Skip to content
Bowtie risk templates

Bowtie — Customer Data Exfiltration from Cloud Storage

Cloud data-protection bowtie over 9 million customer records: 14.5 exposure events a year reduced to 0.66 readable accesses, ranking short-lived federated credentials narrowly above the org-level public-access block and 98.7% of inherent risk removed.

Template previewBowtie risk
Customer data exfiltration from cloud object storageHAZARD9 million customer records held in object storageTHREATSPREVENTIVE BARRIERSRECOVERY BARRIERSCONSEQUENCESEmergency change appliedstraight in the consoleConsole write access needs abreak-glass ticketOrg-level policy blockingpublic access90%Policy-as-code gate onevery IaC change70% · detectionLegacy build agents still holdstatic keysSecret scanning on everypush and in the registry80% · detectionShort-lived federatedcredentials85%Access recertificationevery quarter by dataowner55% · controlAnomalous bulk-readalerting on the data plane60% · detectionField-level encryption ofidentifiers65%Accountability evidencefor the regulator30% · recoveryTransparent notificationwithin 72 hours40% · recoveryCredit monitoring offeredto affected customers35% · recoveryTokenised card data heldonly by the acquirer80%Storage bucketmisconfigured aspublicly readable5/yr → 0.15/yrLong-lived access keyleaked in a publicrepository8/yr → 0.24/yrInsider copies databefore leaving thecompany1.5/yr → 0.27/yrRegulatory fine underUK GDPRsev 4 · risk 0.6468Customer churn andbrand damagesev 3 · risk 0.7722Fraud losses onexposed paymentcredentialssev 3 · risk 0.396Unauthorisedparty readscustomer data…0.66/yrtop-event frequencyTop event0.66/yrinherent 14.5/yrResidual risk1.81inherent 145Risk reduction98.7%threat side 95.4%Barriers113 threats · 3 consequencesDominant threatInsider copies data before leaving the …40.9% of the top eventResidual risk 1.81 against an inherent 145 — the barriers remove 98.7% of it. 2 things are probably not what was meant — every path and every escalation factor was checked.Barrier criticality — residual risk if that one barrier were removed1. Short-lived federated credentials+3.74 ×3.12. Org-level policy blocking public access+3.71 ×33. Secret scanning on every push and in the registry+2.64 ×2.54. Tokenised card data held only by the acquirer+1.58 ×1.95. Field-level encryption of identifiers+1.2 ×1.76. Anomalous bulk-read alerting on the data plane+1.11 ×1.6FindingsConsequence "Fraud losses on exposed payment credentials" rests on ONE barrier. Defence in depth is the claim a bowtie is drawn to make, and a single barrier is a single point of failure: the day it fails is the day the consequ…Escalation factor "Legacy build agents still hold static keys" degrades barrier "Short-lived federated credentials" and nothing is holding it off. The 85% credited to that barrier — and every figure computed from it — assumes t…Each of the 3 consequences is credited the full top-event frequency of 0.66/yr — the model here is that one top event produces all of them, so the residual score of 1.81 adds 3 outcomes to one event. That is right when they hap…

Make it your own.

title "Customer data exfiltration from cloud object storage"
hazard "9 million customer records held in object storage"
top "Unauthorised party reads customer data at scale"
unit "/yr"

threat "Storage bucket misconfigured as publicly readable" likelihood: 5
  barrier "Org-level policy blocking public access" effectiveness: 0.9
  barrier "Policy-as-code gate on every IaC change" effectiveness: 0.7 type: detection
    escalation "Emergency change applied straight in the console"
      control "Console write access needs a break-glass ticket"

threat "Long-lived access key leaked in a public repository" likelihood: 8
  barrier "Secret scanning on every push and in the registry" effectiveness: 0.8 type: detection
  barrier "Short-lived federated credentials" effectiveness: 0.85
    escalation "Legacy build agents still hold static keys"

threat "Insider copies data before leaving the company" likelihood: 1.5
  barrier "Access recertification every quarter by data owner" effectiveness: 0.55 type: control
  barrier "Anomalous bulk-read alerting on the data plane" effectiveness: 0.6 type: detection

consequence "Regulatory fine under UK GDPR" severity: 4
  barrier "Field-level encryption of identifiers" effectiveness: 0.65
  barrier "Accountability evidence for the regulator" effectiveness: 0.3 type: recovery

consequence "Customer churn and brand damage" severity: 3
  barrier "Transparent notification within 72 hours" effectiveness: 0.4 type: recovery
  barrier "Credit monitoring offered to affected customers" effectiveness: 0.35 type: recovery

consequence "Fraud losses on exposed payment credentials" severity: 3
  barrier "Tokenised card data held only by the acquirer" effectiveness: 0.8