CYBERSECURITY

Customer data breach barriers

This data-breach bowtie makes the boundary between prevention and response explicit. It treats customer data as the hazard and unauthorised access as the top event. Credential theft and application weaknesses are separate threats because they need different controls. Detection, revocation and response sit on the consequence side because they limit harm after access has occurred. A security team can use the diagram to discuss whether every control has an owner, monitoring and a realistic response procedure. Replace the generic controls with the systems and requirements used by the organisation. This is a qualitative risk map, not a security assessment, compliance determination or incident-response runbook.

UPDATED 2026-09-24
TYPEBowtie
EXAMPLECustomer data breach barriers
Make this diagram your own.

Open it in the AI editor with a prompt pre-filled — keep what works, change what doesn't.

CASE ANALYSIS

Scenario

Data-security risk review

Key decisions

  • Hazard: Identify the protected data asset.
  • Top event: Focus on unauthorised access.
  • Prevention: Separate identity and application controls.
  • Recovery: Include detection and response actions.

When to reuse this

Use to structure a cybersecurity risk discussion, then map controls to the organisation's security programme.

FAQ

Frequently asked questions

Why is unauthorised access the top event?01
It is the loss of control that can occur before data is disclosed or other impacts follow.
Where do monitoring controls go?02
Detection controls usually reduce consequences after access and belong on the right side.
Can supplier risk be included?03
Yes. A supplier compromise can be added as a threat with contractual and technical barriers.
Open this example in the editor →

Tweak it with chat, export PNG/SVG, or fork it for your own use case.