Chosen Risk Management Project
Project Title: Cybersecurity Risk Management for a Retail Business
Business Area: IT and Data Protection
Role: Leading the risk management process for cybersecurity, ensuring compliance
with data protection laws, and mitigating security threats.
Scope: Identifying and addressing cybersecurity risks, implementing controls, and
ensuring compliance with industry regulations.
Excluded Risks: Hardware-related risks and third-party vendor risks, as they are
managed by a separate IT procurement team.
Establishing the Risk Context
Legal and Organizational Requirements:
o Compliance with GDPR (data protection and privacy laws).
o Adherence to Work Health and Safety (WHS) Act for IT security in
workplaces.
Policies and Procedures:
o Cybersecurity policies covering data access, password management, and
system monitoring.
o Risk assessment and incident response procedures.
Resources Available:
o Risk management software, IT security experts, employee training
programs, budget allocation for system upgrades.
Objectives and Critical Success Factors:
o Objective 1: Prevent unauthorized access and data breaches.
o Objective 2: Ensure compliance with cybersecurity regulations.
o Critical Success Factors:
Effective employee training.
Robust monitoring systems.
Regular risk assessments and updates.
Stakeholders & Responsibilities:
o IT Manager: Oversees security infrastructure and risk mitigation.
o Compliance Officer: Ensures adherence to regulations.
o Employees: Responsible for following cybersecurity policies.
o Executives: Approve risk management strategies.
Communicating with Stakeholders
Meeting Details: Conducted with IT Manager, HR, and Finance representatives.
Discussion Points:
o Current cybersecurity threats.
o Compliance requirements and risk mitigation strategies.
Stakeholder Input:
o IT Manager emphasized system updates.
o HR proposed mandatory cybersecurity training.
o Finance assessed the cost-effectiveness of mitigation strategies.
Outcome: Agreement on conducting a cybersecurity risk assessment and
improving employee awareness.
Analyzing the Business Environment
Internal Risks:
o Weak password policies.
o Lack of employee training.
o Unpatched security vulnerabilities.
External Risks:
o Cyber-attacks and phishing scams.
o Non-compliance with GDPR, leading to legal penalties.
o Third-party system failures impacting operations.
Strengths and Weaknesses:
o Strengths: Dedicated IT team, existing cybersecurity measures.
o Weaknesses: Inconsistent security awareness among employees.
Documentation Reviewed: Security audit reports, compliance guidelines,
incident logs.
Identifying and Discussing Risks
Key Risks Identified:
1. Phishing Attacks: Employees being tricked by fraudulent emails.
2. Weak Passwords: Use of simple or reused passwords.
3. Unpatched Software: Delayed security updates leaving vulnerabilities open.
Potential Outcomes and Prioritization:
Phishing Attacks: High likelihood, high impact → Top priority
Weak Passwords: Moderate likelihood, high impact → Second priority
Unpatched Software: Low likelihood, high impact → Third priority
Prioritization Method Used: Risk scoring based on impact and likelihood assessment.
Risk Analysis and Documentation
Risk Register Updated: Included risk category, likelihood, impact, and
mitigation plan.
Cybersecurity Risk Scale: Used qualitative and quantitative data to assess risk
levels.
Documentation Stored: Incident response plans, training materials, risk
assessment reports.
Action Plan Development and Implementation
Risk Treatment Plan for Weak Passwords:
Solution: Implement mandatory Multi-Factor Authentication (MFA) and
enforce strong password policies.
Implementation Process:
o IT team enabled MFA on all accounts.
o Employees received training on secure password creation.
o Regular security audits introduced.
Stakeholder Communication:
o Employees informed via email and online training sessions.
o IT department monitored compliance through security logs.
Risk Management Documentation:
o Updated policy documents to reflect new security requirements.
Monitoring and Evaluating the Risk Management
Process
Evaluation Period: One month after implementing MFA and new security
policies.
Findings:
o Phishing incidents dropped by 60%.
o Unauthorized access attempts reduced by 80%.
o Employee compliance rate improved to 95%.
Stakeholder Feedback:
o IT team recommended periodic security drills.
o HR proposed ongoing refresher training for employees.
Adjustments Made:
o Strengthened password policies.
o Increased phishing awareness campaigns.
Outcome Report:
o Risk mitigation efforts successfully reduced security threats and
improved regulatory compliance.
Considerations
Evaluation Period: One month after implementing MFA and new security policies.
Findings:
Phishing incidents dropped by 60%.
Unauthorized access attempts reduced by 80%.
Employee compliance rate improved to 95%.
Stakeholder Feedback:
IT team recommended periodic security drills.
HR proposed ongoing refresher training for employees.
Adjustments Made:
Strengthened password policies.
Increased phishing awareness campaigns.
Outcome Report:
Risk mitigation efforts successfully reduced security threats and improved
regulatory compliance.