0% found this document useful (0 votes)
135 views23 pages

BioNova Risk Analysis on Theft Threats

The document outlines a case study on BioNova Solutions, a pharmaceutical company facing risks related to organized crime and physical theft of valuable drugs. Jim Matthews, the CRO, is tasked with conducting a risk analysis using the FAIR model to assess potential losses and develop mitigation strategies. The document also includes a second case study on Stark Industries, focusing on risks from DDoS attacks on their order processing system.

Uploaded by

Andrew Kupiec
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
135 views23 pages

BioNova Risk Analysis on Theft Threats

The document outlines a case study on BioNova Solutions, a pharmaceutical company facing risks related to organized crime and physical theft of valuable drugs. Jim Matthews, the CRO, is tasked with conducting a risk analysis using the FAIR model to assess potential losses and develop mitigation strategies. The document also includes a second case study on Stark Industries, focusing on risks from DDoS attacks on their order processing system.

Uploaded by

Andrew Kupiec
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Case Study Solutions

Document
Case Study #1: BioNova Solutions
The following case study will be completed as a class with the instructor leading
discussion and entering estimates into the RiskLens software.

Part 1: Scoping the Scenario


Read the following information and write a properly scoped scenario statement for
the analysis Jim and his team will conduct.

BioNova Solutions is a pharmaceutical company located in Eugene, Oregon that leads


the industry in R&D of ground-breaking therapy drugs. The company has experienced
significant growth in the past 5 years due to continual innovation.

Jim Matthews, the company’s CRO, is facing pressure from the Board of Directors to
update and improve reporting on the top risks facing the company. Through a series
of risk identification interviews Jim and his team have concluded that physical security
at the company’s warehouse is a potential area of concern, as the drugs the company
manufactures are highly valuable on the black market.

Organized criminal groups are known by BioNova to have broken into competitors’
warehouses in the past, so Jim and his team have decided to conduct a risk analysis
on this topic. Given the Board’s directives to improve risk reporting, Jim has decided to
adopt the FAIR model and methodology so he can provide insight into the amount of
risk exposure the company has from this scenario and, if warranted, help prioritize
mitigation strategies in terms of amount of risk reduced per dollar spent.

Scenario statement:
Analyze the risk associated with organized criminal groups impacting the availability
of manufactured pharmaceuticals via physical theft from the warehouse.
Part 2: Collecting Data and Estimates
Read the following context-specific questions and identify which variable of the FAIR
model each was written for.

1. Over the next year, how many times will organized criminals attempt to steal
therapy drugs from the BioNova warehouse?
Threat Event Frequency

2. Over the next year, how many times will organized criminals successfully steal
therapy drugs from the BioNova warehouse?
Loss Event Frequency

3. Of the attempts by organized criminals to steal therapy drugs from the BioNova
warehouse in the next year, what percentage will be successful?
Vulnerability

4. When organized criminals successfully steal therapy drugs from the BioNova
warehouse, what is the probability that BioNova will face losses from secondary
stakeholders such as regulators, future clients, business partners, etc.?
Secondary Loss Event Frequency

Read the following information (continued on the next page) about BioNova’s
operations. Afterwards, you’ll need to decide which variables on the Loss Event
Frequency side of the model Jim’s team should use in their analysis.

Jim and his team begin investigating the control environment at the warehouse
complex. The team learns that employees must use a badge reader to pass through a
gate upon arrival. This allows access to multiple buildings within the compound,
including the warehouse. The warehouse has an additional badge reader with
restricted access at its main entrance, but employees were observed holding the
doors open for others. Additionally, the cargo loading bay doors are often left open
for long periods of time.
In addition to their own observations the team met with managers from the
warehouse, physical security, and information security teams to gather additional
data relevant to their analysis. The team collected the following information:

Warehouse Management

• Warehouse employees typically pass through an entry or exit point 8 times a day.

• Approximately 15% of team members are known to have allowed another team
member to follow them through a gate or door without scanning their badge.

Physical Security Team

• Drugs from the warehouse have been stolen once in the past 7 years. A warehouse
employee experienced a medical emergency in his immediate family and attempted
to sell the drugs to generate additional income to cover medical expenses.

• Federal law enforcement has alerted BioNova to two credible threats of theft from
their facilities in the last year, both of which were pre-empted by arrests on other
charges.

• The physical security team has apprehended 4 individuals during three trespassing
incidents on BioNova property in the last year. Routine security checks of the
warehouse building and the campus perimeter occur every hour.

• The perimeter fence is 8 feet tall with concertina wire at the top of both the internal

and external sides of the fence.

• There are 13 cameras and 5 motion sensors connected to the warehouse’s alarm
system. This equipment provides coverage of 90% of the warehouse’s entrances and
exits.

• Physical security awareness training is conducted only to newly hired employees as


part of onboarding.

Network Security Team

• In the past 6 months, chatter about BioNova on the dark web and in known

organized crime communication channels has increased ten-fold, with the


information security team registering three to five credible mentions each month.
For which variables does Jim’s team have the largest amount of high-quality, readily-
available information?
Threat Event Frequency and Vulnerability

Which of the estimates and rationale below seems most reasonable for Threat
Event Frequency given the information the team collected?

Option Min ML Max Rationale


A 2 4 30 Per the physical security team, federal law enforcement
has alerted BioNova to two credible threats of theft in the
past year and the physical security team handled three
instances of trespassing. The information security team
reports that BioNova is attracting increased attention on
communication channels known to be used by organized
crime, thus it is reasonable to estimate that the number
of attempted thefts will increase ten-fold over the next
year.
B 1 2 8 While federal law enforcement has alerted BioNova to
two credible threats of theft in the past year, it is
probable that attempted theft will decrease over the next
year as organized criminals realize that previous
attempts have been discovered and thwarted, whether
by federal law enforcement or by BioNova’s own
physical security staff. The 4 individuals apprehended for
trespassing in the past year, if connected to organized
crime, could serve as a deterrent against further
attempts. It is also probable, however, that attempted
thefts will increase given the additional attention
BioNova is getting in organized crime circles per the
information security team.
C 0 0.5 2 BioNova has never experienced a theft of therapy drugs
from the warehouse by organized criminals in the past.
In fact, there has only been one successful theft in the
past 7 years according to the physical security team. At
most, we expect two attempted thefts over the next year,
matching the two credible threats of theft reported by
federal law enforcement in the last year.
Which of the estimates and rationale below seems most reasonable for
Vulnerability given the information the team collected?

Option Min ML Max Rationale


A 30% 50% 60% Team members are known to allow others to
piggyback on badge access and to leave the
cargo loading dock door open for long periods of
time. These conditions make it more probable
than not that attempted thefts will be successful.
B 0% 1% 2% The Physical Security team has proven capable of
stopping all attempted thefts, as evidenced by the
previous trespassing arrests.
C 0% 5% 20% The Physical Security team conducts regular
perimeter and warehouse checks, has camera
coverage of a majority of the warehouse
entrances and exits, and has a known history of
apprehending trespassers. However, checks only
occur every hour, and team members do not
exhibit a security-focused culture. It is
conceivable, but not tremendously probable, that a
group of thieves would successfully evade
BioNova’s security controls.
Having made estimates for Threat Event Frequency and Vulnerability the team
moves on to understanding how much the organization might lose from the theft of
therapy drugs from the warehouse by organized criminals.

Interviews were conducted with a number of teams within BioNova resulting in


collection of the following information:

• The warehouse contains anywhere from 5,000 to 30,000 units of medicines


manufactured by BioNova at any given time. It is estimated that the most a small
team of thieves could quickly remove between routine security checks is 12,000 units.

• In the event of a theft the physical security team is likely to work overtime
investigating and assisting law enforcement officials. 2 to 5 team members will likely
work 8 to 40 hours of overtime at a rate of $40/hr.

• Profit per unit ranges from $170 to $320 depending on the product.

• BioNova’s contracts with drug distributors specify penalties if products aren’t


delivered to distributors on time. For late delivery within one week of scheduled
delivery date, BioNova will be penalized $2.25 per unit. This penalty triples to $6.75
per unit for delivery more than one week late.

• BioNova’s name-brand medicines are proprietary and cannot be manufactured by


competitors.

• The raw materials to make each unit of medicine cost BioNova $1.40, and factory
workers will be paid overtime to manufacture medicine to replace the stolen units. It
takes a team of 15 workers 8 hours to produce 1,000 units. At overtime rates those
workers will be paid $32 per hour.

• BioNova expects to be able to rush deliver up to 10,000 units to distributors within 7


days.
What types of loss can BioNova anticipate arising from this scenario based on the
information above? Circle all that apply:

Primary Productivity Secondary Productivity


Primary Response Secondary Response
Primary Competitive Advantage Secondary Competitive Advantage
Primary Replacement Secondary Replacement
Primary Fines/Judgments Secondary Fines/Judgments
Primary Reputation Secondary Reputation

Use the space below to record the calculations used to arrive at calibrated
estimates for each relevant type of loss.

Primary Productivity
The profit BioNova would have made from the sale of the stolen drugs.
Min: 5,000 stolen units x $170 profit per unit = $850,000
Max: 12,000 stolen units x $320 profit per unit = $3,840,000
Use suggested most likely value with normal curve shape and low confidence.

Primary Response
The time the physical security team will spend investigating and liaising with law
enforcement.
Min: 2 team members x 8 hours x $40/hour = $640
Max: 5 team members x 40 hours x $40/hour = $8,000
Use suggested most likely value with normal curve shape and low confidence.
Primary Replacement
The capital BioNova will spend replacing the stolen assets.
Min: 15 workers x 8 hours x $32 = $3,840 to replace 1,000 units
$3,840 x 5 (since a minimum of 5,000 units need to be replaced) = $19,200
1.40 x 5,000 = $7,000 + $19,200 = $26,200

Max: $3,840 x 12 (since a maximum of 12,000 units need to be replaced) = $46,080


1.40 x 12,000 = $16,800 + $46,080 = $62,880
Use suggested most likely value with normal curve shape and low confidence.

Secondary Fines/Judgments

Min: 5,000 late units x $2.25 per unit = $11,250


Max: 12,000 late units
10,000 late units x $2.25 per unit = $22,500
2,000 late units x $6.75 per unit = $13,500
$13,500 + $22,500 = $36,000
Use suggested most likely value with normal curve shape and low confidence.

Secondary Loss Event Frequency

Given no information to the contrary, assume that 100% of thefts of drugs from the
warehouse would result in some secondary losses.
Part 3: Presenting Results
How would you summarize the calculated risk results to senior leadership?
Case Study #2: Stark Industries

Part 1: Scoping the Scenario


Read the following information and write a properly scoped scenario statement for
the analysis the CyberRisk Team will conduct.

Stark Industries is a manufacturing company focusing on clean energy located in


Cleveland, OH. During a recent Cyber Security Awareness week, the CTO, Tony Stark,
learned of the numerous external threats that could potentially cause an outage to
Stark Industries’ applications, most notably DDoS attacks.

Tony began to worry, particularly about the order processing system. The order
processing application is a web-based application customers use to order specific
products Stark Industries manufactures. While Stark Industries does not attract
attention from advanced cyber-criminal groups or nation-state actors, they have
faced attacks from the general hacking community in the past.

Tony asked the CyberRisk Team to investigate and prepare a report for him on the risk
to the company if the order processing system were to go down from a DDoS attack.
The CyberRisk Team got right to work scoping the analysis.

Scenario statement:

Analyze the risk associated with malicious external hackers impacting the
availability of the order processing system via a DDoS attack.

Write context-specific questions for Threat Event Frequency and Vulnerability.

Over the next year, how many times will malicious external hackers attempt to
impact the availability of the order processing system via a DDoS attack.

Of the attempts over the next year by malicious external hackers to impact the
availability of the order processing system via DDoS attack, what percent will be
successful?
Part 2: Collecting Data and Estimates
The CyberRisk Team held meetings with teams from across the company and
obtained the following information. Note that not all data points are relevant to
your analysis. As in the real world, you have to determine what information applies
to your scenario, and to what variable of the FAIR model the information
corresponds.

• The Incident Management Team reports that DDoS attacks hit the order processing
system once or twice a month, and that the team manages 3-5 security-related
incidents per week related to the network, systems, and desktops.

• The Network Security Team estimated that remote sources scan the order
processing web application between 1 and 5 times per day. Firewalls and scanners
are in place to detect spikes in incoming traffic. They also reported that the order
processing system has only gone down one time in the past 5 years due to an
internal software development error. Finally, they shared information about the
Claridge tool, a DDoS protection/mitigation service in place to protect the order
processing system. The tool registers, on average, 12 attempted DDoS attacks
against Stark Industries per year.

• The Application Security Team estimated that 10,000 transactions are handled by
the order processing system each day.

Based on the information above, should the CyberRisk Team estimate Loss Event
Frequency, or should they estimate Threat Event Frequency and use it to derive
Loss Event Frequency?

Threat Event Frequency

What is a reasonable estimate for Threat Event Frequency given the information
above? Remember that you’ll need to provide a minimum, maximum, most likely,
and level of confidence in the most likely.
Answers will vary, but something like min: 10, max: 24, most likely 12 is reasonable.
Medium confidence since multiple teams corroborated with hard data.
Having made an estimate of Threat Event Frequency, the CyberRisk Team continues
interviews to understand how vulnerable Stark Industries is to a DDoS attack.

• Annually the company holds a Cyber Security Week where all employees are trained
on how to recognize and respond to various types of attack.

• IT management meets once a month to discuss security, new risk scenarios, and
functionality of relevant business process applications.

• The Database Security Team reported that all databases that support internal-facing
applications are patched regularly. At any point, they estimate that there is at least
one bug or defect on the databases they control. These issues are often very limited
and, in their opinion, would require a very sophisticated threat actor to exploit.

• The Database Security Team also discussed the Claridge DDoS mitigation service
which filters traffic and blocks malicious campaigns. They reported that, while there
hasn’t been a successful DDoS attack against the company yet, based on increasing
sophistication of attacks they believe that 1 attack in 20 (or 5%) are likely to
overcome the Claridge tool’s current capabilities.

What is a reasonable estimate for Vulnerability given the information above?


Remember that you’ll need to provide a minimum, maximum, most likely, and level
of confidence in the most likely.

Answers will vary, but min: 1%, max: 10%, most likely: 5%. Low confidence since this
appears to be well-informed conjecture but with no hard evidence offered.
The CyberRisk Team now begins to investigate probable loss magnitude in the
event of a successful DDoS attack. The following information was gathered from
meetings with teams from across the organization.

Sales Management

• The company generates approximately $100M of revenue per year and values the
average customer at $2,000. Stark Industries manufactures many products, but
their main source of revenue (accounting for more than 90%) is niche products
which can only be purchased from Stark. If a customer is temporarily unable to
place an order they will not likely switch to another manufacturer as there are no
other manufacturers of Stark Industries’ niche products.

• The company employs approximately 4,000 employees. 200 employees exclusively


use the order processing system to manage orders.

Incident Response

• In the event of a DDoS attack, 2-5 people would be assigned for 8-40 hours at a
loaded hourly wage of $100 per hour.

• If an outage of the order processing system was caused by an external threat, a


third-party forensic investigation team would be hired. These investigations cost an
average of $100,000.

• The order processing system has gone down once in the past 5 years due to an
internal error. In that incident the system was brought back online within 30
minutes.

Business Continuity and Disaster Recovery

• There is no redundancy for the order processing system. Prior outages have been
rectified within 30 minutes, so the organization has decided not to invest in a
backup order processing system in the past. The RTO for the order processing
system is 4 hours.
Business Continuity and Disaster Recovery (continued)

• In the event of an outage, the productivity of 200 employees who process online
orders, ship and receive orders, and perform administrative tasks requiring the
order processing system would be impacted. These employees’ average loaded
hourly wage is $75.

• From past outages, Customer Service estimates they would experience an increase
of 50-200 calls for an outage ranging from 30 minutes to 4 hours. Each customer
service call costs the company on average $2.00.

Application Security Team

• Stark Industries pays Claridge $1,000/month to provide DDoS protection services.

Regulatory Compliance

• Fines related to a breach of customer credit card information of over 100,000


records have ranged from $20,000 to $100,000 over the last 5 years.

• Industry data indicates that regulators have rarely sued organizations for outages
caused by an external threat.

• The company has signed a contract with a credit monitoring service and would offer
that service to clients in the event of a data breach. The contract states it would cost
Stark Industries $23 per customer up to 20,000 customers. Beyond that a 50%
discount would apply.

What types of loss should Stark Industries consider? Circle all that apply.

Primary Productivity Secondary Productivity


Primary Response Secondary Response
Primary Competitive Advantage Secondary Competitive Advantage
Primary Replacement Secondary Replacement
Primary Fines/Judgments Secondary Fines/Judgments
Primary Reputation Secondary Reputation
Use the space below to record the calculations used to arrive at calibrated
estimates for each relevant type of loss.

Primary Productivity
200 employees’ productivity impacted by the outage, wages paid for downtime
200 affected employees, outage minimum duration of 15 minutes, most likely of 30
minutes, maximum of 2 hours (4 times as long as last known restore seems
reasonable)
min: 200 x .25 x 75 = 3750
ml: 200 x .5 x 75 = 7500
max: 200 x 2 x 75 = 30,000

Primary Response
$81,650, $104,900, $145,200

Internal incident response


min: 2 x 8 x 100 = 1600
ml: 3 x 16 x 100 = 4800
max: 5 x 40 x 100 = 20000

External incident response/investigation


min: 80k
ml: 100k
max: 125k

Additional call volume


min: 25 calls x $2 = $50
ml: 50 calls x $2 = $100
max: 100 calls x $2 = $200
Part 3: Presenting Results
How would you summarize the calculated risk results to senior leadership?
Case Study #3: Initech

Part 1: Scoping the Scenario


Read the following information and write a properly scoped scenario statement for
the analysis Initech’s Risk Team will conduct.

Initech Corporation is a Software Company (SaaS) located in Denver, Colorado. Their


software helps start-ups across the nation with their marketing plans. The company
has experienced significant growth in the past 5 years due to the influx of start-ups.

In an effort to determine the company’s top risks, the CISO, Lydia, recently decided to
update their Risk Register. From this exercise, Lydia learned that phishing is of high
concern to her company and industry. Phishing campaigns were found to be one of
the top vectors by which threat actors could gain a foothold into a company’s network
and possibly exfiltrate sensitive data. While Initech is not a target for nation-state
actors or advanced groups of cybercriminals, the company is occasionally targeted by
run-of-the-mill external malicious hackers.

Lydia considered the various systems Initech relies on and determined that the
largest risk exposure is associated with a breach of the eCommerce database. This is
an internal database that stores information when customers purchase Initech’s
software, including company name, address, credit card number, purchasing history,
product pricing, etc.

Lydia shares this information with the Risk Team and asks them to conduct an
analysis.

Scenario statement:

Analyze the risk associated with external malicious hackers impacting the
confidentiality of customer data in the eCommerce database via a phishing attack.
Write context-specific questions for Threat Event Frequency, Vulnerability, and
Secondary Loss Event Frequency.

Over the next year, how many times will malicious external hackers attempt to
impact the confidentiality of the customer data in the eCommerce database via a
phishing attack?

Of the attempts over the next year by malicious external hackers to impact the
confidentiality of the customer data in the eCommerce database, what percentage
will be successful?

When malicious external hackers successfully breach the confidentiality of the


customer data in the eCommerce database via phishing, what is the probability that
Initech will experience any secondary losses?

Part 2: Collecting Data and Estimates


The Risk Team held meetings with teams from across the company and obtained
the following information. Note that not all data points are relevant to your
analysis. As in the real world, you have to determine what information applies to
your scenario, and to what variable of the FAIR model the information corresponds.

• The Incident Response Team doesn’t often perform root cause analysis on
incidents, so there is limited knowledge of past security events and their causes.

• No IT or Information Security-related teams report knowledge of a breach of this


type occurring within the last 10 years.

• The Network Security Team reports that they detect malicious activity on the
network on average once per quarter. They estimate that remote sources scan the
eCommerce website between 1 and 7 times per day.

• The Application Security Team estimates that 850 connections are made to the
eCommerce database each day, and the site has not experienced an unplanned
outage in the last 5 years.
Based on the information obtained should the Risk Team estimate Loss Event
Frequency or estimate Threat Event Frequency and use it to derive Loss Event
Frequency?
Since there is “limited knowledge of past security events and their causes,” an
estimate of Loss Event Frequency is unadvisable. The best data point we have is
detected malicious activity on the network on average once per quarter. We’ll need
to build a range around this since some of that activity may not be related to
phishing, and there could be malicious activity related to phishing that hasn’t been
detected.

What is a reasonable estimate for Threat Event Frequency given the information
above? Remember that you’ll need to provide a minimum, maximum, most likely,
and level of confidence in the most likely.
Responses will vary, min: .5, most likely: 2, max: 6, low confidence is reasonable.

The Risk Team continued to interview additional teams to gain information about
Initech’s vulnerability to breaches via phishing attacks.

• The Database Security Team is behind on patching the majority of databases that
support internet-facing applications and only patch internal systems every 3-6
months. They are confident that open issues/bugs would take sophisticated threat
actors to exploit.

• Change Management processes require automated code testing that looks for
errors and known security weaknesses in code. Only an estimated 5 out of 100
changes do not follow the entire process. These changes are usually related to
emergency hot fixes.

• Extensive anti-phishing training is provided on an annual basis. All team members


are required to pass a quiz before access to work-necessary systems is restored.
Team members can report phishing emails by clicking a button in their email client.

• Email filtering tools catch around 90% of phishing emails per the Database Security
Team, and only around 10% of phishing emails that make it to team members’
inboxes are opened. Only the most convincing phishing emails are opened.
Does the information above allow us to estimate Initech’s vulnerability to
confidentiality breaches via phishing attacks? Or will we need to estimate Threat
Capability and Resistance Strength to derive Vulnerability?
Since there is no data directly applicable to the number of attempts that will be
successful, we should estimate at TCap and RS. We’ll use the out of the box figure
for TCap.

Based on the information about Initech’s control environment, which Resistance


Strength estimate is most appropriate?

5% to 15% 65% to 90% 35% to 55%

Open bugs would require sophisticated threat actors to exploit, and the control
environment seems strong, with extensive phishing training and filtering
capabilities. Only the most sophisticated phishing emails would even be opened,
indicating that someone would have to be high up on the threat capability
continuum to defeat Initech’s controls.

Having obtained data and estimates for Threat Event Frequency, Threat Capability,
and Resistance Strength, the Risk Team moves on to gathering data about loss
magnitude in the event of a breach.

Sales Management

• Approximately 2 million customers use the eCommerce website on an annual basis.


Approximately 500,000 customers have stored their credit card information on the
website. The eCommerce website generates roughly $12.5M in revenue each year,
with an average customer value of $400.

Incident Response

• In the event of a breach a team of 5-8 people would be deployed for 8-20 hours at a
loaded hourly wage of $100/hr.

• Industry data shows that companies typically don’t discover data breaches for
months after the event. Given this, Initech would likely continue to operate the
website during the investigation.
Incident Response (continued)

• In the event of a data breach, a third-party forensic team would be hired to


investigate how much data was stolen and how it was taken. Investigations of this
scale cost an average of $200,000.

Regulatory Compliance

• Notifying impacted customers will cost around $5 per customer.

• Over the past 3 years, fines related to a breach of over 500,000 customer credit card
records have ranged from $150,000 to $500,000.

• Industry data shows that courts and regulators have rarely held companies
accountable for fraudulent credit card charges that occur after a data breach.

• Initech has a contract in place to provide credit monitoring to customers impacted


by a breach. The cost is $35 per customer up to 10,000 customers, after which the
price drops to $30 per customer. It is estimated that only 10% of impacted
customers would elect to use the credit monitoring service.

Marketing/Public Relations

• In the event of a data breach it is estimated that 2% of affected customers would


stop purchasing products from Initech and choose a competitor going forward.

What types of loss should Initech consider? Circle all that apply.

Primary Productivity Secondary Productivity


Primary Response Secondary Response
Primary Competitive Advantage Secondary Competitive Advantage
Primary Replacement Secondary Replacement
Primary Fines/Judgments Secondary Fines/Judgments
Primary Reputation Secondary Reputation
Use the space below to record the calculations used to arrive at calibrated
estimates for each relevant type of loss.

Primary Response
$154,000, $209,600, $282,000
Internal Incident response:
5 people x 8 hours x 100/hr = $4,000
6 people x 16 hours x 100/hr = $9,600
8 people x 40 hours x 100/hr = $32,000

External incident response:


min: $150k
ml: $200k
max: $250k

Secondary Loss Event Frequency: 100%

Secondary Response
$3,300,000, $4,050,000, $5,550,000

Credit monitoring costs


min: 500k impacted x 5% take up rate = 25k customers = $800k dollars
ml: 500k impacted x 10% take up rate = 50k customers = $1.55m dollars
max: 500k impacted x 20% take up rate = 100k customers = $3.05m dollars
Notifying impacted clients: 500,000 x $5 = $2.5mil

Secondary Fines and Judgments


$150,000, $325,000, $500,000
Regulatory fines associated with a breach of over 500k records.

Secondary Reputation
$2,100,000, $4,000,000, $6,500,000
Approximately 10k customers would no longer do business with us, and the value
of a customer is $400.
min: 7k x $300 = $2.1m, ml: 10k x $400 = $4m, max: 13k x $500 = $6.5m
Part 3: Presenting Results
How would you summarize the calculated risk results to senior leadership?

Common questions

Powered by AI

To improve risk reporting, BioNova should enhance the precision of data estimates, extend vulnerability assessment to behavioral and technical controls, and integrate quantitative analysis results into strategic meetings with leadership to guide decision-making on risk trade-offs and investments .

Secondary losses for BioNova could include regulatory penalties, strained relationships with clients and partners, and potential reputational damage. Since 100% of thefts are expected to cause these secondary effects, BioNova must account for the long-term strategic and operational impacts beyond immediate financial losses .

The economic impact of a theft could be significant, involving potential loss of up to 12,000 drug units between security checks, with a profit per unit between $170 and $320. This translates into a maximum potential loss ranging from $2.04 million to $3.84 million, highlighting vulnerability in asset management without adequate mitigation .

Employee behavior significantly impacts vulnerability estimation, with practices such as allowing unauthorized access and leaving loading doors open displaying a security culture gap. These behaviors heighten the risk of successful thefts despite technological controls, underscoring a need for continuous security training and behavioral interventions .

The vulnerability estimates at BioNova range from 0% to 60% based on several factors including employee behavior, such as unauthorized access practices and periods of unsecured access points, contributing to increased likelihood of successful theft. The physical security team's successful prevention of past attempts suggests lower vulnerability, but gaps identified necessitate a cautious vulnerability estimate .

BioNova's current security measures include badge controls and security training, yet these seem compromised by behavioral lapses like door propping and habitual bypassing of badge requirements. Although there is substantial coverage by security cameras and routine perimeter checks, vulnerability appears higher than optimal due to these lapses, making additional security enforcement necessary .

The FAIR model helps BioNova Solutions quantify and prioritize its risk exposure from organized crime theft through structured analysis. It breaks down risk into components like Threat Event Frequency, Loss Event Frequency, and Vulnerability. By doing so, BioNova can estimate the probability and potential impact of theft attempts, allowing the CRO to provide insight into risk exposure and prioritize mitigation strategies based on risk reduction per dollar spent .

The increased attention from organized crime networks, evidenced by the rise in chatter on dark web and crime channels, suggests a higher probability of theft attempts, leading to an estimated increase in threat event frequency. This necessitates incorporation of these intelligence insights into strategic security planning and resource allocation .

Factors contributing to threat event frequency include historical data of theft alerts and trespassing incidents, increased chatter on organized crime channels about BioNova, and prior pre-empted theft attempts as reported by law enforcement and physical security teams. This suggests that threats are credible and may escalate in frequency, especially given the valuable nature of BioNova’s products .

Stark Industries should consider primary productivity loss from disrupted operations, costs associated with incident response such as overtime and forensic investigations, potential fines/judgments if customer data is compromised, and impacts on reputation. The comprehensive understanding of these factors aids in preparing robust response and mitigation strategies .

You might also like