Cyber Security 201: From Personal Habits to Organisational Discipline
The first course gave you a list: enable two-factor, update your devices, take a backup. That is enough for a business run by one or two people.
From a Checklist to a Method: The Risk Register
By the end of this lesson you will be able to:
- Know when a list of measures expires and a method becomes necessary
- Build an eight-column risk register and estimate likelihood and impact without guessing
- Compute impact in money and time rather than by feeling
- Choose between reduce, transfer, avoid and accept — and write the reason for any acceptance
The first course gave you a list: enable two-factor, update your devices, take a backup. That
list is enough for a business run by one or two people.
Then the business grows, and the list expires.
When the list expires
Five signs that you have outgrown the do-it-yourself level:
1. You have employees — and security now depends on the behaviour of people you do not watch all day.
2. A system or two has arrived — point of sale, accounts, stock, and perhaps links between them.
3. You have suppliers reaching your data — an accountant, a marketing agency, a developer.
4. You now have something real to lose — years of data, and customers who depend on you.
5. Your customers have started asking — a larger company wants answers about how you protect its data.
At this point the list becomes inadequate, because it answers "what do I do?" and not the question you
now face: "what is worth my effort specifically?"
The difference between 101 and 201 in one sentence
**101 gives you what to do. 201 gives you how to decide what to do — and then how to make it outlast
you.**
The first is about measures; the second about method and discipline: risk assessment, threat
modelling, roles instead of people, detection instead of prevention alone, and evidence instead of
assertion.
Is this course for you? An honest test
I will say it plainly because I do not want you paying for something that does not suit you yet:
If you have not completed the 101 basics — two-factor on your accounts, a password manager, updates,
and a backup whose restore you have tested — stop here and do those first.
This is not marketing for the other course. It is that **201 assumes those basics and does not repeat
them**, and building governance on accounts without two-factor is building a second floor on an incomplete
foundation.
And if you have done them, you are in the right place, and the rest builds on them.
From an inventory to a risk register
In 101 you built an asset inventory: what I own. Here we take the next step: **what might happen to
each of them, and how much I care.**
The risk register is one table, and it is the central document of this course:
| # | Risk | Asset | Likelihood | Impact | Score | Action | Owner | Review |
|---|---|---|---|---|---|---|---|---|
| 1 |
Likelihood and impact: each from 1 to 5. And score = their product (1 to 25).
How to estimate likelihood without guessing
There are no statistics for your particular business. But three questions give you a reasonable estimate:
1. Has it happened to me or to someone I know in my field? Prior occurrence is the strongest indicator
available.
2. How easy is it? What does someone need to do it — a minute or a week?
3. How many people could do it? Your five employees, or anyone on the internet?
And the practical rule: estimate with reasonable confidence and move on. **A risk register with
approximate estimates is far more useful than a perfect one never written.**
Impact: compute it in money and time
Impact is not a feeling. Ask of every risk:
- How many hours of downtime? × what you earn per hour
- What does the repair cost?
- How many customers might I lose?
- Does it stop the business entirely or partly?
An example: the point of sale down for a full day on a busy day — calculate that day's sales, and that
is the impact in numbers. **And one number persuades you to spend on prevention more than ten pages of
advice.**
Four decisions per risk
Once you know the score, you have four options — and this is the point missed by everyone who assumes
security means addressing everything:
1. Reduce — a measure that lowers the likelihood or the impact. This is most of what you will do.
2. Transfer — insurance, or a supplier taking on part of it by contract.
3. Avoid — stop the activity that creates the risk at all.
4. Accept — an entirely legitimate decision for a low-scoring risk, or one whose treatment costs
more than its impact.
And conscious acceptance is far better than unconscious neglect. The difference is that you write it:
"we accepted this risk because... and we will review it on...". **A written, dated decision rather than
neglect.**
Prioritising
Sort your register by score descending, then work from the top — **and start within each level with the
cheapest to carry out.**
**A risk scoring 20 that is addressed by a free measure gets done before a risk scoring 25 that needs a
month and a budget.**
This is not evasion — it is that the cumulative effect of quick measures exceeds waiting for the big
project.
Review: what keeps it alive
A risk register written once and forgotten is worthless.
- Quarterly: review the scores, close what has been addressed, add what is new
- On any change: a new system, a new employee, a new service, a new branch
- After any incident: add it, and add what you learned from it
Action steps
- Confirm you have completed the 101 basics — and if not, complete them before continuing.
- Create a "risk register" file with the eight columns.
- Write ten real risks for your business — not generic ones.
- Estimate likelihood and impact for each (1–5) and compute the score.
- Compute the financial impact of your top three risks in numbers.
- Choose a decision per risk: reduce/transfer/avoid/accept — and write the reason for any acceptance.
- Name an owner and a review date for every entry.
- Put a quarterly review in your calendar now.
That was the full sample — here is the rest
What you just read is one part. The full edition includes:
- All 8 lessons: the risk register, threat modelling, roles, network segmentation, the supply chain, detection, continuity, and governance
- The hands-on task and quiz that close every lesson — neither is included in this sample
- A capstone of five documents that answer a larger customer's questions about your security
- A completion certificate in your name, in Arabic and English