Scenario Library

Cyber Risk Scenario Library

A scenario library gives teams a starting point for cyber risk discussion. The goal is not to predict every event. The goal is to describe plausible paths that help people understand consequence, ownership, and preparation.

Purpose: Adapt these starting scenarios to the organization’s own services, dependencies, safeguards, and consequences. They are prompts, not predictions.

Scenario starters

Compromised administratorA privileged account is misused to change configurations, disable safeguards, or access sensitive systems.
Cloud-service outageA major external platform becomes unavailable during a critical operating period.
Supplier data exposureA processor or service provider reports unauthorized access to information handled for the organization.
Malicious software updateA trusted update channel distributes altered software that affects internal or customer systems.
Ransomware disruptionMultiple business services become unavailable while data theft and recovery uncertainty are investigated.
Payment diversionCompromised email or supplier information leads to changed payment instructions and financial loss.
Lost operational technology visibilityMonitoring or control systems become unreliable, forcing reduced or manual operation.
Insider misuseAn employee or contractor uses legitimate access outside authorized purpose.
Recovery failureBackups exist but restoration is incomplete, too slow, or dependent on unavailable expertise.
Identity-provider concentrationA shared authentication service failure blocks access to several unrelated business systems.

Worked examples

{rows}
ExampleContext / RatingCondition / Safeguard

How to use this page

  1. Choose a scenario tied to a real business objective.
  2. Add the conditions that make the scenario plausible.
  3. Describe the consequence over time, not only at the first moment.
  4. Identify points where safeguards or decisions could change the outcome.
  5. Record assumptions and evidence gaps for follow-up.

Cautions

  • Do not use a library scenario unchanged as an assessment result.
  • Avoid combining several unrelated events into one unmanageable scenario.
  • Use credible ranges rather than dramatic unsupported claims.
Educational use: Tailor the language and decision authority to the organization. This page is not a certification, legal opinion, security assessment or substitute for professional advice.

Frequently asked questions

Can a small organization use this tool?

Yes. Reduce the number of fields or questions, but retain the scenario, business consequence, accountable owner, decision and review date.

Does this replace professional advice?

No. It is an educational structure. Legal, insurance, compliance, cybersecurity and other professional decisions may require qualified advice.

How often should it be updated?

Update it when the related service, supplier, data, threat conditions, controls, incident history or business priorities change materially.