Cyber Risk Compendium

Coercion, extortion or corruption

BSI ID: G 0.35

Coercion, extortion or corruption can compromise the security of information or business processes. By threatening violence or other disadvantages, an attacker may, for example, attempt to coerce the victim into disregarding security guidelines or circumventing security measures (coercion). Instead of threats, attackers may also offer money or other benefits to employees or other individuals in order to turn them into instruments for security breaches (corruption).

For example, there is a risk that a corrupt employee may pass on confidential documents to unauthorised persons. Coercion or corruption can fundamentally compromise all core values of information security. Attacks may be aimed, among other things, at passing confidential information to unauthorised persons, manipulating business-critical information or disrupting the smooth running of business processes. There is a particular risk when such attacks are directed against high-ranking executives or persons in positions of special trust.