TechKnowSurge
NIST CSF GV.RM-02 ISC2 CC 1.2 NIST 800-53 PM-9 Cisco CCST Cybersecurity 4.3
InteractiveSecurityFree

Lock It Down: The Balancing Act

Turn a security dial for five organizations and find the setting that fits how much risk each one can accept.

⚑ Complete this interactive to capture a CTF flag worth 5 points.

About this interactive

There is a tug-of-war at the heart of cybersecurity: when you increase security, you decrease accessibility. The most secure thing you could do with any data is unplug it so nobody can reach it, and then it is useless. So every organization has to find a balance, and that balance is different for each one. This activity puts you in charge of five of them. For each organization you see what it protects, who needs to get in and how much risk it can accept. A dial sets how strict the controls are, from wide open to locked down, and each notch names the actual controls in place: a shared password, personal logins, a code from your phone, only company devices, a manager approving every request. Two meters, Security and Ease of access, move in opposite directions as you turn it. When you lock in a setting, you find out whether it fits. Too loose, and the organization is exposed to a breach it cannot accept. Too tight, and people start working around the controls, customers leave or the business stalls. The skill being practiced is risk management: weighing what a control costs against the risk of going without it. The same setting that is exactly right for a water treatment plant would shut down a café.

How to play

You are setting the security controls for five organizations, one at a time. Each card tells you what the organization protects, who needs to get in and its risk tolerance: how much risk it can accept.

Turn the dial (drag it, use the arrow keys, or pick a number) from 1, the loosest, to 5, the strictest. Each setting names the controls in place. Watch the Security and Ease of access meters: raising one lowers the other.

When you think you have the right balance, press Lock it in. You will see whether your setting was too loose, too tight or in the zone, and why.

Get 4 of 5 in the zone to pass.

What you'll learn

Aligned to

NIST CSF
GV.RM-02 Risk appetite and risk tolerance statements are established, communicated, and maintained.
ISC2 CC
1.2 Understand risk management concepts
NIST 800-53
PM-9 Risk Management Strategy
Cisco CCST Cybersecurity
4.3 Explain risk management

Key terms

Risk Management
The ongoing process of identifying, assessing, and mitigating risks to an acceptable level.
Risk Tolerance
The level of risk an organization is willing to accept before taking action to reduce or eliminate it. Risk tolerance is determined by leadership and reflects the organization's risk appetite, regulatory environment, and available resources.
Security Control
Any safeguard or countermeasure — whether technical, physical, or administrative — implemented to protect the confidentiality, integrity, and availability of systems and data. Security controls are classified by function (preventative, detective, corrective) and type (technical, physical, administrative).
Multi-Factor Authentication
MFA
An authentication method that requires users to provide two or more verification factors to gain access.

Topics

Interactive Risk Management Scenario

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →