SolidBowtie

Ransomware attack

From phishing and unpatched services to encryption and double extortion — the full ransomware kill-chain with ISO 27001 Annex A controls.

HazardBusiness operations dependent on networked IT systems and data
Top eventRansomware detonates on the corporate network

5 threats 17 barriers 3 consequences safety-critical barriers marked

Use this template free. Copy “Ransomware attack” into your own workspace and adapt every barrier — no credit card.

Start free with this template →

Threats & preventive barriers

Each threat is a credible pathway to the top event; its barriers interrupt that pathway before control is lost.

Phishing email with malicious payload

  • Email filtering & attachment sandboxing (A.8.7)

    Active hardware · 85% effective · Owner: SOC Manager

    Zero-day attachment types evade the sandbox

  • Security awareness & phishing drills (A.6.3)

    Behavioural (human) · 65% effective · Owner: CISO

    📅 Phishing simulation · quarterly keep-alive task

  • EDR with automated isolation (A.8.7) ★ critical

    Active hardware · 90% effective · Owner: Security Engineering Lead

Exploitation of unpatched internet-facing service

  • Vulnerability & patch management (A.8.8)

    Socio-technical · 75% effective · Owner: IT Operations Manager

    Legacy systems without vendor support

    Change-freeze windows delay patching

    📅 Patch compliance review · monthly keep-alive task

  • External attack-surface scanning (A.8.8)

    Continuous · 80% effective · Owner: Security Engineering Lead

Compromised credentials (stuffing / brute force)

  • Phishing-resistant MFA everywhere (A.5.17) ★ critical

    Active hardware · 92% effective · Owner: IAM Lead

    Legacy protocols bypass MFA

    Push-bombing / MFA fatigue

  • Breached-password screening & lockout (A.5.17)

    Active hardware · 80% effective · Owner: IAM Lead

Third-party software supply-chain compromise

  • Supplier security assessment (A.5.19–5.22)

    Socio-technical · 65% effective · Owner: CISO

  • Application allow-listing on servers (A.8.19)

    Active hardware · 78% effective · Owner: Security Engineering Lead

Lateral movement after initial foothold

  • Network segmentation & east-west controls (A.8.22) ★ critical

    Passive (hardware) · 85% effective · Owner: Head of Infrastructure

  • Privileged access management (A.8.2)

    Socio-technical · 75% effective · Owner: IAM Lead

Consequences & recovery barriers

Once the top event happens, recovery barriers limit each consequence.

Production systems encrypted; operations halt

  • Immutable offline backups (A.8.13) ★ critical

    Passive (hardware) · 95% effective · Owner: Backup Administrator

    Backup jobs failing silently

    📅 Restore test from immutable copy · quarterly keep-alive task

  • Tested DR & business continuity plan (A.5.30)

    Socio-technical · 80% effective · Owner: IT Operations Manager

Data exfiltrated for double extortion

  • Egress filtering & DLP monitoring (A.8.12)

    Active hardware · 70% effective · Owner: SOC Manager

    Alert fatigue in the SOC

  • Encryption of data at rest (A.8.24)

    Passive (hardware) · 85% effective · Owner: Security Engineering Lead

Regulatory exposure & breach notification

  • Incident response plan & retainer (A.5.24–5.26) ★ critical

    Socio-technical · 85% effective · Owner: CISO

    📅 IR tabletop exercise · semiannual keep-alive task

  • 72-hour breach notification procedure (A.5.26)

    Socio-technical · 80% effective · Owner: Data Protection Officer

Copying this template gives you a fully editable bowtie: barrier owners arrive as role suggestions, escalation factors sit on their barriers, and keep-alive activities are scheduled from the moment you copy. New to the notation? Read what the bowtie method is or browse the practical guides.

Use this template free. Copy “Ransomware attack” into your own workspace and adapt every barrier — no credit card.

Start free with this template →