Session 8: Policies, Risk & Final Project
The final session turns individual knowledge into something an organisation can run: simple policies that people actually follow, a risk assessment a small business can act on, and a complete security review of a real setup delivered as a professional report.
Learning objectives
By the end of this session you will be able to do each of these without prompting.
- Write simple security policies that survive contact with real staff
- Conduct a risk assessment a small business can act on
- Prioritise remediation by risk reduced rather than by impression
- Deliver a security review as a professional written report
- Explain your findings to a non-technical owner
- Identify your next step in a security career
The taught content
Policies that people actually follow
Most security policies fail because they are written to be impressive rather than usable: twenty pages nobody reads, requiring behaviour that makes the job harder, and enforced by nobody. A policy that is followed is short, specific, and costs people almost nothing. For a small business, one page covering five things outperforms a handbook covering fifty.
The five that matter: passwords and accounts — a password manager is provided and required, passwords are never shared or written down, and two-factor is on for every business account. Devices — every laptop and phone is locked and encrypted, and a lost or stolen device is reported immediately. Data — backups run automatically and nobody stores business data only on their own machine. Messages — no one-time code is ever shared with anyone, and any request for payment is verified through a second channel. Reporting — if something seems wrong, say so immediately and there will be no blame.
That last point deserves emphasis, because it is the one organisations get wrong. If staff fear being told off for clicking a link, they hide it, and a hidden incident becomes a large one. A no-blame reporting culture is a security control, and it is free. The policy should say so explicitly, because otherwise nobody believes it.
Conducting the risk assessment
The assessment follows the model from session one and produces something a business can act on. List the assets — what would genuinely hurt to lose or expose: customer data, the bank account, the social accounts, the order records, the ability to trade. Apply the CIA triad to each, because it turns vague worry into a specific question.
Then identify the vulnerabilities in this specific setup, not generic threats: no backup, one shared password, an unencrypted laptop, a router on its default admin password, no two-factor, software installed from a pirated source, a staff member who is the only person who knows the passwords. These are findable by looking, and they are what you can act on.
Score each on likelihood and impact — a simple high, medium, low is sufficient and more honest than a false numeric precision. Rank them, and then recommend controls in order of risk reduced per naira, which for almost every small business means backups, two-factor, a password manager, updates, device encryption, and staff awareness, in that order. Include what you would deliberately not spend on, because that is as valuable as what you recommend.
The written report
A security review is a document, and its quality determines whether anything changes. The structure that works: an executive summary of one paragraph in plain language, stating the overall position and the top three actions — because the owner will read this and possibly nothing else. Then the scope, so it is clear what was and was not examined. Then the findings, each with what it is, why it matters in this business's terms, and how to fix it. Then the prioritised recommendations with cost and effort. And finally what was not covered.
Two habits make the difference. Write every finding in the business's terms, not in technical ones: not 'the router uses default credentials' but 'anyone who knows your router model can take control of your internet connection and see where your staff go online'. And give each finding a clear fix with a cost, because a problem without a solution is just a worry, and a business owner who cannot act on it will set the report down.
Be honest about the limits of what you did. A review is not a penetration test and does not prove anything is unbreakable; it identifies the exposures that matter and the order to fix them. Saying so protects you and it is what a professional does. Overclaiming — 'your systems are now secure' — is both false and a liability waiting to arrive.
Explaining it to a non-technical owner
The conversation matters as much as the document. Lead with the business consequence, not the technical fault: 'if this laptop is stolen today, every customer record on it goes with it, and there is no copy' lands where 'the disk is unencrypted' does not. Then give the fix and its cost, and let them decide.
Avoid fear as a sales technique. A frightened client makes bad decisions, buys the wrong things, and resents you later. The honest framing is that most risks are ordinary and most fixes are cheap, and that doing the five basics puts them ahead of nearly every comparable business. That is true, it is reassuring, and it is more likely to produce action than a threat.
And be willing to say 'you do not need this'. Declining to sell a control that does not reduce their actual risk is the fastest way to be trusted with everything else, and in a market where everyone knows everyone, that trust is the entire business.
Where to go next
The honest position after four weeks: you can assess a small business's security, apply the controls that matter, respond to the common incidents, and explain all of it to someone with no technical background. That is genuinely employable and genuinely useful, and it is more than most small businesses in this market have ever had done.
The natural next steps branch. Security operations and monitoring — watching for and triaging alerts — is where most entry-level jobs sit. Governance, risk and compliance is document and process work, largely non-technical, and it is a large and steady employment area. Technical specialisms such as penetration testing need deeper networking and scripting skill, which you can build on top of this. And IT support is the most common entry route into security in practice, because it teaches you how systems actually fail.
Certifications help once you have the grounding — CompTIA Security+ is the usual first one and it maps closely to what this course covered — but they certify knowledge you already have rather than supplying it. What actually gets you hired is being able to look at a real setup, name what is wrong with it in plain language, and fix the things that matter in the right order. That is what the final project demonstrates.
Instructor demonstration
The instructor writes a one-page policy set for a real small business, conducts a full risk assessment, then delivers the review as a written report and presents it to a non-technical owner, fielding the objections that actually come up.
- 01
Show a policy nobody follows
Display a twenty-page corporate policy and explain why a small business ignores it entirely. Contrast with what a usable one page contains.
- 02
Write the five-point policy
Draft passwords and accounts, devices, data, messages, and reporting. Explain why each is included and what it costs staff to comply.
- 03
Add the no-blame reporting clause
Write it explicitly and explain that fear of blame turns a small incident into a large one because staff hide it.
- 04
List the business's assets
Identify what would genuinely hurt to lose, and apply the CIA triad to each. Explain that you cannot protect what you have not named.
- 05
Find the actual vulnerabilities
Walk the setup: no backup, shared password, unencrypted laptop, default router credentials, no two-factor, pirated software. Note that these are found by looking, not by scanning.
- 06
Score and rank
Apply high, medium and low for likelihood and impact, and produce a ranked list. Explain why a simple scale is more honest than false numeric precision.
- 07
Recommend in order of risk reduced
Order the controls by benefit per naira with a cost against each, and name one thing you would deliberately not buy.
- 08
Write the executive summary
Draft one plain-language paragraph with the top three actions. Explain that the owner may read this and nothing else.
- 09
Translate a finding into business terms
Rewrite 'the router uses default credentials' as a consequence the owner feels. Explain that the translation is what produces action.
- 10
State the report's limits
Note that this is a review, not a penetration test, and does not prove anything is unbreakable. Explain why overclaiming is a liability.
- 11
Present to the owner
Deliver the summary, take the objections — cost, disruption, 'we have never had a problem' — and answer each without fear tactics.
- 12
Map the next steps
Lay out security operations, governance and compliance, technical specialisms and IT support as routes, and explain where certification fits.
Guided practice
The final project: a complete security review
You conduct a full security review of a real Nigerian small business: a one-page policy set, an asset and vulnerability assessment with scored and ranked risks, prioritised recommendations with costs, and a written report with an executive summary — then present it to a non-technical owner and handle their objections.
- 01Describe the business: what it does, staff count, devices, accounts and how it takes payment.
- 02List the assets that would genuinely hurt to lose or expose.
- 03Apply the CIA triad to each asset, stating which property is at stake and why.
- 04Walk the setup and list the actual vulnerabilities you find, with evidence for each.
- 05Score each on likelihood and impact and produce a ranked list.
- 06Write a one-page policy covering passwords, devices, data, messages and reporting.
- 07Include an explicit no-blame reporting clause.
- 08Recommend controls ordered by risk reduced per naira, each with a cost and an effort estimate.
- 09Name at least one control you would deliberately not buy, and justify it.
- 10Write a one-paragraph executive summary in plain language with the top three actions.
- 11Translate every finding into a business consequence rather than a technical fault.
- 12State clearly what the review did not cover and that it is not a penetration test.
- 13Present the report to a non-technical owner and record their objections.
- 14Answer each objection without fear tactics and note which recommendations they accepted.
The standard we hold you to
A complete written review with assets mapped to the CIA triad, real vulnerabilities evidenced and scored, risks ranked, a one-page policy with a no-blame clause, recommendations ordered by risk reduced per naira with costs, at least one justified omission, a plain-language executive summary, every finding expressed as a business consequence, stated limits, and a delivered presentation with objections handled without fear tactics.
Common mistakes and how to fix them
You wrote a long policy nobody will read
Fix: One page, five topics, specific and cheap to comply with. A policy is measured by whether it is followed, and a twenty-page document in a small business is followed by nobody.
Your policy punishes people for reporting incidents
Fix: Add an explicit no-blame clause and mean it. Fear of being told off makes staff hide a clicked link, and a hidden incident becomes a large one.
You listed generic threats instead of this business's vulnerabilities
Fix: Walk the actual setup and find the real weaknesses: no backup, shared passwords, default router credentials, unencrypted devices. Generic threats are not actionable; specific vulnerabilities are.
You used false numeric precision in your scoring
Fix: High, medium and low is sufficient and more honest. A risk score of 7.4 implies a precision you do not have, and it invites arguments about the number rather than the risk.
You wrote findings in technical language
Fix: Translate each into a business consequence the owner feels. 'Anyone who knows your router model can see where your staff go online' produces action; 'default credentials' does not.
You recommended without costs
Fix: Every recommendation needs a cost and an effort estimate. A problem without a priced solution is a worry the owner will set down and forget.
You used fear to sell controls
Fix: A frightened client buys the wrong things and resents you later. The honest framing is that most risks are ordinary and most fixes are cheap, which is both true and more likely to produce action.
You claimed the business is now secure
Fix: Say plainly that this is a review, not a penetration test, and that it does not prove anything unbreakable. Overclaiming is false and it is a liability waiting to arrive.
Expert notes
The habits that separate someone who can do this from someone who does it well.
- Write every policy so compliance costs staff almost nothing. A policy that makes the job harder is worked around, and a worked-around policy is worse than none because it creates the illusion of control.
- Lead every conversation with the business consequence, not the technical fault. Owners act on what they feel, and translating 'unencrypted disk' into 'every customer record leaves with a stolen laptop' is the skill that makes the rest of your work matter.
- Recommend in order of risk reduced per naira and always include something you would not buy. Declining an easy sale is the fastest way to be trusted with everything else.
- State the limits of your review explicitly. 'This is not a penetration test and does not prove anything is unbreakable' protects you, and it is what a professional says rather than something a professional has to retract.
Key terms
- Acceptable use policy
- What staff may and may not do with business systems. Short and specific beats long and ignored.
- No-blame reporting
- A commitment that reporting an incident brings no punishment. A genuine control, because fear makes staff hide incidents.
- Risk scoring
- Rating likelihood and impact. High, medium and low is more honest than false numeric precision.
- Remediation
- Fixing an identified vulnerability. Prioritised by risk reduced, not by how impressive the fix sounds.
- Executive summary
- One plain-language paragraph with the top actions. Often the only part an owner reads.
- Scope
- What the review did and did not examine. Stating it prevents misunderstanding and protects you.
- Penetration test
- An authorised simulated attack proving whether defences hold. Distinct from a review, and worth saying so.
- Governance, risk and compliance
- The policy, assessment and standards side of security. Largely non-technical and a large employment area.
Homework before the next session
Write a one-page policy
Passwords, devices, data, messages, reporting — with an explicit no-blame clause. Give it to one real business and see whether they follow it.
Assess one real business
Assets, CIA triad, real vulnerabilities found by walking the setup, scored and ranked. This is the exercise that makes everything else concrete.
Translate five findings
Take five technical findings and rewrite each as a business consequence the owner would feel. Practise until the translation is immediate.
Plan your next step
Choose between security operations, governance and compliance, a technical specialism and IT support, and write what you would do in the next three months to get there.
Assessment rubric
How this session is marked. The certificate for Cybersecurity is awarded on the deliverable, not on attendance.
| Criterion | Passing | Excellent |
|---|---|---|
| Policy design | Writes some rules. | One page covering five specific topics, cheap to comply with, and including an explicit no-blame reporting clause. |
| Assessment | Identifies some risks. | Assets mapped to the CIA triad, real vulnerabilities found by inspecting the setup, and risks scored and ranked with honest rather than falsely precise scoring. |
| Recommendations | Suggests fixes. | Ordered by risk reduced per naira with a cost and effort for each, plus at least one justified omission. |
| Communication | Explains the findings. | Every finding expressed as a business consequence, an executive summary a non-technical owner can act on, and objections handled without fear tactics. |
| Professional honesty | Delivers a report. | States the scope and the limits, does not claim the business is secure, and does not oversell controls the business does not need. |
Session questions
Does a small business really need a written security policy?+
Yes, but a one-page one. It sets the expectation that passwords are not shared and codes are never given out, it tells staff what to do when something seems wrong, and the no-blame clause means incidents get reported rather than hidden. A twenty-page document would simply be ignored.
How do I get my first security job?+
IT support is the most common route, because it teaches how systems actually fail. Governance, risk and compliance is a large non-technical area. What gets you hired is being able to look at a real setup and say what is wrong with it in plain language — which is exactly what the final project demonstrates, so keep it as a portfolio piece.
Do I need certifications?+
They help once you have the grounding. CompTIA Security+ is the usual first step and maps closely to this course. But a certification certifies knowledge you already have; being able to assess a real business and explain it to its owner is what actually gets you work.
How do I price a security review?+
Price it as a professional assessment with a written deliverable, not as an hourly favour. It is a document a business can act on and keep, and it is worth considerably more than the hours suggest — particularly when it prevents a single incident. Business & Freelancing covers pricing in depth.
What should I never claim in a report?+
Never claim the business is secure or that anything is unbreakable. State what you examined, what you found, what you recommend, and what was out of scope. Overclaiming is false, and it becomes a liability the moment something goes wrong.
This session is part of
Cybersecurity
4 weeks · 8 sessions · ₦50,000 · you leave with a security assessment report