Skip to content
Bowtie risk templates

Bowtie — Ransomware Encryption of Production Systems

Cyber bowtie treating ransomware as a barrier problem rather than a tooling problem: 48 attempts a year reduced to 1.51 executions, ranking phishing-resistant MFA three times above the mail gateway and flagging an appliance missing from the asset inventory.

Template previewBowtie risk
Ransomware encryption of production systemsHAZARDBusiness-critical data on internet-connected serve…THREATSPREVENTIVE BARRIERSRECOVERY BARRIERSCONSEQUENCESMFA fatigue push bombingaccepted by the userNumber matching enforced inthe authenticatorPhishing-resistant MFA onevery admin account90%Mail gateway detonation oflinks and attachments75% · detectionQuarterly simulatedphishing with coaching35%Appliance missing from the assetinventory14-day patch SLA oninternet-facing assets70%External attack surfacescanning every week60% · detectionJust-in-time access withsession recording80% · controlNetwork segmentation fromthe MSP jump host65%Backup catalogue lives in theencrypted domainBackup identity held in aseparate tenantImmutable offline backupsproven by restore drill85% · recoveryRecovery runbook exercisedannually60% · recoveryData loss preventionegress monitoring45% · detectionEncryption at rest withkeys held in an HSM50%72-hour breachnotification playbook50% · recoveryCyber insurance with an IRretainer40% · recoveryPhishing emailharvests a privilegedcredential40/yr → 0.65/yrUnpatchedinternet-facing VPNappliance exploited6/yr → 0.72/yrCompromised managedservice providerconnection2/yr → 0.14/yrMulti-week outage oforder processingsev 5 · risk 0.453Exfiltrated customerdata published forextortionsev 4 · risk 1.66Regulatory penaltyand contractualbreachsev 3 · risk 1.36Ransomwareexecutes andencrypts…1.51/yrtop-event frequencyTop event1.51/yrinherent 48/yrResidual risk3.47inherent 576Risk reduction99.4%threat side 96.9%Barriers133 threats · 3 consequencesDominant threatUnpatched internet-facing VPN appliance…47.7% of the top eventResidual risk 3.47 against an inherent 576 — the barriers remove 99.4% of it. 1 thing is probably not what was meant — every path and every escalation factor was checked.Barrier criticality — residual risk if that one barrier were removed1. Phishing-resistant MFA on every admin account+13.46 ×4.92. Mail gateway detonation of links and attachments+4.48 ×2.33. 14-day patch SLA on internet-facing assets+3.86 ×2.14. Immutable offline backups proven by restore drill+2.57 ×1.75. External attack surface scanning every week+2.48 ×1.76. Encryption at rest with keys held in an HSM+1.66 ×1.5FindingsEscalation factor "Appliance missing from the asset inventory" degrades barrier "14-day patch SLA on internet-facing assets" and nothing is holding it off. The 70% credited to that barrier — and every figure computed from it — …Each of the 3 consequences is credited the full top-event frequency of 1.51/yr — the model here is that one top event produces all of them, so the residual score of 3.47 adds 3 outcomes to one event. That is right when they hap…

Make it your own.

title "Ransomware encryption of production systems"
hazard "Business-critical data on internet-connected servers"
top "Ransomware executes and encrypts production data"
unit "/yr"

threat "Phishing email harvests a privileged credential" likelihood: 40 {
  barrier "Phishing-resistant MFA on every admin account" effectiveness: 0.9 {
    escalation "MFA fatigue push bombing accepted by the user" {
      control "Number matching enforced in the authenticator"
    }
  }
  barrier "Mail gateway detonation of links and attachments" effectiveness: 0.75 type: detection
  barrier "Quarterly simulated phishing with coaching" effectiveness: 0.35
}

threat "Unpatched internet-facing VPN appliance exploited" likelihood: 6 {
  barrier "14-day patch SLA on internet-facing assets" effectiveness: 0.7 {
    escalation "Appliance missing from the asset inventory"
  }
  barrier "External attack surface scanning every week" effectiveness: 0.6 type: detection
}

threat "Compromised managed service provider connection" likelihood: 2 {
  barrier "Just-in-time access with session recording" effectiveness: 0.8 type: control
  barrier "Network segmentation from the MSP jump host" effectiveness: 0.65
}

consequence "Multi-week outage of order processing" severity: 5 {
  barrier "Immutable offline backups proven by restore drill" effectiveness: 0.85 type: recovery {
    escalation "Backup catalogue lives in the encrypted domain" {
      control "Backup identity held in a separate tenant"
    }
  }
  barrier "Recovery runbook exercised annually" effectiveness: 0.6 type: recovery
}

consequence "Exfiltrated customer data published for extortion" severity: 4 {
  barrier "Data loss prevention egress monitoring" effectiveness: 0.45 type: detection
  barrier "Encryption at rest with keys held in an HSM" effectiveness: 0.5
}

consequence "Regulatory penalty and contractual breach" severity: 3 {
  barrier "72-hour breach notification playbook" effectiveness: 0.5 type: recovery
  barrier "Cyber insurance with an IR retainer" effectiveness: 0.4 type: recovery
}