Chapter 4. Insecurity Impacts

Executive summary

No organization is immune from the complex range of threats to its information assets and technology infrastructure. The financial, reputational, operational and punitive impacts of successful cyber attacks or information security failures are significant.

Types of impact

‘Impact’ is the consequence of the realisation of a threat. It is usually quantified financially, in terms of the likely loss to the organization. Estimation of likely loss is inexact, but should take into account both direct and indirect costs, including the likely business cost of reputational damage, loss of business, remedial advertising, investigating, closing the stable door, etc.

  • Every organization will suffer multiple instances ...

Get The Case for ISO 27001 now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.