A city risk team scopes ransomware exposure only to one forgotten departmental Access database. Critical 911 and utility billing applications are left out. What coverage problem does that create?
Select an answer to reveal the explanation.
Short Explanation
Scoping ransomware to one dusty Access file is like locking the garden shed while leaving the city hall doors wide open. The forgotten database might matter, but the real blast radius sits on 911 and billing. Tiny scopes create silent gaps that look tidy on paper and fail in an incident.
Full Explanation
Entity scoping for a risk must include the populations where the threat can cause material impact. Limiting ransomware to a single low-criticality database omits high-value applications that attackers would preferentially target. Those omissions create coverage gaps: assessments, indicators, and responses never attach to the systems leadership assumes are covered. Effective scoping starts from critical services and expands with evidence, not from the easiest orphan record.