malik7mb7.com Free sample
Free sample — the first lesson's full text

Cyber Security 201: From Personal Habits to Organisational Discipline

The first course gave you a list: enable two-factor, update your devices, take a backup. That is enough for a business run by one or two people.

Lesson 1 / 8

From a Checklist to a Method: The Risk Register

By the end of this lesson you will be able to:

The first course gave you a list: enable two-factor, update your devices, take a backup. That

list is enough for a business run by one or two people.

Then the business grows, and the list expires.

When the list expires

Five signs that you have outgrown the do-it-yourself level:

1. You have employees — and security now depends on the behaviour of people you do not watch all day.

2. A system or two has arrived — point of sale, accounts, stock, and perhaps links between them.

3. You have suppliers reaching your data — an accountant, a marketing agency, a developer.

4. You now have something real to lose — years of data, and customers who depend on you.

5. Your customers have started asking — a larger company wants answers about how you protect its data.

At this point the list becomes inadequate, because it answers "what do I do?" and not the question you

now face: "what is worth my effort specifically?"

The difference between 101 and 201 in one sentence

**101 gives you what to do. 201 gives you how to decide what to do — and then how to make it outlast
you.**

The first is about measures; the second about method and discipline: risk assessment, threat

modelling, roles instead of people, detection instead of prevention alone, and evidence instead of

assertion.

Is this course for you? An honest test

I will say it plainly because I do not want you paying for something that does not suit you yet:

If you have not completed the 101 basics — two-factor on your accounts, a password manager, updates,

and a backup whose restore you have testedstop here and do those first.

This is not marketing for the other course. It is that **201 assumes those basics and does not repeat

them**, and building governance on accounts without two-factor is building a second floor on an incomplete

foundation.

And if you have done them, you are in the right place, and the rest builds on them.

From an inventory to a risk register

In 101 you built an asset inventory: what I own. Here we take the next step: **what might happen to

each of them, and how much I care.**

The risk register is one table, and it is the central document of this course:

#RiskAssetLikelihoodImpactScoreActionOwnerReview
1

Likelihood and impact: each from 1 to 5. And score = their product (1 to 25).

How to estimate likelihood without guessing

There are no statistics for your particular business. But three questions give you a reasonable estimate:

1. Has it happened to me or to someone I know in my field? Prior occurrence is the strongest indicator

available.

2. How easy is it? What does someone need to do it — a minute or a week?

3. How many people could do it? Your five employees, or anyone on the internet?

And the practical rule: estimate with reasonable confidence and move on. **A risk register with

approximate estimates is far more useful than a perfect one never written.**

Impact: compute it in money and time

Impact is not a feeling. Ask of every risk:

An example: the point of sale down for a full day on a busy day — calculate that day's sales, and that

is the impact in numbers. **And one number persuades you to spend on prevention more than ten pages of

advice.**

Four decisions per risk

Once you know the score, you have four options — and this is the point missed by everyone who assumes

security means addressing everything:

1. Reduce — a measure that lowers the likelihood or the impact. This is most of what you will do.

2. Transfer — insurance, or a supplier taking on part of it by contract.

3. Avoid — stop the activity that creates the risk at all.

4. Acceptan entirely legitimate decision for a low-scoring risk, or one whose treatment costs

more than its impact.

And conscious acceptance is far better than unconscious neglect. The difference is that you write it:

"we accepted this risk because... and we will review it on...". **A written, dated decision rather than

neglect.**

Prioritising

Sort your register by score descending, then work from the top — **and start within each level with the

cheapest to carry out.**

**A risk scoring 20 that is addressed by a free measure gets done before a risk scoring 25 that needs a
month and a budget.**

This is not evasion — it is that the cumulative effect of quick measures exceeds waiting for the big

project.

Review: what keeps it alive

A risk register written once and forgotten is worthless.

Action steps

  1. Confirm you have completed the 101 basics — and if not, complete them before continuing.
  2. Create a "risk register" file with the eight columns.
  3. Write ten real risks for your business — not generic ones.
  4. Estimate likelihood and impact for each (1–5) and compute the score.
  5. Compute the financial impact of your top three risks in numbers.
  6. Choose a decision per risk: reduce/transfer/avoid/accept — and write the reason for any acceptance.
  7. Name an owner and a review date for every entry.
  8. Put a quarterly review in your calendar now.

That was the full sample — here is the rest

What you just read is one part. The full edition includes:

Subscribe now