Bowtie analysis template — Information Security

Cyber security bowtie example: unauthorised access to a customer database

A complete, worked bowtie analysis example: 5 threats, 4 consequences, and 24 controls — 7 of them critical — around the top event, each carrying effectiveness, degradation factors, and a performance standard.

Open it read-only in the real editor → No sign-in required.

Cyber-security bowtie diagram: threats and preventive controls to the left, unauthorised access to a customer database in the centre, consequences and recovery controls to the right.

Bowtie Risk Engine writes barriers as controls and the top event as the risk — same method, stricter bookkeeping.

The scenario

Unauthorised Access to Customer Database

A data-breach bowtie for a SaaS or data-platform business: phishing, exposed secrets, web vulnerabilities, insider misuse, and supply chain on the left; exfiltration, regulators, customer harm, and reputation on the right. Security teams use it to show executives the whole story on one page.

Area. Production customer data store (PII, payment metadata, account credentials)

Hazard. Confidentiality breach with regulatory, financial, and reputational consequences

Activity. Continuous service operation across web, mobile, and API surfaces

Top event. Unauthorised Access to Customer Database — the moment control of the hazard is lost, at the knot of the bowtie.

Left side of the bowtie

Threats and preventive controls

Control set reads naturally against ISO 27001 Annex A and NIST CSF families, written barrier-style.

Preventive controls (barriers)5 threats · 15 controls
Threat Control Criticality Effectiveness
Credential phishing of employeesExternal attacker obtains valid employee credentials via phishing, smishing, or business-email compromise. Phishing-resistant MFA (FIDO2 / WebAuthn) Critical High
Inbound email filtering and DMARC enforcement Standard Medium
Security awareness and phishing simulation Standard Medium
Exposed credentials or API keysLong-lived credentials leak via source repos, build logs, third-party SaaS breach, or developer machines. Centralised secret manager Critical High
Secret scanning in repos and CI Standard Medium
Automatic credential rotation Standard Medium
Exploited web application vulnerabilitySQL injection, IDOR, SSRF, deserialisation, or supply-chain vulnerability in application code or dependencies. Secure SDLC (SAST, code review, threat modelling) Critical Medium
DAST and dependency scanning Standard Medium
WAF with anomaly-based rules Standard Medium
Bug bounty programme Standard High
Insider misuseAuthorised user accesses customer data outside their need-to-know — curious employee, malicious insider, or compromised account. Role-based access control with least privilege Critical Medium
Data-access audit logging Critical High
Privileged Access Management (PAM) for production Standard Medium
Compromised third-party / supply chainMalicious update to a third-party dependency, SaaS provider breach with downstream blast radius, or compromised build pipeline. Third-party risk management Standard Medium
Build integrity (SLSA / signed artefacts) Standard Medium
Right side of the bowtie

Consequences and recovery controls

If the top event happens anyway, these are the controls that limit how bad it gets.

Recovery controls (barriers)4 consequences · 9 controls
Consequence Control Criticality Effectiveness
Data exfiltrationCustomer data leaves the environment to attacker-controlled infrastructure. Egress controls and DLP Critical Medium
Encryption at rest and in transit Standard High
Tokenisation of high-sensitivity fields Standard High
Regulatory action and fineGDPR / CCPA / sector-specific regulator imposes fines, mandates remediation, and publishes breach notices. Incident response plan with regulator playbook Critical High
Data minimisation and retention Standard High
Customer harm and notificationCustomers exposed to identity theft, account takeover, or fraud. Account fraud monitoring Standard High
Customer notification and credit-monitoring offer Standard High
Reputational damageLost customer trust, churn, and market-cap impact independent of regulatory or direct customer harm. Crisis communications plan Standard High
Public trust page and continuous transparency Standard Medium
Degradation factors (escalation factors)What defeats a control — and what defends it
Control Degradation factor Degradation control
Phishing-resistant MFA (FIDO2 / WebAuthn) Account recovery / MFA-reset abuse In-person verification with manager and IT for any recovery
Automatic credential rotation Legacy services pinned to long-lived credentials Deprecation list and migration to short-lived SDK credentials
Privileged Access Management (PAM) for production Break-glass access bypassing PAM Automatic security review triggered on any break-glass use
Inside one control

Phishing-resistant MFA (FIDO2 / WebAuthn)

Every control in this template carries this level of detail — this is one of the critical ones.

What it does. Hardware security keys or platform authenticators required for all employees with production access. SMS and TOTP not accepted.

Performance standard — objective. Stop credential phishing from yielding a usable production login by requiring phishing-resistant authentication factors.

A verification criterion. All employees with production access authenticate with a phishing-resistant factor (FIDO2 / WebAuthn); SMS and TOTP are not accepted.

How it erodes. Legacy or 'break-glass' logins that still accept SMS/TOTP, contractor and service accounts exempted from the policy, or new production systems onboarded outside the identity provider quietly reintroduce phishable factors.

Questions about this template

Is this bowtie example free to use?

Yes. Open it read-only in the real editor with no sign-in and read every control in full. To adapt it to your own operation, start the free 3-month trial — full editor and register, work email, no credit card.

What does the template include?

5 threats, 4 consequences, and 24 controls (barriers) around the top event, plus 3 degradation factors with their own controls, and a performance standard on every control. The control register and audit-ready PDF are generated from the same model.

What standard or framework does it align with?

The controls read naturally against ISO 27001 Annex A and NIST CSF categories, but they are written barrier-style — what the control stops, how it degrades, and how you verify it — rather than as a compliance checklist.

Can I export it?

Yes — PNG and SVG for slides and reports, JSON for version control, and a multi-page PDF containing the control registers, degradation factors, and performance standards. Trial exports are brand-marked.

Open this bowtie in the editor.

Read every control, criterion, and degradation factor in the live model — then adapt it to your own operation on the free 3-month trial.

Licensing & pricing · What the product does