# 2 Business Context

# 2. Business Context (What You Are Protecting)

Goal: Align security with how the company actually operates.

Document

  • Business model (SaaS, retail, fintech, services, etc.)
  • Critical assets:
    • Customer data
    • Revenue-generating systems
    • Intellectual property
  • Regulatory drivers (if any): ISO, PCI, GDPR, local laws

Output

  • Short business overview
  • List of “crown jewels”

# Examples

Industry Business Overview Crown Jewels (What Must Be Protected)
Banking / Financial Services Provides digital and branch-based financial services, generating revenue through transactions, lending, and investment products under strict regulatory oversight. Customer financial and personal data; core banking and payment systems; transaction processing platforms; regulatory and reporting data
Healthcare Delivers clinical and healthcare services supported by electronic systems, with strong focus on patient safety, privacy, and compliance. Patient medical records; clinical and diagnostic systems; healthcare service availability; compliance and audit data
E-Commerce / Retail Sells products and services through online and physical channels, relying on digital platforms for payments and order fulfillment. Customer personal and payment data; online storefront and payment systems; inventory and fulfillment systems; brand reputation
Technology / SaaS Provides subscription-based digital services through cloud platforms, with revenue dependent on availability and customer trust. Customer data; core application and cloud infrastructure; source code and product IP; service uptime
Manufacturing Produces physical goods using automated and digitally enabled production environments where downtime directly impacts revenue. Production and control systems; product designs and trade secrets; supply chain systems; operational continuity
Telecommunications Delivers communication services relying on always-on network infrastructure and regulated operations. Network infrastructure and control systems; customer identity and billing data; service availability; regulatory data
Energy / Utilities Supplies essential services through critical infrastructure, operating under national and industry regulations. Operational and control systems; infrastructure availability; customer billing data; safety and compliance systems
Government / Public Sector Provides public services and manages citizen information with emphasis on availability, integrity, and trust. Citizen personal and identity data; critical public service systems; government records; legal and regulatory data
Education Provides academic services through physical and digital learning environments supporting students and staff. Student and staff data; learning management systems; research data; institutional reputation
Logistics / Transportation Operates transportation and supply chain services across distributed environments with time-sensitive operations. Fleet and routing systems; customer and shipment data; operational availability; partner integrations