| Risk Management Plan Example |
| Threat |
Vulnerability |
Assets (& Consequences) |
Risk |
Solution |
| Network outage – overheating in the service room
High |
Our central air system is over ten years old
High |
Servers, email, processes, and websites will be unavailable for at least 2 hours.
Critical |
(Potential loss of $50,000 per event)
High |
Purchase and install a new central air system
(costs: $8,600) |
| Malicious human attacks (interference of DDoS attacks)
High |
Firewalls are configured properly and have effective DDoS mitigation
Low |
Website will be unavailable.
Critical |
(Potential loss of $5,600 per minute).
High |
Monitor firewall or invest in firewall-as-a-
service |
| Natural disasters like floods, tornados, and earthquakes (location matters)
Moderate |
Our servers are located on our bottom floor – who has access to the server room and does it remain dry year-around?
Moderate |
Servers may be at risk, which may result in all of our services becoming unavailable.
Critical |
Low |
No actions needed |
| Human-based errors such as accidentally deleting files or compromising business email credentials.
High |
User permission controls are properly configured, software patches are in place, and backups are routine.
Low |
Sometimes data loss is unpreventable but in most cases, it should be fully restored by a backup. An example would include files on a file share drive.
Moderate |
Low |
Provide ongoing monitoring over privileged users, permission changes, and backups |