R001 Data breaches L 2026-06-22 R002 Compliance issues - Operations M 2026-08-01 R002a Compliance issues -Business M 2025-12-23 R003 Reputation damage - Operations L 2025-12-23 R003a Reputation damage - Business L 2025-12-23 R004 Financial losses L 2025-12-23 R005 Outdated policies L 2025-12-23 R005a Outdated policies L 2025-12-23 R006 Non-compliance L 2025-12-23 R006a Non-compliance L 2025-12-23 R007 Increased risk of data breaches L 2025-12-23 R007a Increased risk of data breaches L 2025-12-23 R008 Decreased employee awareness L 2025-12-23 R009 Decreased employee engagement L 2025-12-23 R010 Processes incorrect or not executed L 2025-12-23 R011 Non authorized people or processes gain access via devices used for work. L 2025-12-23 R012 Devices for work used in uncontrolled/unknown work environments - mishandling L 2025-12-23 R012a Devices for work used in uncontrolled/unknown work environments - configuration L 2025-12-23 R013 Employees with a history that conflicts with information security profile needed L 2025-12-23 R014 Employees not sufficiently aware of their duties - Business & General L 2026-06-24 R014a Employees not sufficiently aware of their duties - Operations L 2025-12-23 R014b Employees not sufficiently aware of their duties - Management M 2026-08-01 R015 Employees not willing to comply L 2025-12-23 R016 Employees leaving the organization have access to the organization's assets or information. L 2025-12-23 R017 Incorrect handling of security incidents L 2025-12-23 R018 Supplier works in a not sufficient compliant way L 2025-12-23 R019 Supplier delivers results that are not sufficiently compliant or does not deliver in accordance to the contract L 2025-12-23 R020 Insufficient priority, attention, or means to ensure the required level of the ISMS L 2026-08-01 R021 Unauthorized access - Operations L 2025-12-23 R021 Unauthorized access - Business L 2025-12-23 R022 Insider threat - Operations L 2025-12-23 R022 Insider threat - Business L 2025-12-23 R023 Lack of accountability - Operations L 2025-12-23 R023 Lack of accountability - Business L 2025-12-23 R024 Technical vulnerabilities L 2025-12-23 R025 Key management M 2025-12-23 R026 Implementation vulnerabilities L 2025-12-23 R027 Algorithmic vulnerabilities L 2025-12-23 R028 Legal and regulatory compliance L 2025-12-23 R029 Lack of security testing L 2025-12-23 R030 Vulnerabilities in new systems L 2025-12-23 R031 Unauthorized changes - Operations L 2025-12-23 R031a Unauthorized changes - Business L 2025-12-23 R032 Lack of visibility L 2025-12-23 R033 Lack of accountability for assets L 2025-12-23 R034 Inconsistent classification L 2026-08-01 R035 Operational disruption L 2025-12-23 R036 Loss of information L 2025-12-23 R037 Delayed incident response L 2025-12-23 R038 Unsecure network L 2025-12-23 R039 Unsafe transport of information and unsafe access to information in application services via network L 2025-12-23 R040 Insecure development of (unsafe) software L 2025-12-23 R041 Insufficient continuity Security Officer L 2026-08-01 R042 Insufficient measures against malicious software L 2025-12-23 R043 Adding incorrect user during Workspace creation L 2025-12-23 R044 Lack of automation leading to human errors L 2025-12-23 R045 Authorized users are unable to execute the necessary action L 2025-12-23 R046 Downtime Entra ID L 2025-12-23 R047 Data center destruction L 2026-02-23 R048 Redundancy H 2026-08-18 R049 Platform or VM unavailability L 2025-12-23 R050 Application changes L 2025-12-23 R051 Incorrect or incomplete reporting L 2025-12-23 R052 Secret Management L 2025-12-23