Asset : Login credentials to the financial software system
Threats: phishing emails, vishing calls, credential theft, which are all being used to gain access to financial system details. The attackers impersonate bankers, employees, legitimate individuals, trying to trick staff into giving out sensitive financial information.
Likelihood: High. Financial departments are a frequent target due to their sensitive information. A data breach is also likely, especially if proper security measures are not in place.
Impact: If financial detalls are compromised the company could suffer from unauthorized transactions, fraud, financial loss and financial penalties for non-compliance with data protection regulations, and damage to the organization's reputation.
Cyber Security Requirements: MFA, employee training on phishing and vishing scams, use email filtering tools which self-reporting, and least privilege models.
Asset: Employee Information
Threats: personal credentials being stolen and used to impersonate company executives, health insurance providers and ete Likelihood: High, HR and finance teams are common targets because of their access to sensitive information.
Impact: if contact details or salary information is exposed, employees could be targeted for identity theft, social engineering scams and further attacks. Breach of health records could cause a privacy legalissue.
Requirements: strong password policies, MFA, role based access controls, employee awareness training.
Asset: Company Information
Threat: Credential stealing malware can infect systems and extract stored passwords, granting attackers unauthorized access.
Likellhood: Medlum - High. many breaches occur due to compromised credentials, specially from unknowingly malware
Impact: could lead to financial fraud, data manipulation, company wide security breaches. financial penalties for non-compliance with data protection regulations, and damage to the organization's reputation
Requirements: password encryption, MFA, threat detection tools, anti-virus, regular password audits and awareness training.