3. Determine Who and What Is at Risk
For each hazard, map out the people, systems, processes, and assets that could be affected. Don’t stop at direct stakeholders—think about downstream effects such as customers, vendors, sensitive data, or operational continuity.
For example, a ransomware attack might begin by locking employees out of critical systems, which halts day-to-day operations. That downtime delays vendor payments, disrupts customer orders, and triggers regulatory reporting requirements if sensitive data is exposed. What appears like a single IT issue quickly cascades into financial losses, reputational damage, and compliance penalties.
The more specific you are in identifying initial risks and potential ripple effects at this stage, the easier it becomes to design meaningful controls later.