The diagram depicts a cyber risk taxonomy structured as a hierarchy. At the top is Cyber Risks, branching into Cyber Threats, Cyber Attacks, and Vulnerabilities. Cyber Threats include Malware with viruses, worms, trojans, ransomware, spyware, and adware, Social Engineering with phishing, spear phishing, whaling, pretexting, and baiting, Insider Threats with malicious insiders and negligent insiders, and Advanced Persistent Threats with denial-of-service, distributed denial-of-service, man-in-the-middle, eavesdropping, and D N S spoofing. Cyber Attacks include Network Attacks, Application Level Attacks with S Q L injection, cross-site scripting, cross-site request forgery, remote code execution, and buffer overflow, Cryptographic Attacks with brute force, dictionary, birthday, side-channel, and replay attacks, and Supply Chain Attacks. Vulnerabilities include Software Vulnerabilities with zero-day vulnerabilities, unpatched software, insecure deserialisation, improper input validation, and authentication bypass, Network Vulnerabilities with open ports, weak encryption protocols, misconfigured firewalls, and default credentials, Hardware Vulnerabilities with firmware exploits and side-channel attacks, and Human Factors with social engineering susceptibility, poor password practices, and insufficient training.Cyber risk taxonomy diagram
Sharing content requires targeting cookies to be enabled. Please update your cookie preferences to use this feature.