malik7mb7.com Free sample
Free sample — the first lesson's full text

Cyber Security 201: From Personal Habits to Organisational Discipline

The first course gave you a list: enable two-factor, update your devices, take a backup. That is enough for a business run by one or two people.

Lesson 1 / 8

From a Checklist to a Method: The Risk Register

By the end of this lesson you will be able to:

The first course gave you a list: enable two-factor, update your devices, take a backup. That list is enough for a business run by one or two people.

Then the business grows, and the list expires.

When the list expires

Five signs that you have outgrown the do-it-yourself level:

1. You have employees — and security now depends on the behaviour of people you do not watch all day.

2. A system or two has arrived — point of sale, accounts, stock, and perhaps links between them.

3. You have suppliers reaching your data — an accountant, a marketing agency, a developer.

4. You now have something real to lose — years of data, and customers who depend on you.

5. Your customers have started asking — a larger company wants answers about how you protect its data.

At this point the list becomes inadequate, because it answers "what do I do?" and not the question you now face: "what is worth my effort specifically?"

The difference between 101 and 201 in one sentence

101 gives you what to do. 201 gives you how to decide what to do — and then how to make it outlast you.

The first is about measures; the second about method and discipline: risk assessment, threat modelling, roles instead of people, detection instead of prevention alone, and evidence instead of assertion.

Is this course for you? An honest test

I will say it plainly because I do not want you paying for something that does not suit you yet:

If you have not completed the 101 basics — two-factor on your accounts, a password manager, updates, and a backup whose restore you have tested — stop here and do those first.

This is not marketing for the other course. It is that 201 assumes those basics and does not repeat them, and building governance on accounts without two-factor is building a second floor on an incomplete foundation.

And if you have done them, you are in the right place, and the rest builds on them.

From an inventory to a risk register

In 101 you built an asset inventory: what I own. Here we take the next step: what might happen to each of them, and how much I care.

The risk register is one table, and it is the central document of this course:

#RiskAssetLikelihoodImpactScoreActionOwnerReview
1

Likelihood and impact: each from 1 to 5. And score = their product (1 to 25).

How to estimate likelihood without guessing

There are no statistics for your particular business. But three questions give you a reasonable estimate:

1. Has it happened to me or to someone I know in my field? Prior occurrence is the strongest indicator available.

2. How easy is it? What does someone need to do it — a minute or a week?

3. How many people could do it? Your five employees, or anyone on the internet?

And the practical rule: estimate with reasonable confidence and move on. A risk register with approximate estimates is far more useful than a perfect one never written.

Impact: compute it in money and time

Impact is not a feeling. Ask of every risk:

An example: the point of sale down for a full day on a busy day — calculate that day's sales, and that is the impact in numbers. And one number persuades you to spend on prevention more than ten pages of advice.

Four decisions per risk

Once you know the score, you have four options — and this is the point missed by everyone who assumes security means addressing everything:

1. Reduce — a measure that lowers the likelihood or the impact. This is most of what you will do.

2. Transfer — insurance, or a supplier taking on part of it by contract.

3. Avoid — stop the activity that creates the risk at all.

4. Accept — an entirely legitimate decision for a low-scoring risk, or one whose treatment costs more than its impact.

And conscious acceptance is far better than unconscious neglect. The difference is that you write it: "we accepted this risk because... and we will review it on...". A written, dated decision rather than neglect.

Prioritising

Sort your register by score descending, then work from the top — and start within each level with the cheapest to carry out.

A risk scoring 20 that is addressed by a free measure gets done before a risk scoring 25 that needs a month and a budget.

This is not evasion — it is that the cumulative effect of quick measures exceeds waiting for the big project.

Review: what keeps it alive

A risk register written once and forgotten is worthless.

Action steps

  1. Confirm you have completed the 101 basics — and if not, complete them before continuing.
  2. Create a "risk register" file with the eight columns.
  3. Write ten real risks for your business — not generic ones.
  4. Estimate likelihood and impact for each (1–5) and compute the score.
  5. Compute the financial impact of your top three risks in numbers.
  6. Choose a decision per risk: reduce/transfer/avoid/accept — and write the reason for any acceptance.
  7. Name an owner and a review date for every entry.
  8. Put a quarterly review in your calendar now.

That was the full sample — here is the rest

What you just read is one part. The full edition includes:

Request your copy