The SMB risk library
62 risks I keep seeing at small organizations, written the way a register entry should be written: event, caused by cause, resulting in impact. Each comes with a suggested starting score, the first controls worth deploying, and the evidence that proves them.
A risk you can't write as event–cause–impact is a worry, not a risk. The suggested scores are starting points from my own anchors — re-score against yours (the register's Scoring Guide shows how).
Filter by situation, sort any column, and click a risk to see its full statement, first controls, and evidence. Sorting by score puts the library's 80/20 on top — the rows most registers should start from. Copy what fits into your risk register, or download the whole library as a workbook below. Don't import all 62 — a register with everything on it manages nothing. And notice the Response column: not everything here says Mitigate. Some risks are best accepted (with an owner and a review date), transferred, or avoided outright — a register that only ever says Mitigate isn't making decisions.
| Fits | |||||
|---|---|---|---|---|---|
| RL-01 | Cyber | Universal | 6 | Mitigate | |
|
Ransomware encrypts servers and shared data, caused by phished credentials and no MFA on remote access, resulting in multi-day operational shutdown and recovery costs. Suggested score: L2 × I3 = 6 · Response: Mitigate First controls: MFA everywhere with legacy auth blocked; one backup copy offline or immutable; 7-day patch SLA for internet-facing systems. Evidence that counts: MFA policy export; dated restore test result. |
|||||
| RL-02 | Process | Universal | 6 | Mitigate | |
|
Unauthorized access via active accounts of departed employees, caused by offboarding without same-day disablement, resulting in standing credentials nobody monitors plus license waste. Suggested score: L3 × I2 = 6 · Response: Mitigate First controls: Same-day disable checklist triggered by HR; quarterly account-vs-roster reconciliation. Evidence that counts: Quarterly reconciliation note with findings. |
|||||
| RL-03 | Operational | Universal | 6 | Mitigate | |
|
Permanent data loss after hardware failure or ransomware, caused by backups that were never restore-tested, resulting in unrecoverable systems and data. Suggested score: L2 × I3 = 6 · Response: Mitigate First controls: Quarterly restore test with documented results; offline/immutable copy; written recovery order. Evidence that counts: Restore test log, dated. |
|||||
| RL-04 | Financial | Universal | 6 | Mitigate | |
|
Fraudulent vendor or payroll payment, caused by business email compromise impersonating an executive or supplier, resulting in unrecoverable financial loss. Suggested score: L2 × I3 = 6 · Response: Mitigate First controls: Callback verification on any payment/banking change using known numbers; dual approval; DMARC at quarantine or reject. Evidence that counts: Documented callback rule; DMARC record. |
|||||
| RL-05 | People | Universal | 6 | Mitigate | |
|
Inability to operate or recover IT systems, caused by critical knowledge held by one person with no documentation, resulting in extended outages during absence or departure. Suggested score: L2 × I3 = 6 · Response: Mitigate First controls: Runbooks for the top 10 procedures; decision log; cross-train a deputy; vendor contact list off-network. Evidence that counts: Runbooks with last-updated dates. |
|||||
| RL-06 | Cyber | Universal | 4 | Mitigate | |
|
Network intrusion, caused by delayed patching of firewall/VPN/edge appliances, resulting in data exfiltration or ransomware staging. Suggested score: L2 × I2 = 4 · Response: Mitigate First controls: Vendor advisory subscriptions; 7-day SLA for critical edge patches; retire out-of-support gear. Evidence that counts: Firmware version list vs current. |
|||||
| RL-07 | Vendor | Universal | 3 | Transfer | |
|
Exposure of customer or company data, caused by a breach at a vendor holding it, resulting in notification obligations and reputational damage you didn't cause but still own. Suggested score: L1 × I3 = 3 · Response: Transfer First controls: Vendor inventory with data sensitivity; security evidence on file; verify insurance covers third-party incidents. Evidence that counts: Vendor inventory, reviewed dates. |
|||||
| RL-08 | Cyber | Universal | 4 | Mitigate | |
|
Breach notification obligations, caused by lost or stolen devices without verified disk encryption, resulting in legal exposure from what should have been a hardware loss. Suggested score: L2 × I2 = 4 · Response: Mitigate First controls: Enforce encryption via MDM; verify compliance reporting; remote wipe capability. Evidence that counts: Encryption compliance report. |
|||||
| RL-09 | Process | Universal | 6 | Mitigate | |
|
Unmanaged data exposure, caused by easy self-signup SaaS adoption with no approval path, resulting in company data in tools nobody secures, renews, or offboards. Suggested score: L3 × I2 = 6 · Response: Mitigate First controls: Lightweight approval path (fast yes beats silent no); review card statements quarterly for unknown subscriptions. Evidence that counts: SaaS inventory with owners. |
|||||
| RL-10 | Financial | Universal | 6 | Mitigate | |
|
Cyber insurance claim denied or reduced, caused by controls misrepresented on the application, resulting in uninsured incident costs at the worst moment. Suggested score: L2 × I3 = 6 · Response: Mitigate First controls: Answer applications literally, not aspirationally; verify each claimed control actually operates; keep evidence. Evidence that counts: Application answers cross-checked against reality. |
|||||
| RL-11 | Cyber | Universal | 6 | Mitigate | |
|
Full environment compromise, caused by administrators using privileged accounts for email and browsing, resulting in one phish handing over the keys. Suggested score: L2 × I3 = 6 · Response: Mitigate First controls: Separate admin accounts; 2-4 global admins max; phishing-resistant MFA for admins. Evidence that counts: Admin role membership export. |
|||||
| RL-12 | Process | Universal | 6 | Mitigate | |
|
Quiet data exposure, caused by permissive sharing defaults (anyone-links) in M365/Google, resulting in sensitive folders reachable via forwardable links nobody remembers. Suggested score: L3 × I2 = 6 · Response: Mitigate First controls: Default sharing to specific people; link expiration; quarterly review of externally shared content. Evidence that counts: Sharing settings export. |
|||||
| RL-13 | Operational | Universal | 4 | Mitigate | |
|
Unplanned downtime of core systems, caused by aging servers and network gear past support, resulting in halted operations and premium-priced emergency replacement. Suggested score: L2 × I2 = 4 · Response: Mitigate First controls: Lifecycle plan with budget line; replace before failure; evaluate hosted alternatives at refresh. Evidence that counts: Asset list with support dates. |
|||||
| RL-14 | Operational | Universal | 4 | Mitigate | |
|
Idle staff and missed commitments, caused by single internet connection failure with cloud-dependent operations, resulting in company-wide stoppage from one cable. Suggested score: L2 × I2 = 4 · Response: Mitigate First controls: Secondary connection or LTE failover sized for critical work; test the failover. Evidence that counts: Failover test note. |
|||||
| RL-15 | People | Universal | 4 | Mitigate | |
|
Competitive and legal harm, caused by departing employees retaining access during notice periods with no data review, resulting in customer lists and IP leaving quietly. Suggested score: L2 × I2 = 4 · Response: Mitigate First controls: Access review at resignation; revoke high-risk access immediately; exit acknowledgment of obligations. Evidence that counts: Offboarding checklist runs. |
|||||
| RL-16 | Financial | Startups | 6 | Mitigate | |
|
Slipped or lost enterprise revenue, caused by no prepared security answers or evidence when the questionnaire arrives, resulting in weeks of delay and rushed concessions. Suggested score: L3 × I2 = 6 · Response: Mitigate First controls: Master questionnaire answered once and maintained; evidence folder; honest gap list with dates. Evidence that counts: Master questionnaire, last-updated date. |
|||||
| RL-17 | Cyber | Startups | 6 | Mitigate | |
|
Cloud account compromise, caused by API keys and credentials committed to source repositories, resulting in data breach or a five-figure compute bill. Suggested score: L2 × I3 = 6 · Response: Mitigate First controls: Secret scanning in CI; secrets manager instead of env files in repos; rotate anything ever committed. Evidence that counts: Scanner output; rotation log. |
|||||
| RL-18 | Process | Startups | 6 | Mitigate | |
|
Customer data breach via the weakest copy, caused by production data cloned into dev/test environments with weaker controls, resulting in exposure no production control could prevent. Suggested score: L2 × I3 = 6 · Response: Mitigate First controls: Synthetic or masked data for non-production; if prod data is unavoidable, same controls apply. Evidence that counts: Data handling rule; spot-check. |
|||||
| RL-19 | Process | Startups | 6 | Mitigate | |
|
IP and system exposure, caused by contractor offboarding that misses accounts outside SSO (repos, cloud consoles, SaaS), resulting in third parties retaining quiet access. Suggested score: L3 × I2 = 6 · Response: Mitigate First controls: Contractor access inventory at engagement start; offboarding checklist includes non-SSO accounts. Evidence that counts: Completed offboarding checklists. |
|||||
| RL-20 | People | Startups | 6 | Mitigate | |
|
Operational standstill, caused by the founder holding sole admin for every critical system with nothing documented, resulting in lockout during absence, departure, or dispute. Suggested score: L2 × I3 = 6 · Response: Mitigate First controls: Second admin (or break-glass) on every critical system; password manager with emergency access; one-page system map. Evidence that counts: System map; emergency access test. |
|||||
| RL-21 | Compliance | Startups | 4 | Mitigate | |
|
Contractual liability, caused by DPA data-deletion commitments with no implementing process, resulting in breach of contract discovered at audit, renewal, or worse, post-incident. Suggested score: L2 × I2 = 4 · Response: Mitigate First controls: List contractual data commitments; build the deletion runbook; test it once. Evidence that counts: Deletion run log. |
|||||
| RL-22 | Operational | Startups | 3 | Mitigate | |
|
Days-long platform outage, caused by accidental deletion or compromise of the single production cloud account, resulting in rebuild from memory without tested infrastructure-as-code. Suggested score: L1 × I3 = 3 · Response: Mitigate First controls: Separate prod/dev accounts; IaC for core infrastructure; backup outside the primary account; test a rebuild. Evidence that counts: Rebuild test notes. |
|||||
| RL-23 | Compliance | US Gov | 6 | Mitigate | |
|
Non-compliance with obligations already in force, caused by receiving CUI without identifying it (no marking review or contract analysis), resulting in 800-171/CMMC exposure on live contracts. Suggested score: L2 × I3 = 6 · Response: Mitigate First controls: Contract-by-contract data analysis with your primes, in writing; CUI handling decision before the next award. Evidence that counts: Written CUI determinations. |
|||||
| RL-24 | Compliance | US Gov | 6 | Mitigate | |
|
False Claims Act liability, caused by self-assessment scores submitted as better than reality, resulting in settlements, penalties, and lost contracts when checked. Suggested score: L2 × I3 = 6 · Response: Mitigate First controls: Score literally, as an assessor would; POA&M with dates for gaps; re-score after changes. Evidence that counts: Scoring worksheet with evidence per item. |
|||||
| RL-25 | Operational | US Gov | 6 | Mitigate | |
|
Disqualification from CUI solicitations, caused by starting C3PAO certification later than assessor availability allows, resulting in eligible work you can't bid after Nov 2026. Suggested score: L2 × I3 = 6 · Response: Mitigate First controls: Treat certification as a dated pipeline decision with leadership now; book assessment early; enclave first to shrink scope. Evidence that counts: Decision recorded in leadership briefing. |
|||||
| RL-26 | Vendor | US Gov | 6 | Mitigate | |
|
Unbudgeted compliance scramble, caused by prime contractors passing requirements down late in the bid cycle, resulting in rushed spend or forced no-bids. Suggested score: L3 × I2 = 6 · Response: Mitigate First controls: Ask primes now what next cycle requires; standing compliance summary ready to send. Evidence that counts: Prime correspondence on requirements. |
|||||
| RL-27 | Compliance | US Gov | 4 | Mitigate | |
|
Costly migration under deadline, caused by tenant architecture (commercial vs GCC/GCC High) decided before contract analysis, resulting in five-figure rework to qualify. Suggested score: L2 × I2 = 4 · Response: Mitigate First controls: Decide cloud architecture from contract data types before migration; segregate CUI workloads. Evidence that counts: Architecture decision record. |
|||||
| RL-28 | Operational | US Gov | 4 | Mitigate | |
|
Whole-company assessment boundary, caused by CUI allowed to flow through every mailbox and laptop instead of an enclave, resulting in compliance cost scaling with headcount instead of contracts. Suggested score: L2 × I2 = 4 · Response: Mitigate First controls: Enclave strategy: CUI confined to defined systems and people; written data flow. Evidence that counts: Data flow diagram; enclave access list. |
|||||
| RL-29 | Compliance | India | 4 | Mitigate | |
|
Regulatory exposure from a minor incident, caused by no detection-and-reporting pipeline able to meet CERT-In's six-hour window from noticing, resulting in penalties stacked on incident costs. Suggested score: L2 × I2 = 4 · Response: Mitigate First controls: One reporting channel everyone knows; no-blame rule; CERT-In contacts and report format pre-staged in the IR policy. Evidence that counts: IR policy with CERT-In details; a test run. |
|||||
| RL-30 | Compliance | India | 4 | Mitigate | |
|
Inability to produce required logs, caused by retention under 180 days or storage outside Indian jurisdiction, resulting in non-compliance discovered exactly when logs are needed most. Suggested score: L2 × I2 = 4 · Response: Mitigate First controls: Verify retention and storage location per log source now; fix gaps; document the map. Evidence that counts: Log source inventory with retention/location. |
|||||
| RL-31 | Compliance | India | 6 | Mitigate | |
|
Failed DPDP breach reporting, caused by no notification process, contacts, or templates prepared, resulting in regulatory penalties compounding incident damage. Suggested score: L2 × I3 = 6 · Response: Mitigate First controls: Breach notification runbook with Board and data-principal templates; legal contact retained before needed. Evidence that counts: Runbook; tabletop note. |
|||||
| RL-32 | Compliance | India | 6 | Mitigate | |
|
Processing without valid notice or consent, caused by apps and forms designed before DPDP requirements, resulting in remediation under deadline pressure and Board complaints. Suggested score: L3 × I2 = 6 · Response: Mitigate First controls: Inventory collection points; itemized notices and withdrawal mechanism; retention schedule per purpose. Evidence that counts: Notice text; consent records. |
|||||
| RL-33 | Financial | India · ISO/MS | 4 | Mitigate | |
|
Disqualification from government and PSU tenders, caused by certification listed as a qualifying gate with lead time longer than the tender window, resulting in lost pipeline. Suggested score: L2 × I2 = 4 · Response: Mitigate First controls: Treat certification timing as a leadership pipeline decision with costs and lead times on the table. Evidence that counts: Decision recorded with dates. |
|||||
| RL-34 | Compliance | ISO/MS | 4 | Mitigate | |
|
Major nonconformity and credibility loss, caused by policy documents describing controls that don't operate, resulting in failed or delayed certification and a skeptical auditor thereafter. Suggested score: L2 × I2 = 4 · Response: Mitigate First controls: Policy-reality review: change the statement or change the operation; document deviations honestly. Evidence that counts: Review notes; updated policies. |
|||||
| RL-35 | Process | ISO/MS | 6 | Mitigate | |
|
Recurring crunch and missed findings, caused by evidence assembled retrospectively instead of produced by operations, resulting in burnout and nonconformities that routine evidence would have caught. Suggested score: L3 × I2 = 6 · Response: Mitigate First controls: Evidence as byproduct: reviews end in dated sign-offs, tests file their results, register carries review dates. Evidence that counts: Evidence calendar with completions. |
|||||
| RL-36 | Operational | ISO/MS | 4 | Mitigate | |
|
Permanent audit tax, caused by certifying broader scope than any customer required, resulting in surveillance cost across systems nobody asked about, forever. Suggested score: L2 × I2 = 4 · Response: Mitigate First controls: Narrowest defensible scope; revisit scope at each recertification, not just additions. Evidence that counts: Scope statement with rationale. |
|||||
| RL-37 | Process | ISO/MS | 4 | Mitigate | |
|
Certificate at risk, caused by internal audits or management reviews skipped in busy seasons, resulting in major nonconformity at the next surveillance audit. Suggested score: L2 × I2 = 4 · Response: Mitigate First controls: Calendar the system: internal audit and management review as recurring, owned, dated events. Evidence that counts: Meeting minutes; audit reports. |
|||||
| RL-38 | Cyber | Universal | 6 | Mitigate | |
|
Extortion over stolen data even after systems are restored, caused by attackers exfiltrating files before encrypting them, resulting in leak threats, notification duties, and a ransom your backups can't answer. Suggested score: L2 × I3 = 6 · Response: Mitigate First controls: Least privilege on shares and mailboxes; alert on mass downloads and unusual egress; a pre-agreed leak-response decision path with counsel and insurer contacts written down. Evidence that counts: Alert configuration export; dated leak-response one-pager. |
|||||
| RL-39 | Financial | Universal | 6 | Mitigate | |
|
Payments redirected to a fraudster's account, caused by a spoofed or compromised vendor emailing "updated" bank details, resulting in unrecoverable funds and a strained vendor relationship. Suggested score: L2 × I3 = 6 · Response: Mitigate First controls: Out-of-band verification of any bank-detail change using a number you already had; dual approval above a threshold; no exceptions for urgency — urgency is the tell. Evidence that counts: Finance SOP; a logged verification callback. |
|||||
| RL-40 | Vendor | Universal | 3 | Mitigate | |
|
Compromise of many clients at once, including you, caused by an attacker breaching your managed service provider's remote-access tooling, resulting in an intruder arriving through the front door you pay for. Suggested score: L1 × I3 = 3 · Response: Mitigate First controls: MFA enforced on all MSP accounts in your tenant; least-privilege scoping; a breach-notification clause in the contract; quarterly review of MSP access. Evidence that counts: MSP account list with MFA status; the contract clause. |
|||||
| RL-41 | Operational | Universal | 3 | Mitigate | |
|
Email and website dead, caused by a domain renewal tied to a card or mailbox nobody watches, resulting in outage, spoofing exposure, and a scramble to recover the name. Suggested score: L1 × I3 = 3 · Response: Mitigate First controls: Auto-renew on; registrar lock on; two current contacts on the account; a 90-day-out calendar reminder. Evidence that counts: Registrar settings screenshot, dated. |
|||||
| RL-42 | Cyber | Universal | 4 | Mitigate | |
|
Silent copying or hiding of financial email, caused by attacker-created inbox rules after a credential phish, resulting in invoice fraud staged from inside your own mailbox. Suggested score: L2 × I2 = 4 · Response: Mitigate First controls: Alert on new forwarding and inbox rules; block auto-forward to external domains; review all rules after any credential incident. Evidence that counts: Transport and alert policy export. |
|||||
| RL-43 | Process | Universal | 6 | Mitigate | |
|
Confidential data in third-party AI tools, caused by staff pasting client and internal material into unvetted chatbots, resulting in loss of control over where the data lives and contractual confidentiality exposure. Suggested score: L3 × I2 = 6 · Response: Mitigate First controls: A short AI-use policy naming approved tools and forbidden inputs; an approved tool good enough that people actually use it; quarterly revisit — this moves fast. Evidence that counts: Published policy; the approved-tool decision note. |
|||||
| RL-44 | Operational | Universal | 2 | Accept | |
|
Loss of the physical office, caused by fire, flood, or forced closure, resulting in replaced laptops and a few disrupted days — for a cloud-first organization. Suggested score: L1 × I2 = 2 · Response: Accept First controls: Confirm nothing irreplaceable lives only in the office; know the laptop replacement path. Then accept the residual: named owner, insurance in force, annual review date. Not every risk earns a project. Evidence that counts: Signed acceptance line in the register, with review date. |
|||||
| RL-45 | Operational | Universal | 4 | Accept | |
|
A business-critical application stuck on an unsupported stack, caused by a vendor that folded or a migration never funded, resulting in a permanent soft spot that patching can't fix. Suggested score: L2 × I2 = 4 · Response: Accept First controls: Isolate first: no internet exposure, its own credentials, restricted network reach, backed up. Then accept what remains — in writing, with an owner, a review date, and the exit plan's cost on record. Evidence that counts: Segmentation note; the signed acceptance with review date. |
|||||
| RL-46 | Financial | Universal | 3 | Transfer | |
|
Incident costs beyond what reserves cover, caused by forensics, notification, legal, and downtime stacking on a single event, resulting in an existential cash crunch after an otherwise survivable breach. Suggested score: L1 × I3 = 3 · Response: Transfer First controls: This is what insurance is for: cyber cover with truthful application answers (RL-10 is this control failing), limits sized to a realistic worst week, and the insurer's hotline in your incident contacts. Evidence that counts: Policy in force; application answers on file that match reality. |
|||||
| RL-47 | Financial | Universal | 3 | Avoid | |
|
A cardholder-data breach with contractual penalties, caused by storing card numbers the business never needed to hold, resulting in PCI scope, fines, and liability a small organization can't absorb. Suggested score: L1 × I3 = 3 · Response: Avoid First controls: Don't hold them: run payments through a processor so card data never touches your systems, and purge any historic copies. Some risks are best avoided, not managed. Evidence that counts: Processor integration note; confirmation of purged stores. |
|||||
| RL-48 | Cyber | Universal | 9 | Mitigate | |
|
Takeover of remote access, caused by RDP or VPN exposed to the internet with password-only login, resulting in an intruder holding a legitimate session inside the network — the most reliable ransomware entry point there is. Suggested score: L3 × I3 = 9 · Response: Mitigate First controls: MFA on all remote access this week; exposed RDP closed entirely; if either can't happen now, treat it as an active incident, not a project. Evidence that counts: Remote-access policy export; external scan showing the port closed. |
|||||
| RL-49 | Cyber | Universal | 2 | Mitigate | |
|
MFA bypassed on a key account, caused by SIM-swap or interception where text messages are the second factor, resulting in an attacker who passes your strongest check. Suggested score: L1 × I2 = 2 · Response: Mitigate First controls: Move admins and finance to app-based or hardware-key MFA; keep SMS only as a last-resort fallback on low-privilege accounts. Evidence that counts: Per-admin MFA method export. |
|||||
| RL-50 | Operational | Universal | 4 | Mitigate | |
|
Corruption or loss of the one workbook everything depends on, caused by years of quiet accretion with no owner, versioning, or access control, resulting in operational blindness and error-prone rebuilds. Suggested score: L2 × I2 = 4 · Response: Mitigate First controls: Name an owner; move it to versioned cloud storage with restricted edit rights; document what feeds it; restore last month's copy once to prove you can. Evidence that counts: Version history screenshot; access list. |
|||||
| RL-51 | Process | Universal | 3 | Mitigate | |
|
Warnings nobody acts on, caused by security alerts routed to an unwatched mailbox or to everyone-and-therefore-no-one, resulting in incidents discovered late that the tooling flagged on day one. Suggested score: L3 × I1 = 3 · Response: Mitigate First controls: Every alert source gets one named owner and a response SLA; a monthly 15-minute check that alerts still flow; delete alerts nobody will ever action. Evidence that counts: Alert routing list with owners, dated. |
|||||
| RL-52 | Process | Startups | 4 | Mitigate | |
|
Standing third-party access to mail and files, caused by OAuth consents from long-abandoned app trials, resulting in forgotten vendors holding live tokens to your workspace. Suggested score: L2 × I2 = 4 · Response: Mitigate First controls: Quarterly review of third-party app grants; admin consent required for new apps; revoke anything unused for 90 days. Evidence that counts: Grant review note with revocations, dated. |
|||||
| RL-53 | Compliance | Startups | 4 | Avoid | |
|
Public security claims you can't evidence, caused by marketing shipping "SOC 2" or "bank-grade encryption" copy ahead of reality, resulting in failed due diligence and contract-breach exposure at the worst possible moment. Suggested score: L2 × I2 = 4 · Response: Avoid First controls: Don't make the claim: publish only what you can evidence today, and review security wording before it ships. "SOC 2 in progress; report available when issued" closes deals too — and survives diligence. Evidence that counts: Copy review step in the release checklist; claims-to-evidence map. |
|||||
| RL-54 | Compliance | Startups | 4 | Mitigate | |
|
License obligations surfacing in due diligence, caused by open-source components pulled in without tracking their terms, resulting in remediation demands or price adjustments mid-deal. Suggested score: L2 × I2 = 4 · Response: Mitigate First controls: Generate a dependency license inventory (free scanners exist); flag copyleft in anything you distribute; decide the policy before the data room, not inside it. Evidence that counts: License scan report, dated. |
|||||
| RL-55 | Compliance | US Gov | 4 | Mitigate | |
|
A basic-safeguarding failure on federal contract information, caused by "it's not CUI" quietly becoming "no rules apply", resulting in noncompliance with the clause nearly every federal contract already carries. Suggested score: L2 × I2 = 4 · Response: Mitigate First controls: Map where FCI lives; apply the FAR 52.204-21 basic safeguards — they overlap heavily with the five controls; record the Level 1 self-assessment. Evidence that counts: FCI data map; self-assessment record. |
|||||
| RL-56 | Compliance | US Gov | 3 | Mitigate | |
|
A reportable cyber incident on a covered contract, caused by no rehearsed path to DIBNet reporting within 72 hours, resulting in a missed clock, preservation failures, and contract exposure stacked on top of the incident itself. Suggested score: L1 × I3 = 3 · Response: Mitigate First controls: Get the reporting credential before you need it; a one-page "incident on a federal contract" runbook: report, preserve images 90 days, notify the contracting officer. Evidence that counts: Runbook with the reporting account noted; a tabletop walkthrough, dated. |
|||||
| RL-57 | Vendor | US Gov | 4 | Mitigate | |
|
A compliance failure below you, caused by flow-down clauses passed to subcontractors without verification, resulting in your posture undermined by a sub's handling of the same CUI. Suggested score: L2 × I2 = 4 · Response: Mitigate First controls: Flow down in writing; collect each sub's assessment status annually; route CUI to subs through your controlled channel, not their inboxes. Evidence that counts: Flow-down matrix; sub attestation on file. |
|||||
| RL-58 | Compliance | India | 3 | Avoid | |
|
Processing a minor's personal data unlawfully, caused by collecting age-sensitive data without verifiable parental consent or with tracking attached, resulting in exposure under the DPDP Act's strictest provisions. Suggested score: L1 × I3 = 3 · Response: Avoid First controls: If children's data isn't core to the business, design it out — don't collect it. If it is core, build verifiable consent and drop behavioural tracking before launch, not after a notice. Evidence that counts: Data map showing the exclusion, or the consent design note. |
|||||
| RL-59 | Compliance | India | 2 | Mitigate | |
|
Data-principal complaints with nowhere to land, caused by no published grievance channel or named contact, resulting in an easy-to-find compliance gap and escalations going straight to the Board instead of to you. Suggested score: L2 × I1 = 2 · Response: Mitigate First controls: Publish the grievance contact and response window; route it to a monitored mailbox; log closures. One of the cheapest fixes in this library. Evidence that counts: The published page; the grievance log. |
|||||
| RL-60 | Compliance | India | 2 | Accept | |
|
Cross-border data flows disrupted, caused by a future government notification restricting transfers under the DPDP framework, resulting in re-architecture on a deadline if your processing footprint lands on the wrong list. Suggested score: L1 × I2 = 2 · Response: Accept First controls: Know where your data is processed — the map is cheap now. Then accept: no restriction currently applies — named owner, quarterly review against new notifications. Monitoring a moving rule beats re-architecting for a rumor. Evidence that counts: Processing-location map; acceptance line with review date. |
|||||
| RL-61 | Process | ISO/MS | 4 | Mitigate | |
|
Repeat nonconformities audit after audit, caused by corrective actions that fix the instance but never the cause, resulting in escalating findings and an auditor who stops believing your CAPA log. Suggested score: L2 × I2 = 4 · Response: Mitigate First controls: Root cause in one honest sentence before closure; an effectiveness check at +90 days; close nothing that hasn't changed the system. Evidence that counts: CAPA log with root-cause and effectiveness fields filled in. |
|||||
| RL-62 | Compliance | ISO/MS | 4 | Mitigate | |
|
Customers assuming the whole company is certified, caused by a certificate scoped to one site or service being marketed without its scope statement, resulting in an awkward correction mid-deal — or a misrepresentation claim. Suggested score: L2 × I2 = 4 · Response: Mitigate First controls: Quote the scope statement wherever the certificate is claimed; align sales collateral with it; expand scope deliberately, not rhetorically. Evidence that counts: Collateral showing the scope line. |
|||||
The whole library, as a workbook
Same 62 risks in register-compatible columns — copy rows straight into your risk register. No macros, ever.
Download the workbookHow this connects: pick 8–15 risks that match your situation, paste them into the register, re-score with your own anchors, and take the top rows to leadership with the briefing template. The library is a menu, not a meal — and the 90-day plan shows where seeding the register fits in your first quarter.