01 · Explanation
Threats, assets, and shared responsibility
Objective: Identify the business assets and plausible harms that matter most, assign ownership, and prioritize defensive actions without pretending to perform a full professional risk assessment.
Cybersecurity protects the work the organization must continue and the people who could be harmed. Inventory critical accounts, devices, applications, data, vendors, payment paths, domains, backups, and operating processes. For each asset, name an accountable business owner, technical custodian, authorized users, dependencies, and consequence of loss of confidentiality, integrity, or availability. Begin with crown-jewel and single-point-of-failure assets rather than attempting a perfect inventory. Include services managed by outside providers because outsourcing operation does not remove business responsibility.
Describe plausible threat events in plain language: account takeover, payment-change fraud, ransomware, lost device, malicious or mistaken insider action, vendor compromise, exposed cloud share, domain hijack, service outage, or destroyed backup. Then record current protections and the next proportionate improvement. Governance matters: leaders set priorities and risk tolerance; system owners approve access; users follow controls and report problems; IT or security specialists implement and investigate technical safeguards. This course supports baseline decisions but is not a penetration test, compliance certification, legal opinion, or substitute for qualified incident, privacy, or security professionals.
Before you begin
- Confirm F01-F12; record that authoritative asset inventory, data classification, business-impact tiers, system owners, network/data-flow diagrams, supplier contacts, backup topology, and risk acceptance are not supplied.
- STOP. If asset ownership, classification, impact tiers, data flows, supplier contacts, backup topology, or risk acceptance is missing or conflicts across F01–F12, route the exposure map to authorized finance, security, and IT owners; do not claim risk approval or execute payment, access, containment, or recovery action.

