What's the Play

Real scenarios. Concrete next steps.

Security advice is only useful when it maps to your actual situation. Browse the scenarios below to find your role, understand the risk, and walk away with a clear action plan β€” no jargon, no vendor pitch.

How to use this page: Find the scenario closest to your situation. The β€œThe Play” section gives you the highest-leverage actions to take first. Start there, then explore the linked frameworks for deeper guidance.

Small Business Owner
Email SecurityMFAPhishing

The Scenario

You run a 12-person accounting firm. A client emails asking why you sent them a strange invoice link β€” you didn't. Someone is impersonating your domain.

The Play

Lock down your email with SPF, DKIM, and DMARC records today. Enable MFA on every account that touches client data. Run a phishing simulation with your team so they recognize spoofed senders before the next attempt lands.

Software Development Team
Supply ChainDevSecOpsPatch Management

The Scenario

Your CI/CD pipeline uses a popular open-source library. A critical CVE drops on a Friday afternoon and your release is scheduled for Monday morning.

The Play

Integrate a software composition analysis (SCA) tool into your pipeline so vulnerabilities surface before merge, not after deploy. Establish a patch SLA policy β€” critical CVEs get a 24-hour response window, not a backlog ticket.

Healthcare Practice Manager
HIPAARansomwareIncident Response

The Scenario

Your clinic stores patient records in a cloud EHR. A staff member clicks a malicious attachment and ransomware begins encrypting files. HIPAA breach notification clocks are ticking.

The Play

Segment your network so clinical systems are isolated from general office machines. Maintain tested offline backups of all PHI. Have your incident response contacts β€” legal, IT, and your HIPAA privacy officer β€” documented and reachable before an incident, not during one.

IT Manager at a Mid-Size Company
CIS ControlsAsset ManagementRisk Register

The Scenario

Leadership wants a security audit before a Series B close. You have 60 days, a mixed cloud and on-prem environment, and no formal asset inventory.

The Play

Start with an asset discovery scan to build your inventory β€” you cannot protect what you cannot see. Map your environment against CIS Controls Level 1 as a baseline. Prioritize findings by exploitability and business impact so you can show investors a credible risk register, not just a list of open ports.

HR & People Operations Team
Identity ManagementAccess ControlOffboarding

The Scenario

An employee is offboarded on a Friday. By Monday, their credentials are still active in three SaaS tools, including your payroll platform.

The Play

Build a formal offboarding checklist that triggers automatic deprovisioning through your identity provider. Audit third-party SaaS access quarterly β€” most breaches involving former employees exploit accounts that were simply never closed.

Don't see your scenario?

Every organization's risk profile is different. Explore our frameworks library for structured guidance, or use the AI advisor to get a tailored starting point for your specific environment.