Web Application Security Fundamentals #13: Business Impact of Vulnerabilities & Risk Quantification
Memahami business impact dari vulnerabilities, risk quantification, financial calculations, dan effective communication ke leadership.
Security bukanlah technical problem saja, tetapi business problem. Modul ini membantu Anda quantify risk & communicate ke leadership dalam bahasa mereka: uang.
Risk Calculation Framework
Risk = (Likelihood × Impact) × Assets at Risk
Example:
- Likelihood: SQL Injection vulnerability accessible = High (8/10)
- Impact: 10,000 customer records exposed = High (8/10)
- Assets: Customer data value = High (millions Rupiah)
- Risk Score = (8 × 8) × High = Quantifiable business risk
Types of Impact
Financial Impact
Direct Loss
- Data breach: Notification costs, credit monitoring, regulatory fines
- Example: 10,000 records × Rp500K per record notification = Rp5 Miliar
Incident Response Costs
- Forensics, legal, PR agency, remediation
- Typical: Rp500M - Rp5 Miliar per incident
Compliance Fines
- GDPR: Up to 4% of annual revenue
- OJK regulations: Rp50M - Rp500M per violation
- Other: Data protection laws vary by jurisdiction
Business Interruption
- Downtime costs (transactions lost, customers lost)
- Example: Rp1B revenue/day × 3 days downtime = Rp3B lost
Reputational Impact
Customer Churn
- 30-60% customers leave after breach
- Customer acquisition cost (CAC) = Rp2M per customer
- If 100K customers churn: Rp200B loss
Stock Price Impact
- Public companies: -10% to -30% stock decline post-breach
- Market cap impact: potentially Rp Trillions
Brand Damage
- Decades to rebuild trust
- Premium pricing lost
- Competitive advantage eroded
Regulatory Impact
Incident Disclosure Requirements
- GDPR: 72 hours notification required
- Non-compliance: additional fines (€20K per day)
- OJK: Immediate disclosure to regulator
Compliance Violations
- PCI-DSS: Lose payment processor certification
- Financial institutions: Regulatory restrictions
- Government contracts: Debarment possible
Risk Scenarios
Scenario 1: SQL Injection in Payment System
Vulnerability:
- SQL Injection in
/api/payment-history?year=2024 - Can extract credit card details
Likelihood: 9/10 (easy to exploit) Impact: 8/10 (financial data + customer PII) Assets: 50,000 customer records with PII
Calculation:
Direct Financial: 50K records × Rp500K = Rp25 Miliar
Incident Response: Rp2 Miliar
Regulatory Fine (GDPR/PDP): Rp5 Miliar
Customer Churn: 30K customers × Rp2M CAC = Rp60 Miliar
Reputational: Stock decline 15% = Rp300 Miliar (if public company)
TOTAL RISK: Rp 392 Miliar (if exploited)
Risk Prioritization: Critical - Fix immediately
Scenario 2: Missing Security Headers
Vulnerability:
- No CSP header → XSS exploitation possible
- No HSTS → Session hijacking possible
Likelihood: 5/10 (requires some skill) Impact: 6/10 (session hijacking, account compromise) Assets: 10,000 active user sessions
Calculation:
Account Takeover: 500 accounts compromised
Fraud Loss: Rp500M per account × 500 = Rp250 Miliar
Remediation: Rp500M
Customer Support: Rp100M
TOTAL RISK: Rp350.6 Miliar (if exploited)
Risk Prioritization: High - Fix within 1 sprint
Scenario 3: Weak Password Policy
Vulnerability:
- Minimum 6 characters, no complexity requirements
- Brute force possible
Likelihood: 7/10 (automated tools available) Impact: 7/10 (mass account compromise possible) Assets: 100,000 user accounts
Calculation:
Bruteforce Attack: 30% accounts compromised = 30K
Account Takeover: Fraud/data access
Reputational: Customer confidence loss
Incident Response: Rp1.5 Miliar
TOTAL RISK: Rp2+ Miliar (ongoing, not one-time)
Risk Prioritization: High - Address in security roadmap
Communicating Risk to Leadership
Language Matters
❌ Technical (doesn't resonate with C-suite) "We have a SQL Injection vulnerability in the payment API"
✅ Business (speaks their language) "Our payment system is vulnerable to data theft affecting 50,000 customers and potentially causing Rp25B+ in direct losses + Rp5B regulatory fines"
Effective Risk Communication
Executive Summary Template:
VULNERABILITY SUMMARY
- Affected Systems: Payment processing API
- Estimated Impact: Rp 30+ Miliar
- Likelihood: High (9/10)
- Current Status: Open (not patched)
RECOMMENDED ACTION
- Fix severity: Critical
- Estimated remediation time: 1-2 weeks
- Cost of fix: Rp 100M in development
- Cost of inaction: Rp 30B+ if exploited
DECISION REQUIRED
- Approve budget for immediate fix? YES / NO
ROI of Security Investments
Example: Bug Bounty Program
Cost: Rp 500M/year
Benefits:
- Vulnerabilities found: 50/year (before production)
- Average impact prevented: Rp 2B per vulnerability
- Total risk prevented: 50 × Rp 2B = Rp 100B
- ROI: Rp 100B / Rp 500M = 200x return on investment
Example: Security Audit
Cost: Rp 200M for audit + Rp 300M remediation
Vulnerabilities found: Critical (SQL Injection, XSS, CSRF)
Risk prevented: Rp 50B (if exploited)
ROI: Rp 50B / Rp 500M = 100x
Quantification Framework (CVSS to Business Risk)
| CVSS Score | Severity | Business Impact | Priority |
|---|---|---|---|
| 9.0-10.0 | Critical | Rp 10B+ loss | Fix immediately (hours/days) |
| 7.0-8.9 | High | Rp 1B-10B loss | Fix in 1-2 weeks |
| 5.0-6.9 | Medium | Rp 100M-1B loss | Fix in 1-2 months |
| 3.0-4.9 | Low | Rp 10M-100M loss | Fix in next quarter |
Kesimpulan
Security ROI adalah positive. Preventing breaches adalah jauh lebih murah daripada responding to breaches.
Modul terakhir (#14) membahas mindset security & checklist final.
Next: #14 - Security Mindset & Practical Checklist
Post Terkait
Cloud, Container & IaC Security #03: Tutorial kube-hunter + Checkov untuk Kubernetes dan IaC Security
Episode 03/5: tutorial lengkap kube-hunter + Checkov dengan practical workflow, command dan security assessment.
Cloud, Container & IaC Security #02: Tutorial Dive + kube-bench untuk Container dan Kubernetes Hardening
Episode 02/5: tutorial lengkap Dive + kube-bench dengan practical workflow, command dan security assessment.
Cloud, Container & IaC Security #01: Tutorial Lengkap Trivy + Grype untuk Container Vulnerability dan SBOM
Episode 01/5: tutorial lengkap Trivy + Grype dengan practical workflow, command dan security assessment.