Strategic Business Leader · IT systems security and control
IT Systems Security Risks and Threats for ACCA SBL
Updated 11 October 2026 · Fact-checked
IT security threats are events that harm the confidentiality, integrity or availability of systems and data. They come from outside (hackers, malware, phishing, ransomware) or inside (insider fraud, human error). To answer SBL questions, identify the threat, link it to the scenario, explain the business impact, then recommend controls.
Understand IT Systems Security Risks and Threats
Start with what you are protecting. Information security rests on three aims, often called the CIA triad. Confidentiality means only authorised people see data. Integrity means data is accurate and not altered without permission. Availability means systems and data are usable when needed. A threat is anything that could damage one of these aims. A vulnerability is a weakness that a threat can use. Risk is the chance a threat uses a vulnerability, combined with the impact if it does.
Threats are usually split into external and internal. External threats come from outside the organisation. Hacking is unauthorised access to systems. Malware is malicious software, such as viruses, worms, trojans and spyware. Phishing is a deceptive message, often email, that tricks a person into giving away credentials or clicking a harmful link. Ransomware is malware that encrypts data or locks systems and demands payment to restore access. A denial-of-service attack floods a system so legitimate users cannot reach it.
Internal threats come from people inside the organisation. Insider fraud is deliberate misuse of access, such as an employee altering payment details or stealing customer data. Human error is accidental harm, such as sending data to the wrong person, losing an unencrypted laptop, using weak passwords or falling for phishing. Insiders already have access and system knowledge, so their actions can be hard to detect. Many external attacks succeed only because of an internal mistake, so the two categories overlap.
The business impact is the part that earns marks. Think of: financial loss (fraud, ransom, recovery cost, fines), operational disruption (systems down, lost sales), reputational damage and loss of customer trust, legal and regulatory consequences (breach of data protection law), loss of intellectual property and competitive advantage, and harm to staff morale. Link the impact to the business in the case, for example an online retailer loses sales when its site is down.
In SBL you are advising as a professional, not describing technology. Keep the language plain, tie each threat to the scenario and recommend practical responses, such as staff training, access controls, backups, patching and an incident response plan.
Key rules to remember
- CIA triad
- Confidentiality + Integrity + Availability
- Use it to classify the harm a threat causes. Ransomware mainly hits availability; a data leak hits confidentiality; fraud by altering records hits integrity.
- Risk
- Risk = Likelihood × Impact
- A common way to prioritise threats. It is a framework for judgement, not a precise calculation.
- Threat classification
- Threat source: external or internal; intent: deliberate or accidental
- Hacking and ransomware are external and deliberate. Insider fraud is internal and deliberate. Human error is internal and accidental.
- Answer structure
- Threat → Scenario link → Impact → Control
- Use this chain for each point so your answer is applied, not a list of definitions.
How to solve IT Systems Security Risks and Threats questions
Use this method for any SBL question on IT security threats, whether you are asked to identify risks, assess impact or advise the board.
- 1Read the requirement and note the verb (identify, explain, evaluate, recommend) and who you are writing for, such as the board or audit committee.
- 2Scan the scenario for clues: the type of data held, reliance on online systems, remote working, third-party suppliers, weak controls or past incidents.
- 3List the relevant threats and sort them into external and internal. Pick those the scenario supports, not every threat you know.
- 4For each threat, explain how it could happen in this business, using facts from the case.
- 5State the business impact: financial, operational, reputational, legal and strategic. Say which is most serious for this organisation.
- 6Prioritise using likelihood and impact so the reader sees your judgement.
- 7Recommend proportionate controls and responses, such as training, access controls, backups, patching and monitoring, and link them back to the threats.
- 8Close with a clear conclusion or recommendation in the format asked, such as a report or briefing note, to earn professional skills marks.
Quickest way: Threat-Impact-Control grid
When to use it: Use this when time is short and you need a structured answer in a few minutes.
- Draw two columns in your plan: External and Internal.
- Write one or two threats from the scenario in each column.
- Next to each, jot one impact specific to the business.
- Add one control per threat.
- Write the answer in this order: one line on the risk picture, then each threat with impact and control, then a short conclusion.
Common mistakes in IT Systems Security Risks and Threats
Listing definitions of malware, phishing and ransomware with no link to the scenario.
Students recall textbook definitions and treat the question as a knowledge test.
Fix: Use each definition in one sentence only, then spend the rest applying it to the business in the case.
Treating IT security as only an external hacking problem.
News stories focus on cyber attacks, so internal threats are forgotten.
Fix: Always check for insider fraud and human error. Look for weak segregation of duties, poor training or unrestricted access in the scenario.
Describing impact only as financial loss.
Students think in terms of numbers and forget wider effects.
Fix: Cover operational disruption, reputation, legal and regulatory consequences and strategic harm, and say which matters most.
Recommending generic controls such as 'install antivirus' for every threat.
Students rush to the solution without matching it to the threat.
Fix: Match each control to a threat, for example offline backups for ransomware and role-based access for insider fraud, and keep the control proportionate to the risk.
Writing too technical an answer for a board audience.
Students try to show IT knowledge instead of business advice.
Fix: Use plain business language. Explain what could go wrong, what it would cost and what management should do.
Confusing threats with controls or with vulnerabilities.
The terms are used loosely in everyday speech.
Fix: A threat is the danger, a vulnerability is the weakness, a control is the protection. Label them clearly in your answer.
Worked examples
Example 1
A mid-sized online retailer holds customer payment and address data. Staff work from home on personal laptops. The board asks you to explain the main external and internal IT threats it faces and the likely business impact. (10 marks)
Show the solution
- External threats: phishing emails aimed at home-working staff could capture login details. Hackers could then reach customer data. Ransomware could lock the website and order systems.
- Internal threats: staff using personal laptops may lose devices or use weak passwords, which is human error. A dishonest employee with wide access could copy customer data, which is insider fraud.
- Impact: if the site is down, sales stop and the retailer loses revenue immediately. A data breach could lead to regulatory fines and legal claims. Customers may leave, damaging reputation, which matters most for an online business built on trust.
- Prioritise: ransomware and phishing are likely and high impact because the business depends on its website and customer data.
- Controls: train staff to spot phishing, require multi-factor authentication, restrict access by role, encrypt devices, keep tested offline backups and set a clear incident response plan.
Answer: The retailer faces external threats (phishing, hacking, ransomware) and internal threats (human error on personal laptops, insider fraud). The impact includes lost sales, fines, legal claims and reputational damage, with downtime and a data breach the most serious. The board should invest in training, multi-factor authentication, access restrictions, encryption and offline backups.
Example 2
A regional manufacturer suffers a ransomware attack that encrypts its production scheduling system. Management is considering paying the ransom. Advise the board on the business impact and how it should respond. (10 marks)
Show the solution
- Identify the threat: ransomware is malware that locks data and demands payment. It mainly attacks availability.
- Impact: production scheduling stops, so orders are delayed, customers may be lost and penalty clauses may apply. Staff may be idle, adding cost.
- Wider impact: there may be reporting duties under data protection law if personal data was affected, and reputation with customers and suppliers could suffer.
- Paying the ransom: there is no guarantee that data will be restored, it may encourage further attacks and it could raise legal or ethical issues. It should not be the default choice.
- Response: isolate infected systems, activate the incident response and business continuity plans, restore from clean backups if they exist, and involve legal advisers and the relevant authorities.
- Prevention: regular patching, staff training on phishing, network segregation and tested offline backups.
Answer: Ransomware has stopped production, causing delayed orders, extra costs and possible customer loss, plus legal and reputational risk. The board should avoid paying by default because payment gives no guarantee and invites repeat attacks. It should contain the attack, restore from clean backups, take legal advice and then strengthen training, patching and backup controls.
Exam tips
- Always tie the threat to a fact in the scenario. Generic lists earn few marks in SBL.
- Cover both external and internal threats unless the requirement limits you, and say which is more likely for this business.
- Discuss impact in several categories and rank them. Showing judgement scores higher than listing.
- Write in the format asked, such as a briefing note to the board, with plain business language to earn professional skills marks.
- Link controls to threats and keep them proportionate. Mention cost and practicality where the scenario suggests limited resources.
Practice questions from IT systems security and control
- Lindqvist Media gives staff access to systems based on job role, so a new marketing analyst automatically receives the same permissions as o…
- Orion Logistics suffers a ransomware attack at 09:00 Monday. By Tuesday 15:00 it confirms that encrypted servers include unencrypted employe…
- Brightwater Hospital's finance clerk was moved to the payroll team and still has access to the supplier master file, which allows creation o…
- Halden Logistics has suffered two phishing incidents this year. The board has so far treated cyber security as a technical matter for the IT…
- Lumen Telecom wants to launch an app using customer location data. Before design begins, the CIO insists on assessing privacy risks and buil…
IT Systems Security Risks and Threats: frequently asked questions
What is the difference between internal and external IT threats?
External threats come from outside the organisation, such as hackers, malware, phishing and ransomware. Internal threats come from people inside, such as employees committing fraud or making mistakes. Internal threats can be deliberate or accidental, and they often involve people who already have legitimate access.
What is the difference between phishing and ransomware?
Phishing is a deceptive message that tricks someone into revealing information or clicking a harmful link. Ransomware is malware that locks or encrypts data and demands payment. Phishing is often the way ransomware gets in, so the two frequently appear together in a case.
How do I answer an SBL question on cyber threats?
Identify the threats the scenario supports, explain how each could affect this business and state the impact. Then recommend proportionate controls and finish with a clear conclusion. Use the format requested and keep the language suitable for the reader.
Is human error really a security threat?
Yes. Accidental actions such as weak passwords, lost devices, misdirected emails and clicking phishing links cause many incidents. Controls include training, clear policies, access limits and technical safeguards that reduce the damage one mistake can do.