KD-004 // PROTECTING THREAT ANALYSIS INTELLIGENCE ACTIVE
HOUSE VENTER // THREAT ANALYSIS

Cybersecurity Threats Facing South African Businesses

Cybersecurity risk does not come from one single type of attack.

Businesses depend on people, accounts, email, devices, software and data — and each can create a different path for compromise.

OPEN INTELLIGENCE RECORD ↓
THREAT SURFACE // LIVE MODEL MULTI-VECTOR
BUSINESS THREAT SURFACE
BUSINESS
SYSTEM
VECTOR 01 People
VECTOR 02 Identity
VECTOR 03 Email
VECTOR 04 Endpoints
VECTOR 05 Software
VECTOR 06 Data
ATTACK PATHS MULTIPLE
EXPOSURE ENVIRONMENT-SPECIFIC
OBJECTIVE REDUCE RISK
RECORD // KD-004
PROTECTING // CYBERSECURITY
HOUSE VENTER // KNOWLEDGE DOCK
00
EXECUTIVE BRIEF

Cybersecurity Is a Business Risk, Not Just a Technical Problem

Modern businesses rely on technology for communication, banking, customer information, cloud applications, documents and day-to-day operations.

That dependence means a cybersecurity incident can affect more than a computer. It can affect access to systems, information, payments, productivity and the ability of the business to operate normally.

Cybersecurity therefore involves more than installing security software. It requires an understanding of where exposure exists, how different attack paths can develop and which controls are appropriate for the environment.

KD-004 // OPERATING PRINCIPLE RISK REDUCTION
01 EXPOSURE Multiple Attack Paths

People, identities, email, endpoints, software and data can each create different forms of cybersecurity exposure.

→
02 SECURITY OBJECTIVE Reduce the Risk

Appropriate security controls can reduce exposure, improve visibility and strengthen the ability to respond when suspicious activity occurs.

HOUSE VENTER // FIELD POSITION Security controls exist to reduce exposure, improve visibility and strengthen the ability to respond — not to create a guarantee of absolute protection.
01
THE THREAT SURFACE

Where Does Cybersecurity Risk Begin?

A business does not have one single cybersecurity boundary.

Employees use accounts. Accounts access email and cloud services. Email reaches devices. Devices run software. Software interacts with business information and other systems.

Weakness, misuse or compromise at one point can sometimes create a route toward another. Understanding cybersecurity therefore requires looking at the environment as a connected system rather than a collection of isolated devices.

KD-004 // THREAT SURFACE CONNECTED EXPOSURE

Cybersecurity exposure can exist across several connected layers of the business environment.

01 HUMAN LAYER People

Decisions, behaviour and interaction with technology.

02 ACCESS LAYER Identity

User accounts, credentials and authentication.

03 COMMUNICATION LAYER Email

Messages, links, attachments and business communication.

04 DEVICE LAYER Endpoints

Laptops, desktops and other devices used to access business systems.

05 APPLICATION LAYER Software

Applications, operating systems and connected services.

06 INFORMATION LAYER Data

Business information that may be accessed, changed, exposed or made unavailable.

CONNECTED ENVIRONMENT // CONCEPTUAL FLOW
PEOPLE
→
IDENTITY
→
EMAIL
→
ENDPOINTS
→
SOFTWARE
→
DATA
FIELD NOTE

Cybersecurity risk can move through connected systems, identities and processes rather than remaining isolated to one device. A compromised account, deceptive email or vulnerable endpoint can sometimes become the beginning of a wider incident.

02
PHISHING & SOCIAL ENGINEERING

When the Target Is the Person, Not Just the Computer

Not every cyberattack begins by exploiting software. Some begin by persuading a person to do something the attacker wants.

Phishing commonly uses deceptive messages that appear to come from a trusted person, organisation or service. The message may encourage the recipient to open a link, provide credentials, download a file, approve a request or take some other action.

Social engineering is the broader technique of manipulating people into revealing information or performing an action. Phishing is one of the common ways that manipulation can be delivered.

KD-004 // CONCEPT DISTINCTION DELIVERY ≠ MANIPULATION
DELIVERY METHOD Phishing

A deceptive communication intended to influence the recipient into taking an action or providing information.

HUMAN TECHNIQUE Social Engineering

Manipulation that uses trust, authority, urgency, fear, curiosity or other human factors to influence a decision or action.

PHISHING // CONCEPTUAL ATTACK PATH HUMAN INTERACTION
STAGE 01 Deceptive Message
→
STAGE 02 Human Interaction
→
STAGE 03 Credential, Download or Action
→
STAGE 04 Access or Execution
→
STAGE 05 Potential Business Impact
SOCIAL ENGINEERING // COMMON PRESSURE SIGNALS
SIGNAL 01 Urgency

Pressure to act immediately before there is time to verify the request.

SIGNAL 02 Authority

A message appears to come from a manager, supplier, bank or other trusted authority.

SIGNAL 03 Fear

The recipient is warned about an account problem, penalty, security issue or other negative consequence.

SIGNAL 04 Opportunity

Curiosity, reward or an unexpected opportunity is used to encourage interaction.

RISK REDUCTION // LAYERED CONTROLS
CONTROL 01 User Awareness
CONTROL 02 Message & Endpoint Security
CONTROL 03 Strong Authentication
CONTROL 04 Independent Verification
FIELD NOTE

A convincing phishing message does not need to look obviously suspicious. Unexpected requests involving passwords, payments, account changes, downloads or sensitive information deserve verification through a trusted channel before action is taken.

03
BUSINESS EMAIL COMPROMISE

When a Trusted Business Message Cannot Be Taken at Face Value

Business Email Compromise, commonly referred to as BEC, uses the trust surrounding normal business communication to influence payments, information sharing or other business actions.

An attacker may impersonate a director, employee, supplier or other trusted party. In some incidents the message comes from a lookalike address. In others, a genuine email account may have been compromised and used without the legitimate user's knowledge.

This makes BEC particularly important to understand. A fraudulent instruction does not always arrive in an obviously fraudulent email.

KD-004 // TRUST MODEL BUSINESS PROCESS AT RISK
01 IDENTITY Who Appears to Be Asking?

The message may appear to come from somebody the recipient already knows or expects to communicate with.

02 INSTRUCTION What Is Being Requested?

The request may involve a payment, banking-detail change, sensitive information or another business action.

03 PROCESS How Is It Verified?

The strength of the business process can determine whether a deceptive instruction is challenged before it is acted upon.

BEC // CONCEPTUAL TRANSACTION PATH TRUST EXPLOITATION
STAGE 01 Trusted Identity Impersonated or Compromised
→
STAGE 02 Business Request Is Sent
→
STAGE 03 Payment, Banking or Information Instruction
→
STAGE 04 Verification Succeeds or Fails
→
STAGE 05 Business Outcome
PROCESS CONTROL // BREAK THE ATTACK PATH

Verification Creates a Decision Point

When a request involves money, banking details, credentials or sensitive information, an independent verification step can interrupt the attack path. The verification should use a trusted contact method rather than relying only on the contact details contained in the unexpected message itself.

BEC // BUSINESS WARNING SIGNALS
SIGNAL 01 Banking Change

Existing payment details are suddenly replaced with new account information.

SIGNAL 02 Unusual Urgency

The recipient is pressured to bypass the normal approval or verification process.

SIGNAL 03 Unexpected Secrecy

The request discourages discussion with colleagues or normal business contacts.

SIGNAL 04 Process Change

A familiar supplier, manager or customer suddenly asks for something outside the normal process.

RISK REDUCTION // BUSINESS + TECHNICAL CONTROLS
CONTROL 01 Strong Authentication
CONTROL 02 Account & Email Security
CONTROL 03 Payment Verification
CONTROL 04 Defined Approval Process
FIELD NOTE

Checking the sender address is useful, but it is not sufficient in every situation. If a legitimate account has been compromised, the message may genuinely come from the expected address while the instruction itself is fraudulent.

04
RANSOMWARE & EXTORTION

When Cybersecurity Becomes an Operational Crisis

Ransomware is a form of malicious activity designed to disrupt access to systems or data and create pressure on the victim. Encryption is one of the mechanisms commonly associated with ransomware incidents.

Modern ransomware incidents can involve more than encryption alone. Depending on the incident, attackers may also steal information and use the threat of disclosure as an additional form of extortion.

For a business, the technical compromise is therefore only part of the problem. The incident can affect access to information, availability of systems, normal operations and the recovery work required afterwards.

SOUTH AFRICA // THREAT CONTEXT

Ransomware is a relevant threat in the South African environment. INTERPOL's 2025 Africa Cyberthreat Assessment identified ransomware among the prevalent cyberthreats reported across Africa, while private-sector partner data cited in the assessment indicated that South Africa and Egypt recorded the highest numbers of ransomware incidents in Africa during 2024. This provides useful context for the threat, but it does not mean that every South African business faces the same level of risk.

KD-004 // RANSOMWARE RESILIENCE THREE OBJECTIVES
01 BEFORE Reduce the Chance of Compromise

Security controls, patching, authentication and user awareness can reduce opportunities for initial compromise.

02 DURING Limit the Potential Impact

Visibility, appropriate access controls and response processes can help reduce the extent of an incident.

03 AFTER Preserve a Recovery Path

Appropriate backup and recovery arrangements can provide options for restoring required business data.

RANSOMWARE // CONCEPTUAL INCIDENT PATH COMPROMISE → IMPACT
STAGE 01 Initial Compromise
→
STAGE 02 Access or Execution
→
STAGE 03 Systems or Data Affected
→
STAGE 04 Operational Disruption
→
STAGE 05 Response & Recovery
INCIDENT // POTENTIAL BUSINESS IMPACT
IMPACT 01 Data Availability

Required information may become unavailable during the incident.

IMPACT 02 System Availability

Devices or services may need to be isolated, rebuilt or restored.

IMPACT 03 Operations

Normal business activity may be delayed or interrupted.

IMPACT 04 Information Exposure

Some incidents may also involve unauthorised access to or theft of information.

SECURITY MODEL // THREE LAYERS OF RESILIENCE
LAYER 01 Prevention & Reduction

Reduce opportunities for compromise through appropriate security controls.

→
LAYER 02 Detection & Response

Improve visibility and create a process for responding when suspicious activity is identified.

→
LAYER 03 Recovery

Maintain an appropriate recovery path for business data and systems within the recovery scope.

IMPORTANT DISTINCTION // BACKUP

Backup Is Recovery Capability, Not Ransomware Prevention

Backup can provide recovery options after data has been affected, provided appropriate recovery copies remain available and usable. It does not prevent an attacker from gaining access in the first place, and it does not replace endpoint security, authentication, patching, monitoring or incident response.

FIELD NOTE

No single control makes a business ransomware-proof. Resilience comes from reducing the likelihood of compromise, limiting the possible impact of an incident and preserving credible recovery options.

05
MALWARE & ENDPOINT COMPROMISE

When a Business Device Can No Longer Be Trusted

Laptops and desktops are often where users interact directly with email, websites, files, applications and business systems. That makes endpoints an important part of the cybersecurity environment.

Malware is software designed to perform malicious or unwanted activity. Depending on the type of malware and the circumstances, it may attempt to steal information, interfere with a system, provide unauthorised access or perform other harmful actions.

But malware is not the only way an endpoint can become compromised. Stolen credentials, vulnerable software, unsafe remote access, malicious scripts or misuse of legitimate tools can also contribute to an endpoint security incident.

KD-004 // CONCEPT DISTINCTION MALWARE ≠ ALL COMPROMISE
THREAT MECHANISM Malware

Malicious software or code used to perform unwanted actions on or through a system.

≠
SECURITY CONDITION Endpoint Compromise

A broader condition in which the security or trusted state of a device has been undermined.

ENDPOINT // CONCEPTUAL COMPROMISE PATH EXPOSURE → IMPACT
STAGE 01 Exposure or Entry Point
→
STAGE 02 Execution, Access or Exploitation
→
STAGE 03 Endpoint Compromised
→
STAGE 04 Activity on the Device
→
STAGE 05 Potential Wider Business Impact
ENDPOINT // EXAMPLES OF EXPOSURE
EXPOSURE 01 Malicious Files

Files or downloads may contain malicious code or trigger unwanted activity.

EXPOSURE 02 Vulnerable Software

Security weaknesses in software may create opportunities for exploitation.

EXPOSURE 03 Compromised Access

Stolen credentials or insecure access can allow unauthorised interaction with a device or service.

EXPOSURE 04 Misused Tools

Legitimate software and administrative tools can sometimes be abused after access has been obtained.

PROTECTING // LAYERED ENDPOINT DEFENCE
LAYER 01 Endpoint Security

Security technology can identify, block or respond to certain forms of suspicious activity.

LAYER 02 Patching

Keeping supported software updated can reduce exposure to known vulnerabilities.

LAYER 03 Access Control

Appropriate authentication and permissions can reduce unnecessary access and privilege.

LAYER 04 Monitoring & Response

Visibility and response processes help turn security information into action when attention is required.

HOUSE VENTER // PROTECTING PRINCIPLE

Endpoint Protection Is a Layer, Not a Guarantee

Endpoint security technology is an important part of reducing device-level risk, but no endpoint security product can guarantee that every malicious action will always be prevented. Effective endpoint defence combines appropriate security technology with patching, access control, monitoring, user awareness and response processes.

FIELD NOTE

A device does not need to display obvious symptoms before a security concern exists. Endpoint security is therefore concerned not only with visible malware, but with maintaining and monitoring the trusted state of the device.

06
VULNERABILITIES & PATCH EXPOSURE

When Known Weaknesses Remain Unaddressed

Software is complex, and security weaknesses can be discovered in operating systems, applications, services and other technology used by a business.

A vulnerability is a weakness that may create an opportunity for security to be bypassed, information to be exposed or a system to be affected under certain conditions.

When a vendor provides a security update that addresses a vulnerability, applying that update can reduce the organisation's exposure to the weakness being corrected.

That does not mean every vulnerability has an immediate patch, every update should be installed without consideration, or a patched system becomes immune to compromise.

KD-004 // VULNERABILITY MODEL WEAKNESS → EXPOSURE → REMEDIATION
01 CONDITION Vulnerability Exists

A weakness is present in software, configuration or another part of the technology environment.

02 EXPOSURE The Weakness Is Relevant

Actual risk depends on factors such as whether the affected technology is present, exposed and reachable under the required conditions.

03 RESPONSE Appropriate Remediation

A patch, configuration change, workaround, replacement or other control may be used to reduce the relevant exposure.

PATCHING // CONCEPTUAL EXPOSURE PATH KNOWN WEAKNESS
STAGE 01 Vulnerability Identified
→
STAGE 02 Fix or Mitigation Available
→
STAGE 03 Exposure Continues Until Addressed
→
STAGE 04 Relevant Exposure Reduced
PATCH MANAGEMENT // ONGOING PROCESS
STEP 01 Identify

Know which managed devices and supported software require attention.

→
STEP 02 Assess

Consider relevance, urgency, compatibility and operational requirements.

→
STEP 03 Deploy

Apply appropriate updates or remediation according to the management process.

→
STEP 04 Review

Check deployment status and investigate relevant failures or exceptions.

PATCHING // IMPORTANT REALITIES
REALITY 01 Not Every Weakness Has a Patch

Some vulnerabilities may require workarounds, configuration changes or other mitigations.

REALITY 02 Updates Can Require Planning

Compatibility, restart requirements and business operations may affect how an update is deployed.

REALITY 03 Unsupported Software Matters

Technology that no longer receives security support may require replacement or additional risk management.

REALITY 04 Patching Is One Layer

Updated software still requires appropriate security, access, monitoring and user controls.

HOUSE VENTER // PATCHING PRINCIPLE

Patching Reduces Known Exposure. It Does Not Eliminate Cyber Risk.

Applying appropriate security updates can reduce exposure to vulnerabilities addressed by those updates. The objective of patch management is therefore not to create a “fully secure” device, but to maintain an ongoing process for identifying, assessing, deploying and reviewing relevant updates.

FIELD NOTE

Installing updates is only one part of patch management. Somebody also needs visibility of which devices are managed, whether updates were deployed successfully and which systems still require attention.

07
IDENTITY & ACCESS RISK

When the Account Becomes the Attack Surface

Many business systems are protected by identity rather than by physical location. Email, cloud applications, documents and other services may be accessible from anywhere a legitimate user can sign in.

That makes user accounts and credentials valuable targets. If an attacker obtains or abuses valid access, activity may appear to come from an authorised user even when the person behind it is not authorised.

Identity security therefore involves more than choosing a password. Authentication, permissions, account lifecycle and the way suspicious access is handled all influence the risk surrounding an account.

KD-004 // IDENTITY MODEL IDENTITY → ACCESS
LAYER 01 Identity

The person or account attempting to use the service.

→
LAYER 02 Authentication

The process used to establish whether the sign-in should be trusted.

→
LAYER 03 Authorisation

The access and permissions available after authentication succeeds.

→
LAYER 04 Business Resources

Email, applications, files, data and other systems available to the account.

IDENTITY // CONCEPTUAL COMPROMISE PATH CREDENTIAL → ACCESS
STAGE 01 Credential or Session Targeted
→
STAGE 02 Authentication Challenged
→
STAGE 03 Unauthorised Access Obtained
→
STAGE 04 Account Permissions Used
→
STAGE 05 Potential Business Impact
IDENTITY // COMMON RISK AREAS
RISK 01 Weak or Reused Passwords

Reusing credentials can increase exposure when credentials from one service are compromised.

RISK 02 Credential Phishing

Deceptive sign-in pages or requests may attempt to capture account credentials.

RISK 03 Excessive Permissions

Accounts with more access than required can increase the potential impact of compromise.

RISK 04 Dormant Accounts

Accounts that are no longer required can create unnecessary access paths if they remain active.

AUTHENTICATION // MFA ADDITIONAL VERIFICATION
PASSWORD ONLY One Authentication Factor

If the password is obtained by an attacker, the account may have only that single authentication barrier protecting the sign-in.

→
MULTI-FACTOR AUTHENTICATION Additional Authentication Barrier

MFA requires another form of verification and can significantly reduce the usefulness of a stolen password on its own.

IDENTITY SECURITY // CONTROL AREAS
CONTROL 01 Strong Authentication

Use appropriate password and multi-factor authentication controls.

CONTROL 02 Appropriate Permissions

Give users the access required for their role rather than unnecessary privilege.

CONTROL 03 Account Lifecycle

Create, change and remove access as users join, move within or leave the organisation.

CONTROL 04 Visibility & Response

Where appropriate, review security information and respond to suspicious account activity.

HOUSE VENTER // IDENTITY PRINCIPLE

MFA Reduces Account Risk. It Does Not Make an Account Invulnerable.

Multi-factor authentication adds an important additional barrier when account credentials are stolen or guessed. It should be treated as a major risk-reduction control rather than a guarantee that account compromise can never occur.

FIELD NOTE

A successful sign-in does not automatically mean that the person using the account is the legitimate owner. Identity security depends on both authentication and the amount of access available after authentication succeeds.

08
DATA & SECURITY COMPROMISE

Protecting More Than the Confidentiality of Information

Business information can be affected in different ways during a cybersecurity incident. Information may be viewed by somebody who should not have access to it, altered without authorisation or made unavailable to the people who require it.

This means data security is not concerned only with keeping information secret. Confidentiality, integrity and availability each represent a different part of the security requirement.

KD-004 // DATA SECURITY MODEL C // I // A
OBJECTIVE 01 Confidentiality

Information should be accessible only to people and systems that are appropriately authorised to use it.

OBJECTIVE 02 Integrity

Information should remain accurate and protected against inappropriate or unauthorised alteration.

OBJECTIVE 03 Availability

Authorised users should be able to access required information when the business needs it.

DATA // CONCEPTUAL INCIDENT PATH INFORMATION AT RISK
STAGE 01 Security Event
→
STAGE 02 Information Affected
→
STAGE 03 Confidentiality, Integrity or Availability
→
STAGE 04 Business Process Affected
→
STAGE 05 Response & Recovery
SOUTH AFRICA // POPIA CONTEXT

Security Safeguards Are Broader Than Backup

Where personal information is involved, POPIA places security obligations on the responsible party. These include taking appropriate and reasonable technical and organisational measures, identifying reasonably foreseeable internal and external risks, maintaining safeguards and regularly verifying that those safeguards are effectively implemented.

Backup can form part of a wider information-security and resilience strategy, but using backup software or an IT provider does not by itself make an organisation POPIA-compliant.

FIELD NOTE

Security and backup solve different parts of the data problem. Security controls can reduce the risk of unauthorised access or compromise. Backup can help preserve recovery options when required data becomes unavailable or unusable.

09
THREAT CHAINS & LAYERED DEFENCE

Cybersecurity Incidents Rarely Exist in Isolation

The threats in this record have been examined separately so that each one can be understood clearly. In a real incident, however, several of them may form part of the same attack path.

A phishing message may target a user's credentials. Compromised credentials may provide access to an account. That access may then be used to reach information, impersonate the user or support further malicious activity.

Cybersecurity therefore works best as a collection of controls and processes rather than as dependence on one product or one defensive layer.

THREAT CHAIN // EXAMPLE A IDENTITY PATH
01 Phishing
→
02 Credential Compromise
→
03 Account Access
→
04 Email or Data Access
→
05 Potential Business Impact
THREAT CHAIN // EXAMPLE B ENDPOINT PATH
01 Vulnerable Software
→
02 Exploitation
→
03 Endpoint Compromise
→
04 Malicious Activity
→
05 Potential Business Impact
SECURITY MODEL // LAYERED DEFENCE MULTIPLE CONTROL POINTS
LAYER 01 People

Awareness, verification and appropriate business processes.

LAYER 02 Identity

Authentication, MFA, permissions and account management.

LAYER 03 Endpoint

Endpoint security and appropriate device-level controls.

LAYER 04 Software

Supported software, patching and vulnerability remediation.

LAYER 05 Monitoring & Response

Visibility, investigation and an appropriate response process.

LAYER 06 Recovery

Appropriate backup and recovery capability for information within scope.

FIELD PRINCIPLE

Layered defence does not mean stacking products indefinitely. It means using appropriate controls at different points in the attack path so that security does not depend entirely on one barrier succeeding every time.

FC
FIELD CONCLUSION

What Should a South African Business Take From This?

Cybersecurity threats do not affect every organisation in exactly the same way. Technology, users, data, access, suppliers and business processes all influence the exposure of a particular environment.

The objective is therefore not to predict every attack or to promise that compromise can never happen.

The objective is to understand the likely attack paths, reduce unnecessary exposure, create multiple defensive opportunities and maintain the ability to respond when something requires attention.

KD-004 // ANALYSIS COMPLETE FIELD ANSWER
THREAT ASSESSMENT // FINAL POSITION

Cybersecurity Is a Risk Management Process — Not a Promise of Immunity

A business does not become secure because it has antivirus, MFA, backup or any other individual control.

Security becomes stronger when appropriate controls work together across people, identity, endpoints, software, information, monitoring, response and recovery.

KD-004 // OPERATING PRINCIPLE

Understand the attack path. Reduce the exposure. Never assume the risk is zero.

HV
HOUSE VENTER // FIELD APPLICATION

Protecting as an Ongoing Responsibility

Within the House Venter managed services model, Protecting is one of four ongoing technology responsibilities.

The Protecting pillar focuses on endpoint security and the management surrounding that security capability.

It does not operate in isolation. Monitoring provides visibility, Backing Up helps preserve recovery options, and Supporting provides technical assistance when users and systems require attention.

HOUSE VENTER // FOUR PILLARS MANAGED SERVICE MODEL
01 // PROTECTING Endpoint Security

Security controls around managed endpoints.

02 // MONITORING RMM

Visibility and management of the technology environment within scope.

03 // BACKING UP Data Protection

Managed backup and recovery capability for agreed business data.

04 // SUPPORTING IT Support

Remote and on-site technical assistance when support is required.

HOUSE VENTER // COMPLETE ONE PARTNER
PROTECTING // MONITORING // BACKING UP // SUPPORTING

One Partner. Complete IT Care.

House Venter Complete brings the four managed service pillars together under one ongoing service relationship.

The objective is not to promise that incidents will never occur. It is to provide structured management around the technology responsibilities included in the service.

EXPLORE MANAGED SERVICES

KD-004 // INTELLIGENCE SUMMARY
01 PEOPLE CAN BE TARGETED

Phishing and social engineering use human interaction as part of the attack path.

02 TRUST CAN BE EXPLOITED

Business email compromise can abuse trusted identities and normal business processes.

03 ENDPOINTS REQUIRE LAYERS

Endpoint security is important, but it is not the only control involved in endpoint defence.

04 PATCHING REDUCES EXPOSURE

Appropriate updates can reduce known vulnerability exposure without eliminating every form of risk.

05 IDENTITY IS AN ATTACK SURFACE

Authentication, permissions and account management influence what happens when credentials are abused.

06 SECURITY MUST BE LAYERED

Multiple appropriate controls create more opportunities to prevent, detect, limit and recover from an incident.

CLOSING INTELLIGENCE

Cybersecurity is not one product, one setting or one defensive barrier. Understand the technology. Understand the attack paths. Apply appropriate controls. Manage the risk deliberately.

KNOWLEDGE DOCK // RECORD TRANSFER

Continue Intelligence Review

KD-004 // COMPLETE
RECORD STATUS KD-004 // INTELLIGENCE RECORD COMPLETE NEXT ASSIGNMENT // KD-005