Ransomware attack
From phishing and unpatched services to encryption and double extortion — the full ransomware kill-chain with ISO 27001 Annex A controls.
5 threats 17 barriers 3 consequences safety-critical barriers marked
Use this template free. Copy “Ransomware attack” into your own workspace and adapt every barrier — no credit card.
Start free with this template →Threats & preventive barriers
Each threat is a credible pathway to the top event; its barriers interrupt that pathway before control is lost.
Phishing email with malicious payload
-
Email filtering & attachment sandboxing (A.8.7)
Active hardware · 85% effective · Owner: SOC Manager
Zero-day attachment types evade the sandbox
-
Security awareness & phishing drills (A.6.3)
Behavioural (human) · 65% effective · Owner: CISO
📅 Phishing simulation · quarterly keep-alive task
-
EDR with automated isolation (A.8.7) ★ critical
Active hardware · 90% effective · Owner: Security Engineering Lead
Exploitation of unpatched internet-facing service
-
Vulnerability & patch management (A.8.8)
Socio-technical · 75% effective · Owner: IT Operations Manager
Legacy systems without vendor support
Change-freeze windows delay patching
📅 Patch compliance review · monthly keep-alive task
-
External attack-surface scanning (A.8.8)
Continuous · 80% effective · Owner: Security Engineering Lead
Compromised credentials (stuffing / brute force)
-
Phishing-resistant MFA everywhere (A.5.17) ★ critical
Active hardware · 92% effective · Owner: IAM Lead
Legacy protocols bypass MFA
Push-bombing / MFA fatigue
-
Breached-password screening & lockout (A.5.17)
Active hardware · 80% effective · Owner: IAM Lead
Third-party software supply-chain compromise
-
Supplier security assessment (A.5.19–5.22)
Socio-technical · 65% effective · Owner: CISO
-
Application allow-listing on servers (A.8.19)
Active hardware · 78% effective · Owner: Security Engineering Lead
Lateral movement after initial foothold
-
Network segmentation & east-west controls (A.8.22) ★ critical
Passive (hardware) · 85% effective · Owner: Head of Infrastructure
-
Privileged access management (A.8.2)
Socio-technical · 75% effective · Owner: IAM Lead
Consequences & recovery barriers
Once the top event happens, recovery barriers limit each consequence.
Production systems encrypted; operations halt
-
Immutable offline backups (A.8.13) ★ critical
Passive (hardware) · 95% effective · Owner: Backup Administrator
Backup jobs failing silently
📅 Restore test from immutable copy · quarterly keep-alive task
-
Tested DR & business continuity plan (A.5.30)
Socio-technical · 80% effective · Owner: IT Operations Manager
Data exfiltrated for double extortion
-
Egress filtering & DLP monitoring (A.8.12)
Active hardware · 70% effective · Owner: SOC Manager
Alert fatigue in the SOC
-
Encryption of data at rest (A.8.24)
Passive (hardware) · 85% effective · Owner: Security Engineering Lead
Regulatory exposure & breach notification
-
Incident response plan & retainer (A.5.24–5.26) ★ critical
Socio-technical · 85% effective · Owner: CISO
📅 IR tabletop exercise · semiannual keep-alive task
-
72-hour breach notification procedure (A.5.26)
Socio-technical · 80% effective · Owner: Data Protection Officer
Copying this template gives you a fully editable bowtie: barrier owners arrive as role suggestions, escalation factors sit on their barriers, and keep-alive activities are scheduled from the moment you copy. New to the notation? Read what the bowtie method is or browse the practical guides.
Use this template free. Copy “Ransomware attack” into your own workspace and adapt every barrier — no credit card.
Start free with this template →