One of the biggest mistakes you can make in business is underestimating risk.
Consider the case of the Titan submersible that OceanGate CEO Stockton Rush used to give wealthy customers tours of the Titanic wreck on the bottom of the North Atlantic.
Despite being warned against using carbon fiber in the vessel's hull, Rush pressed ahead, severely underestimating the risk.
The submersible tragically imploded in June 2023, highlighting the importance of a formal risk assessment process.
Because the submersible industry is so niche, Rush was able to take deadly risks.
Thankfully, industries like marketing have formal risk assessment processes like NIST SP 800-30 or ISO/IEC 27005 to help protect against disaster.
Step 1: Define scope
Most risk assessment systems work in similar ways at the outset. The process begins by identifying the scope and context of the potential risk landscape.

Every team is different, but generally speaking, marketing teams have the following:
- A public-facing website
- A CMS
- An analytics and tag layer
- Email platforms
- A CRM
The potential risks coming from these systems often involve customer data.
As every marketing department knows, compliance with data regulations is non-negotiable, and the fines for failing to safeguard data keep climbing.
A risk assessment is incomplete without full consideration of potential customer data leaks.
Teams should consider the following when it comes to sensitive data:
- The categories of personal data you collect, from names and email addresses to payment details, and exactly where each type is stored.
- Which of the compliance regulations apply to that data, such as the GDPR or CCPA, and what each one actually requires of you.
- Who can access the data internally, and do those who have access genuinely need it?
- How the data is protected in storage and in transit
But these aren't the only risks. Security is only half the picture, because the data also needs to be accessible.
Without a repository of information about customers and campaign performance, it's impossible for a marketing team to function.
If data is inaccessible for a day, that's a whole day of productivity lost. Another factor is data integrity. Marketing data is only valuable if it's accurate, and if information has been negligently or maliciously altered, it could have a serious impact on marketing operations.
As this section demonstrates, marketing teams should carefully consider the scope and context of potential risks before moving on.
For deeper definitions and step-by-step details, the cybersecurity assessment guide is a useful starting point.
Step 2: List assets
ISO 27005 begins the risk identification process by cataloging information assets, and for a marketing stack that list typically includes the CMS and its plugins, the hosting and DNS, SSL certificates, the analytics property, every tag in the tag manager, third-party scripts, the form scripts, and the customer data those forms collect.
The process involves clearly specifying who is responsible for every one of these assets.
If you don't assign responsibility for assets, coordinating a response during a data leak or compliance crisis becomes a job nobody takes seriously.
Without a clearly identified individual responsible for managing specific assets, everyone will simply assume it's someone else's job to deal with.
Step 3: Identify the threats

The next step involves grouping threat sources into a few categories:
- Adversarial
- Accidental
- Environmental
Adversarial threats include the following:
- Hackers are injecting malicious JavaScript.
- Ransomware attacks targeting confidential data
- Social engineering attacks
- Phishing campaigns
Accidental threats are the everyday slip-ups from your own team, such as a staffer pushing untested code live or pasting visitor emails into the data layer where they do not belong.
Environmental threats sit outside anyone's direct control.
A hosting outage can take the site down in the middle of a campaign, and an expired SSL certificate can do the same while scaring off the visitors who visit your site.
With the categories clear, go back to the asset list from Step 2 and note the threats that realistically apply to each item.
Step 4: Pinpoint the weaknesses
Threats represent potential risk, and unlike acts of nature like tornadoes or floods, cybersecurity threats are dynamic.
New threats emerge constantly because cybercriminal groups are always looking for new exploits and weaknesses.
Cybercriminals also tend to attack organizations where they're weakest, so a comprehensive approach to security is the only winning strategy.
On a marketing site, the common weak points look like this:
- Outdated software: An old CMS version or an unpatched plugin hands attackers a known vulnerability to work with.
- Weak access controls: Shared or reused logins without multi-factor authentication make accounts easy to hijack.
- Excessive tag manager rights: When too many users have access, a compromised account can push a malicious tag live.
- Missing security headers: Without a Content Security Policy, the browser runs whatever script loads, including anything an attacker injects.
- Leaky forms: Fields that send personal data to outside domains expose the visitor information you are meant to protect.
Once each weakness is listed, trace it back to the threat and estimate the likelihood and impact.
Step 5: Score likelihood and impact
Now you put numbers behind the risks. NIST defines risk as a function of two things. First, how likely an exploit is, and second, how serious the consequences would be.

You should assign a score to each threat-and-weakness pairing on both:
- Use one simple scale: Rate likelihood and impact as low, medium, or high.
- Judge likelihood: Weigh the attacker's capability and intent against the strength of your current cybersecurity capabilities.
- Judge impact: Estimate the damage, from lost traffic and broken conversion paths to regulatory fines after a data leak.
- Create a matrix: A risk matrix helps you visualize risk. On one axis, you have risk severity; on the other, you have likelihood. Focus efforts on the most likely and dangerous threats.
- Document your reasoning: NIST calls the matrix a communication tool, so be prepared to explain your reasoning and decision-making.
Search engines regard security as a crucial factor in prioritizing sites, and a hacked or malware-flagged site can see rankings fall or vanish from results entirely.
That makes high-likelihood, high-impact items your first priority.
Step 6: Prioritize and plan
Once you've decided to handle certain risks, it's time to plan solutions, and the order matters as much as the fixes themselves.
Work from the top down, since limited time and budget should always go to the threats that can do the most damage.
Most of the work falls into a few clear moves:
- Start with the worst: Tackle the highest-rated risks first.
- Assign each fix: Give every response an owner and a deadline.
- Write it down: ISO 27005 calls this the risk treatment plan, recording each control and its owner.
- Decide what to defer: When a solution is too costly or slow, ISO lets you accept or insure a residual risk, signed off by someone accountable.
Track these solutions in the same way you track campaigns.
Give each one a status and a due date inside whatever tool your team already uses, then review the open items in your regular standup meetings.
A plan left in a forgotten spreadsheet isn't helping anyone, so always have a centralized list that everyone uses as a clear reference.
Step 7: Monitor and reassess
A risk assessment is just a snapshot, and both your stack and the threat landscape change constantly.
Each new plugin or tag shifts your exposure, and so does every campaign you launch. Both NIST and ISO treat assessment as an ongoing process.
A good practice involves a quarterly review of users and tags, and an off-cycle reassessment after major changes or any incident.
Over time, your records become useful in their own right. Patterns emerge in which risks keep reappearing, and which security strategies worked out.
The more information you collect, the more accurate your assessments and predictions will be.
Cybersecurity data may also be valuable for the latest AI-powered cybersecurity tools.
Prepare for an uncertain security future
The Titan disaster is a reminder of what unchecked risk can do, but the principle scales down to your marketing site.
Without formal risk assessment procedures, it's easy to make disastrous oversights or mistakes.
The cyberthreat landscape is dynamic, and the advent of AI is making the future even more uncertain.
One thing is for certain: those with weak defences are always the preferred target.
Are you interested in learning more about the cybersecurity threatscape and emerging new technology? See our other blog posts for more.
