausible harms that matter most, assign ownership, and prioritize defensive actions without pretending to perform a full professional risk assessment.

Start the lesson

Your learning work, on this device

No signup, cloud storage, cross-device sync or verified completion. Saving is optional. This browser profile is shared with anyone who can use it; private mode, browser cleanup or storage limits may remove work. Use only fictional or non-sensitive material. Export a copy before relying on this device.

Not saved. Worksheets, answers and practice notes currently last only in this tab.

Practice markers are self-reported, never credentials.

01 · Explanation

Threats, assets, and shared responsibility

Objective: Identify the business assets and plausible harms that matter most, assign ownership, and prioritize defensive actions without pretending to perform a full professional risk assessment.

Cybersecurity protects the work the organization must continue and the people who could be harmed. Inventory critical accounts, devices, applications, data, vendors, payment paths, domains, backups, and operating processes. For each asset, name an accountable business owner, technical custodian, authorized users, dependencies, and consequence of loss of confidentiality, integrity, or availability. Begin with crown-jewel and single-point-of-failure assets rather than attempting a perfect inventory. Include services managed by outside providers because outsourcing operation does not remove business responsibility.

Describe plausible threat events in plain language: account takeover, payment-change fraud, ransomware, lost device, malicious or mistaken insider action, vendor compromise, exposed cloud share, domain hijack, service outage, or destroyed backup. Then record current protections and the next proportionate improvement. Governance matters: leaders set priorities and risk tolerance; system owners approve access; users follow controls and report problems; IT or security specialists implement and investigate technical safeguards. This course supports baseline decisions but is not a penetration test, compliance certification, legal opinion, or substitute for qualified incident, privacy, or security professionals.

Before you begin

  • Confirm F01-F12; record that authoritative asset inventory, data classification, business-impact tiers, system owners, network/data-flow diagrams, supplier contacts, backup topology, and risk acceptance are not supplied.
  • STOP. If asset ownership, classification, impact tiers, data flows, supplier contacts, backup topology, or risk acceptance is missing or conflicts across F01–F12, route the exposure map to authorized finance, security, and IT owners; do not claim risk approval or execute payment, access, containment, or recovery action.

Original overview module anchor →

02 · Compare the artifacts

Supported work. Visible uncertainty.

This fictional, sanitized defensive-security case contains no real credentials, account numbers, personal data, or exploitable instructions. It is not legal, forensic, insurance, or cybersecurity assurance.

SilverPine payment-change incident

SilverPine Fabrication is a fictional 38-person manufacturer. At 9:12 a.m., accounts payable received an email inside an existing supplier thread requesting that the next $84,600 payment move to a new bank. The message used the supplier controller's display name and included an attached letter, but the phone number on the letter differs from the approved supplier record. At 9:26, an employee opened the attachment and entered a cloud password on a page that later disappeared. At 9:31, a push-notification approval arrived; the employee denied it and called the office manager. The manager told the employee to change the password from the same laptop but did not contact the incident lead. Email logs available to the internal administrator show a new forwarding rule created at 9:29 and a login from an unfamiliar region. The laptop reports that endpoint protection last checked in 11 days ago. The supplier master record can be changed by three accounts; one belongs to a former contractor and has no recorded multi-factor authentication. Backups run nightly to a connected network share. The dashboard is green, but the last documented restoration test occurred 14 months ago and recovered only one folder. The company's incident sheet lists names but no after-hours method, severity criteria, evidence-preservation steps, payment-hold authority, or customer and regulatory decision process. No payment has been released. Learners must map assets and responsibility, protect authentication and recovery, verify communication independently, manage device and software actions, assess data, vendor, and backup controls, and construct an authorized incident response. They must not investigate outside authorization, contact an attacker, destroy evidence, or declare breach scope and legal notification obligations without qualified review.

Supported example — reference only

Element
Supplier-payment change path
From or trigger
Email requests an $84,600 payment to a new bank.
To or outcome
Verification and authorized banking-change/payment decision path.
Evidence and source ID
F01, F02, F12
Owner
Finance/payment process owner with security and supplier-management reviewers
Open question
Approved supplier contact, change-control record, dual-authorization rule, and decision log are not supplied.
Status
Priority 1 - verification and review pending

A well-handled evidence gap

Element
Backup-recovery dependency
From or trigger
Nightly backup writes to a connected network share.
To or outcome
Verified isolated recovery path and restore evidence.
Evidence and source ID
F10, F11
Owner
IT/recovery owner
Open question
Backup separation, retention, recovery objectives, full restore scope, and current test result are not supplied.
Status
Open - recovery evidence absent

Flawed approach — do not copy

Marking this prioritized asset-and-process map “approved and complete” without the required evidence or reviewer is a flawed submission. Stop payment, access, or recovery assurance claims when authoritative ownership, verification, inventory, or test evidence is absent.

Repair: Rework the prioritized asset-and-process map as an evidence-backed draft, not an approved result. Inventory the payment, email, identity, endpoint, supplier-master, administrative-log, and backup processes named in the case. Map the supplier request from email receipt through banking-detail change and payment authorization. Map credential entry, unexpected push, forwarding rule, unfamiliar login, and endpoint-health facts as linked observations without declaring root cause. Check the revision against this requirement: Payment, email, identity, endpoint, privilege, supplier, log, and backup flows are mapped. If the required evidence is still absent, keep the decision blocked and identify the missing input or authorized reviewer.

Full case record, ambiguities and all assignments →

03 · Bounded practice

Build the prioritized asset-and-process map.

Identify critical processes, assets, owners, dependencies, consequences, and immediate authority gaps.

Deliverable: A prioritized asset-process map and responsibility matrix.

Complete a bounded starter and gap analysis using only CB01, F01, F02, F03, F04, F05, F06, F07, F08, F09, F10, F11, F12, and the assignment-scope record below. Populate supported fields, label every unavailable field “not supplied,” and cite the input ID for each material statement. You may design a proposed template, control, question, or decision rule, but must label it as a learner proposal rather than observed case evidence. Do not contact people, access live systems, run tests, sign records, claim approval, or invent names, dates, quotations, transactions, results, or source documents.

Exact supplied inputs for this assignment
  • M01-I01 · F01 — A supplier-thread email requests an $84,600 payment to a new bank.
  • M01-I02 · F02 — The letter's phone number differs from the approved supplier record.
  • M01-I03 · F03 — An employee entered a cloud password after opening the attachment.
  • M01-I04 · F04 — The employee denied an unexpected push notification and reported to the office manager.
  • M01-I05 · F05 — A new forwarding rule and unfamiliar-region login appear in administrative logs.
  • M01-I06 · F06 — The manager advised a password change from the same possibly affected laptop.
  • M01-I07 · F07 — Endpoint protection on the laptop last checked in eleven days ago.
  • M01-I08 · F08 — Three accounts can change supplier banking details.
  • M01-I09 · F09 — One privileged account belongs to a former contractor and lacks recorded multi-factor authentication.
  • M01-I10 · F10 — Nightly backups write to a connected network share.
  • M01-I11 · F11 — The last recorded restore test was fourteen months ago and covered one folder.
  • M01-I12 · F12 — No payment has been released and the incident sheet lacks operative decision rules.
  • M01-B01 · CB01 — Use CB01, the full versioned case brief printed once at the start of this packet, as a citable narrative source for details not normalized into F01–F12. Preserve its uncertainty language and do not treat narrative detail as approval, complete operational records, or professional judgment.
  • M01-S01 · F01, F02, F03, F04, F05, F06, F07, F08, F09, F10, F11, F12 — Build a starter version of “A prioritized asset-process map and responsibility matrix.” from the listed case facts. Treat requested structures, controls, questions, calculations, and templates as learner-designed proposals. Where an operational record or result is absent, add a gap entry naming the missing evidence and authorized owner instead of fabricating it.

Operating procedure

  1. Inventory the payment, email, identity, endpoint, supplier-master, administrative-log, and backup processes named in the case.
  2. Map the supplier request from email receipt through banking-detail change and payment authorization.
  3. Map credential entry, unexpected push, forwarding rule, unfamiliar login, and endpoint-health facts as linked observations without declaring root cause.
  4. Map who can change banking details and flag the former-contractor privileged account as an access-governance gap.
  5. Map connected backups and stale restore testing as resilience dependencies.
  6. Prioritize by potential business impact and evidence strength, not by invented likelihood.
  7. Final-QC every node for source ID, owner role, open question, priority rationale, and no implied containment.
Field-by-field guidance
Element
Name the process node, asset, state, or transition. Module use: Use the map to connect the payment, identity, endpoint, access, and recovery exposure before selecting controls.
From or trigger
State the observable event that activates the path. Module use: Use the map to connect the payment, identity, endpoint, access, and recovery exposure before selecting controls.
To or outcome
State the proposed next state without implying execution. Module use: Use the map to connect the payment, identity, endpoint, access, and recovery exposure before selecting controls.
Evidence and source ID
Pair the observation with its exact supplied source ID. Module use: Use the map to connect the payment, identity, endpoint, access, and recovery exposure before selecting controls.
Owner
Name the authorized operating or specialist role. Module use: Use the map to connect the payment, identity, endpoint, access, and recovery exposure before selecting controls.
Open question
Record the unanswered question that prevents a final decision. Module use: Use the map to connect the payment, identity, endpoint, access, and recovery exposure before selecting controls.
Status
Use a truthful state such as draft, open—not supplied, review pending, or blocked. Module use: Use the map to connect the payment, identity, endpoint, access, and recovery exposure before selecting controls.
Prioritized asset-and-process map · learning draft
ElementFrom or triggerTo or outcomeEvidence and source IDOwnerOpen questionStatus

Start with 6 rows; the complete workbook specifies 13 stable rows for this artifact. Add rows here or use the full download. No action is saved until you explicitly choose saving above.

Download complete six-module workbook (.md) · Structured case packet (.json)

Keep private client data, unpublished inventions, personal identifiers and credentials out of these public learning tools.

Module 1 · 2-item formative check

Threats, assets, and shared responsibility

Choose an answer and request feedback. Read why each option does or does not fit the evidence. Answers stay in this tab unless you choose device-only saving; they are never submitted.

Question 1 of 2 · MODULE 1 · knowledgeWhich inventory best supports practical small-business cybersecurity risk prioritization?
Question 2 of 2 · MODULE 1 · scenarioSilverPine confirms a payment-change request in F01, mismatched phone data in F02, entered credentials in F03, administrative anomalies in F05, stale privileged access in F09, connected backups in F10, and no released payment in F12. Which exposure map is supported?

Answer either question to review its reasoning.

Inspect the artifact, not just your quiz answers

  • Payment, email, identity, endpoint, privilege, supplier, log, and backup flows are mapped.
  • F09 and F11 are visible rather than hidden in secondary artifacts.
  • No compromise, containment, or recovery outcome is asserted.

Stop: Stop payment, access, or recovery assurance claims when authoritative ownership, verification, inventory, or test evidence is absent.

Go: Proceed to qualified review when assets/processes, sources, owners, impact rationale, and open questions are visible.

Escalate: Escalate the payment request, identity compromise indicators, privileged former-contractor access, and recovery weakness to the designated finance/security/IT owners.

04 · Evidence to keep

Leave with usable work.

Submit the prioritized inventory, responsibility map, rationale, known gaps, and specialist questions that require deeper assessment.

Download your artifact CSV and, if wanted, export the learning-work JSON above. Neither export is a reviewed submission or certificate. Device-only saving is optional; you must press Save my work now after edits.

When all six artifacts are ready, compare the full packet against the track rubric. Qualified human review is still required before real-world decisions.

Computer user working at a secured workstation during a cybersecurity exercise.
Learn the standard. Practice the work.
Technology professional reviewing account and device security controls.
Leave with evidence you can inspect.

Sources, scope and review boundaries

Curriculum 2026.10.08-learning-paths-1. External source dates below are record checks, not continuing guarantees. Verify current requirements before consequential use.

nist-csf-2-publication · Official guidance

The NIST Cybersecurity Framework (CSF) 2.0

Primary NIST framework for governing, identifying, protecting, detecting, responding to, and recovering from cybersecurity risk.

Open reviewed external source ↗

cisa-cross-sector-cpgs · Official guidance

CISA Cross-Sector Cybersecurity Performance Goals

CISA's prioritized voluntary baseline practices, designed to help organizations focus on high-impact risk reduction.

Open reviewed external source ↗

ws-cybersecurity-operating-standard · Academy internal operating standard

Wealth Synergy cybersecurity internal operating standard

Academy-selected asset, access, verification, device, backup, incident, and restoration controls; it does not authorize security testing. This is an internal operating standard selected by Foundry Academy; it is not law, accreditation, licensure, or an external-standard requirement.

Version 1.0 · reviewed 2026-09-01 · owner: Foundry Academy curriculum owner

A future Wealth Synergy private professional-development certificate would be issued only after its assessment, capstone, identity, reviewer, retention, access, deletion, appeal, and issuance controls pass quality review. No credential is currently issued. Any future certificate would not be an accredited academic qualification, professional license, or government certification.