Bowtie — Customer Data Exfiltration from Cloud Storage
Cloud data-protection bowtie over 9 million customer records: 14.5 exposure events a year reduced to 0.66 readable accesses, ranking short-lived federated credentials narrowly above the org-level public-access block and 98.7% of inherent risk removed.
Make it your own.
title "Customer data exfiltration from cloud object storage"
hazard "9 million customer records held in object storage"
top "Unauthorised party reads customer data at scale"
unit "/yr"
threat "Storage bucket misconfigured as publicly readable" likelihood: 5
barrier "Org-level policy blocking public access" effectiveness: 0.9
barrier "Policy-as-code gate on every IaC change" effectiveness: 0.7 type: detection
escalation "Emergency change applied straight in the console"
control "Console write access needs a break-glass ticket"
threat "Long-lived access key leaked in a public repository" likelihood: 8
barrier "Secret scanning on every push and in the registry" effectiveness: 0.8 type: detection
barrier "Short-lived federated credentials" effectiveness: 0.85
escalation "Legacy build agents still hold static keys"
threat "Insider copies data before leaving the company" likelihood: 1.5
barrier "Access recertification every quarter by data owner" effectiveness: 0.55 type: control
barrier "Anomalous bulk-read alerting on the data plane" effectiveness: 0.6 type: detection
consequence "Regulatory fine under UK GDPR" severity: 4
barrier "Field-level encryption of identifiers" effectiveness: 0.65
barrier "Accountability evidence for the regulator" effectiveness: 0.3 type: recovery
consequence "Customer churn and brand damage" severity: 3
barrier "Transparent notification within 72 hours" effectiveness: 0.4 type: recovery
barrier "Credit monitoring offered to affected customers" effectiveness: 0.35 type: recovery
consequence "Fraud losses on exposed payment credentials" severity: 3
barrier "Tokenised card data held only by the acquirer" effectiveness: 0.8