Customer data breach barriers
This data-breach bowtie makes the boundary between prevention and response explicit. It treats customer data as the hazard and unauthorised access as the top event. Credential theft and application weaknesses are separate threats because they need different controls. Detection, revocation and response sit on the consequence side because they limit harm after access has occurred. A security team can use the diagram to discuss whether every control has an owner, monitoring and a realistic response procedure. Replace the generic controls with the systems and requirements used by the organisation. This is a qualitative risk map, not a security assessment, compliance determination or incident-response runbook.
Open it in the AI editor with a prompt pre-filled — keep what works, change what doesn't.
Scenario
Data-security risk review
Key decisions
- Hazard: Identify the protected data asset.
- Top event: Focus on unauthorised access.
- Prevention: Separate identity and application controls.
- Recovery: Include detection and response actions.
When to reuse this
Use to structure a cybersecurity risk discussion, then map controls to the organisation's security programme.
Frequently asked questions
Why is unauthorised access the top event?
Where do monitoring controls go?
Can supplier risk be included?
Tweak it with chat, export PNG/SVG, or fork it for your own use case.